Shopify Storefront Check
matahari.com
Results Summary
34 findings detected across matahari.com.
Severity Breakdown
Total findings detected across all components. The public summary below groups findings by vulnerability type. To see every affected component in full detail, run a free scan on your own domain at vulnify.app/tools.
Findings Overview
30 unique issues shown below, grouped from 34 total findings. When a vulnerability affects multiple components, it is listed once with the affected component count.
-
high CSP missing default-src directive
Missing default-src weakens baseline fallback behavior.
-
high Cookie missing Secure flag
Affects 3 components
_shopify_y: _shopify_y=[REDACTED]; domain=matahari.com; path=/; expires=Mon, 13 Sep 2027 10:51:14 GMT; SameSite=Lax
-
medium Referrer-Policy: missing
Controls how much referrer information is shared
-
medium Permissions-Policy: missing
Controls browser features and APIs
-
medium CSP missing object-src restriction
Object/embed content is not explicitly restricted.
-
medium Cookie missing HttpOnly flag
Affects 3 components
_shopify_y: _shopify_y=[REDACTED]; domain=matahari.com; path=/; expires=Mon, 13 Sep 2027 10:51:14 GMT; SameSite=Lax
-
medium Cookie missing SameSite attribute
localization: localization=ID; path=/; expires=Mon, 13 Sep 2027 04:51:14 GMT
-
medium Disclosure headers or generator metadata expose stack details
Server: cloudflare
-
medium Technology fingerprint signals were detected across the public surface
Shopify on /, /products/[REDACTED], /products/[REDACTED]?variant=46255507964055, /products/[REDACTED]?variant=46255507996823, /products/[REDACTED] | React on /, /products/[REDACTED], /products/[REDACTED]?variant=46255507964055, /products/[REDACTED]?v…
-
low High external-link density detected on storefront HTML
Detected 22 absolute external link references. Validate theme/app injected links and outbound destinations for governance drift.
-
low Shopify app footprint signals detected
Detected 3 app-related asset signal(s). Review installed app governance and remove unused integrations.
-
info Shopify storefront signals detected
Signal count: 6. Ensure the target is the live Shopify storefront domain.
-
info Third-party script footprint appears manageable
Third-party scripts: 0; Shopify CDN scripts: 9.
-
info Broader Shopify route coverage completed
Sampled 7 storefront route(s) plus public JSON/account endpoints for deeper evidence.
-
info Public Shopify JSON storefront surfaces responded during validation
/cart.js (200), /products.json (200), /search/suggest.json (200). Product objects observed: 1; predictive search results observed: 0.
-
info TLS grade: A+
Protocol: TLSv1.3; Cipher: TLS_AES_256_GCM_SHA384 (TLSv1.3)
-
info Strict-Transport-Security (HSTS): present
max-age=7889238
-
info Content-Security-Policy (CSP): present
block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests;
-
info X-Frame-Options: present
DENY
-
info X-Content-Type-Options: present
nosniff
10 findings are grouped in this public summary
This public page groups findings by vulnerability type to avoid exposing sensitive configuration details about matahari.com. To see the full breakdown including every affected component, version number, and remediation step, run a free scan on your own domain using Vulnify.
Run a Free Scan on matahari.comWhat the Shopify Storefront Check Covers
This security profile for matahari.com was generated by Vulnify. The check analyzes:
- Storefront theme and app detection
- JavaScript and asset security review
- Security headers and CSP assessment
- Third-party script and integration checks
Prioritized Actions
- highSet default-src baseline
- highHarden cookies
- mediumAudit Shopify app footprint and ownership
- mediumAdd Referrer-Policy header
- mediumAdd Permissions-Policy header
- mediumDisable object/embed execution
- mediumUse hardened cookie prefixes where possible
- mediumReduce disclosure headers
- lowImprove Content-Security-Policy (CSP) configuration
- lowImprove Strict-Transport-Security (HSTS) configuration
- lowMinimize unnecessary version or generator disclosure
Run a Full Security Scan on matahari.com
Check for XSS, SQL injection, CSRF, broken authentication, and 50+ additional security tests with a complete vulnerability assessment.
About This Check
This report was generated using Vulnify's free security tools. Results reflect the configuration at the time of the check. For ongoing monitoring, detailed remediation guidance, and vulnerability scanning across 50+ security tests, create a free Vulnify account.
Last checked:
Report abuse
If this page contains sensitive data, copyright issues, or should not be public, report it.