Skip to content
The October 1 Indexby StatusBird LLC
Preview. Numbers below are placeholders until the scan data is published. This page is not indexed.
The October 1 Index · Methodology

On October 1, 2026, Shopify stops accepting new script tags from apps. On March 1, 2027, it stops running the existing ones. Merchants were not told.

21days until script tag create and update calls fail (October 1, 2026)
172days until Shopify stops injecting existing script tags (March 1, 2027)
Shopify stores identified by their storefront markers
of confirmed stores still carry at least one legacy ScriptTag injection

The October 1 Index is an independent record of which Shopify apps still load scripts through the deprecated ScriptTag API. StatusBird fetched the public homepage of each storefront from the outside, recorded every script rendered in Shopify's ScriptTag form, and confirmed every store counted as exposed on a second, separate fetch, attributed to the app that injected it. Where an app has already migrated to a theme app extension and only left an old tag behind, the index says so; those stores are not at risk. Scripts that a developer pasted into a theme by hand are not counted, because they are not affected by the deprecation.

Shopify's developer changelog entry of August 24, 2026 states that on October 1, 2026 the ScriptTag create and update calls return errors on every API version, and that on March 1, 2027 Shopify stops injecting script tags into storefronts. The deprecation notices went to app developers. Merchants see an admin warning only after a feature has already stopped working.

Check your store

Homepage only, results in seconds, nothing stored. The full report covers product, collection, cart and search pages.

Which apps still inject legacy script tags?

The vendor table appears here when the scan data is published.

What breaks on March 1?

The injected script stops loading. Whatever the app did on the storefront through that script stops with it, with no error shown to the merchant or the shopper. The app's admin pages keep working, which is why the failure is easy to miss.

What should a merchant do before October 1?

List the apps on your store, ask each one for its migration date, replace the ones that do not have one, and check again after. October 1 matters because after that date a vendor can no longer create or update a script tag; March 1 is when the existing ones stop.

What should an app vendor do?

Ship the theme app extension, remove old script tags on install and update, publish a notice, and request verified status on this page.

$399
Exposure Report

One storefront, every page type: every third-party script, which ones stop on March 1, which vendors have no migration date, delivered within 48 hours with 30 days of continuous detection.

Order the report
$999
Agency portfolio sweep

Every client store on your roster, one report with a page per client you can forward as is. Valid until October 1.

Order the sweep
Quoted
Institutional dataset

The aggregate index by app, vertical or portfolio, for defense counsel, cyber carriers and platforms. Not sold to plaintiffs' firms.

Enquire

Frequently asked questions

What is a Shopify script tag?

A script tag is a JavaScript file that an app asks Shopify to inject into a storefront through the ScriptTag API. Shopify renders it in the page head with the store's domain appended. It was the original way apps added storefront features; theme app extensions replaced it.

What happens on October 1, 2026?

The ScriptTag create and update API calls return errors on every API version, so an app can no longer add or change a script tag. Existing tags keep running until March 1, 2027.

What happens on March 1, 2027?

Shopify stops injecting existing script tags into storefronts. Any app feature that still depends on one stops working on that date.

How does the index know a script is a legacy script tag?

Shopify renders API script tags in one fixed form in the page head. The index counts only that form, outside the markers Shopify uses for theme app extensions, and excludes scripts a developer placed in the theme by hand. Every store counted as exposed is confirmed on a second, separate fetch. The full method is on the methodology page.

Why is my app listed as cleanup only?

On the stores checked, the app loads through a theme app extension and also still has an old script tag installed. Nothing breaks on March 1 for those stores; the old tag is simply redundant.

Does this report mean my store is compliant?

No. The index and the Exposure Report record what a storefront loaded on a given date. They make no statement about compliance with any law or standard.