Axyom Risk Scanner for Shopify

Run a lightweight scan of public-facing exposure. Detect exposed endpoints, misconfigurations, and leaked secrets — without accessing customers, orders, or any PII.

How It Works

Three steps to your first security scan. No code changes required.

1

Install the app

Add Axyom Risk Scanner to your Shopify store. No code changes or theme edits needed.

2

Run a scan

Enter your store URL and launch a lightweight, non-intrusive security scan from the Shopify Admin.

3

Review your score

Get a risk score from 0–100 with actionable findings stored in your shop metafields.

What We Scan

We check publicly visible infrastructure only. No store data is ever accessed.

🛡️

Exposed Admin Paths

Detects publicly accessible admin and debug endpoints.

🔒

Security Headers

Checks for missing or misconfigured HTTP security headers.

🔑

Leaked Secrets

Scans for exposed API keys, tokens, and credentials in public assets.

📜

SSL / TLS Configuration

Validates certificate validity and protocol configuration.

✉️

DNS & Email Security

Checks SPF, DKIM, and DMARC records for domain spoofing risk.

🌐

Open Ports & Services

Identifies unnecessarily exposed network services.

Security & Privacy

Axyom never accesses customer data, orders, or any PII. Scans are server-to-server against publicly visible endpoints only.

🚫

No PII Access

We never read customers, orders, or private store data.

🖥️

Server-to-Server

All scans run from our infrastructure against public endpoints only.

💾

Metafield Storage

Risk scores are stored in your shop metafields. You own your data.

Get Started

Enter your Shopify store domain to install or log in.

e.g. my-store.myshopify.com

Frequently Asked Questions

Is Axyom Risk Scanner free?

Yes, the base scan is free for all Shopify stores. Install the app, enter your store URL, and get your risk score at no cost.

What data do you access?

None. We only scan publicly visible endpoints. We never access customers, orders, or store admin data. The app requires minimal permissions.

How long does a scan take?

Most scans complete in under two minutes. You’ll see your risk score as soon as results are available.

Where are scan results stored?

Results are stored as metafields on your Shopify shop resource. You retain full ownership and can delete them at any time by uninstalling the app.

Can I scan a custom domain?

Yes. You can scan your store's primary custom domain and your .myshopify.com domain.