Vigavo for Shopify
Your Shopify store, checked.We stay awake.
Shopify runs checkout and the servers. We check what you control: email DNS, your domain, theme code and the apps and scripts you installed.
Free. No signup. Read-only checks from the outside.
What Vigavo checks on your Shopify site
A store sends order and marketing email, so spoofing protection matters. Apps and theme edits can also add scripts with keys in them.
Security check
Exposed keys in your custom code and embeds, email spoofing protection, domain expiry, risky subdomains, blacklists and mixed content.
Change alerts
We re-check on a schedule and tell you when something new appears, by email, Telegram, Slack or webhook.
An honest grade
Settings that Shopify controls are shown separately and never lower your grade.
Managed by Shopify
Shopify runs the servers: security headers, TLS certificates, server software and compression are set by Shopify for every site. Your report lists them under "Managed by Shopify" so you know what they are, without asking you to fix them.
What you can fix
- ✓ Email DNS: SPF, DKIM and DMARC so nobody can send mail as you
- ✓ Your domain: renewal date, transfer lock, subdomains
- ✓ Content: search visibility, link previews, broken links
- ✓ Third-party apps, scripts and embeds you added
Tip: Shopify sets some cookies itself; cookie findings are marked as partly managed by Shopify because apps you install add others.
Questions
Why don't missing security headers lower my grade on Shopify?
Shopify sets them for every site it hosts and gives you no way to change them. We show them under "Managed by Shopify" and grade only what you can influence.
Do I need to install anything on Shopify?
No. Paste your address and the check runs from the outside, like a visitor's browser. Nothing is added to your Shopify site.
What happens when something changes?
We compare every scan with the previous one and alert you about new issues. If Shopify changes a security setting on its side, you get one short notice.
Is the scan safe for my site?
Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.
Other platforms