The October 1 Index · Exposure Report
Every third-party script on your storefront, on the record
The free check reads one homepage. The Exposure Report loads five page types of one storefront in a real browser, records every script that runs and which app put it there, and tells you which of them stop on March 1, 2027. It arrives within 48 hours as a dated PDF with the evidence file behind it, and the same pages are re-checked weekly for 30 days.
Read the sample report for colourpop.com before you order. ColourPop is the subject of a public-page check only and has no relationship with StatusBird LLC.
Full refund if nothing is found on any page type. Billed by StatusBird LLC through Stripe; not a Shopify app.
What the report records
Home, product, collection, cart and search pages. Each script is attributed to the app that injected it, using Shopify's own app-block markers or the script host, and classified as a legacy ScriptTag injection, a theme app extension, or hand-placed theme code.
The legacy injections, by app, with the exact script and the page it loads on. Apps that have migrated and left an old tag behind are marked cleanup only.
Requests to known tracking endpoints that fired before any interaction with the page, attributed to the app that made them.
Critical and serious failures from the axe-core WCAG rule set on each page type, counted by rule.
The product page's structured data checked against the fields Google Merchant Center relies on, and the review widget's displayed count against the count in structured data.
A JSON file with every observation, its SHA-256 printed on the report, and a verification page so a forwarded copy can be checked against the issued one.
Who orders it
| Situation | What the report gives you |
|---|---|
| The free check found an at-risk app | Whether the same app, or others, load on product, cart and search pages too, and the exact scripts to put in front of the vendor. |
| The free check found nothing | Confirmation across the pages the homepage cannot show, in writing, before a customer or a partner asks. |
| Preparing a store for sale, financing or a platform review | A dated, hash-sealed record of the third-party layer from an outside party. |
| Disputing a vendor's claim | Observation on a date, in the vendor's own script text, rather than an opinion. |
What happens after you order
- Stripe checkout asks for the storefront domain and your email.
- Within 48 hours the report PDF and the JSON evidence file arrive by email, with a link to the verification page.
- For 30 days the same five pages are re-checked weekly. You get an email only if a new legacy script tag or a new tracker appears.
The report describes what a public storefront loaded on the date shown. It is not legal, compliance, security or accessibility advice, and the absence of a finding is not a statement that none exists. Terms are on the terms page; refunds in section 4.
Frequently asked questions
Does the report need access to my Shopify admin?
No. Everything is observed from the outside, the way a shopper's browser sees the store. Nothing is installed and no credentials are involved.
How is this different from the free check?
The free check fetches the homepage HTML once and looks for legacy script tags. The report loads five page types in a real browser, so it sees scripts that inject only on product, cart or search pages, network requests to trackers, accessibility failures and structured data, and it is delivered as a sealed document.
Can I forward it to an app vendor or my agency?
Yes. The report is yours to forward, and the verification page lets the recipient confirm it is the document that was issued.
What if you cannot fetch my store?
If the storefront cannot be fetched after reasonable attempts, the order is refunded in full.