Mailcraft.
•6 min read•Atelier Dispatch

Why Shopify Email Apps Fail the Security Test: Inside the Permission Dilemma

Apps requesting broad write access to your store database carry an inherent operational risk. Here is why the traditional app architecture is fundamentally broken.

M

Maxime

Founder

Verified Safe

When an independent merchant installs an app to customize their Order Confirmation email, they expect a simple visual editor. What they rarely realize is that clicking "Install App" often grants that external server extensive read and write permissions to their store database, products, and customer records.

Apps that request write access to your catalog, orders, or admin data carry an inherent architectural risk: any software bug, deployment error, or infrastructure issue on the vendor's side can directly affect your live store. This isn't hypothetical—it is the nature of granting write permissions to any third-party system. Mailcraft eliminates this risk entirely by requesting zero permissions.

The Mailcraft Zero-Scope RuleVerified Safe

100% Theme and Database Isolation

scopes = ""

The Anatomy of the Permission Trap

Under standard Shopify App Bridge protocols, apps declare permissions known as OAuth Scopes. To dynamically inject code or fetch live data, apps typically request:

  • write_themes: Permission to alter your Liquid templates and assets directly.
  • read_products & write_products: Unrestricted access to modify categories, handles, and inventory.
  • read_customers & read_orders: Full visibility over personal customer data, addresses, and order history.

The paradox is striking: a notification email is simply a static Liquid template rendered natively by Shopify's core engine. It does not require continuous API access, background cron jobs, or database hooks.

0
Scopes Required
Mailcraft requests zero Shopify OAuth permissions.
100%
Sovereign Control
Templates compile directly to standard Shopify Liquid.
0s
Store Downtime Risk
Zero risk of theme corruption or collection loss.

How Legacy Apps Corrupt Storefronts

Why would an email template tool ever delete a store collection? The answer lies in architectural overreach.

Many legacy tools attempt to be all-in-one marketing suites: they inject tracking tags, monitor user behaviors, sync collections for recommendations, and execute batch updates via background webhooks. When an unhandled exception or malformed API payload occurs on the vendor's cloud server, the blast radius impacts the merchant's live store.

Vulnerability Notice

The Blast Radius Problem

When you grant an external cloud service write permissions to your catalog, any bug in their deployment pipeline becomes an existential threat to your revenue and search engine rankings.

The Zero-Permission Alternative

Mailcraft was engineered from first principles around a radical premise: an email design studio should never touch your production database.

Instead of demanding API keys and persistent store access:

  1. Design in an isolated studio: You craft typography, spacing, and brand accents in an offline-capable browser atelier.
  2. Compile to native Liquid: Mailcraft compiles your visual design into 100% valid, self-contained Shopify Liquid templates.
  3. Copy & paste natively: You paste the code directly into Shopify Admin > Notifications.
Security Standard

Permanent Sovereignty

Because the Liquid code lives natively in your Shopify admin, it cannot break if an external server goes down, and it continues rendering flawlessly even if you uninstall Mailcraft.

Conclusion: Demand Architectural Honesty

Your store catalog and SEO structure represent years of hard work. Entrusting them to an email styling utility is an unnecessary risk. By demanding zero-permission tools, merchants safeguard their data while maintaining uncompromising aesthetic quality.

M
Author & Founder

Maxime

Founder • Mailcraft

Mailcraft is an independent software project built for Shopify merchants who refuse to compromise their store security or pay monthly SaaS ransoms for static email templates. Built with verified zero scopes (scopes=""), it compiles beautiful typography directly into sovereign Shopify Liquid code that you own forever.

Continue Reading

Related Dispatches in Security