shopify

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
references/checkout-extensions.md

Moderate supply-chain/security risk due to (1) UI extension performing an authenticated external network call using a checkout session token, which could enable credential/context exfiltration if the endpoint is compromised/changed; and (2) Web Pixel extension dynamically loading a third-party script and tracking/sending checkout lifecycle data (including order/transaction details). The Rust Shopify Function shows no evident malicious behavior beyond applying discounts based on metafield configuration.

Confidence: 72%Severity: 68%
Audit Metadata
Analyzed At
Mar 31, 2026, 06:24 AM
Package URL
pkg:socket/skills-sh/theneoai%2Fawesome-skills%2Fshopify%2F@45c832335e77caf5b3660a80304d810ca5b27598