Liquid SSTI, storefront API abuse, theme XSS
Check myshopify.com CNAME + X-Shopify-* headers.
Probe for SSTI via Liquid expression evaluation in customisable surfaces.
Test storefront API for permission-misconfig exposure.
Hosted Shopify core is handled by Shopify themselves; this addon scans YOUR storefront surface only.
€49
Any tier · One-time per scan
8 specialized tests + AI-powered analysis
Start Your ScanSelect this addon when configuring your scan