Be Aware of Potential Risks When Using Free Facebook Pixel App

Topic summary

A Shopify store owner discovered a serious security vulnerability after installing a free Facebook Pixel app.

The Security Issue:

  • After approximately one month of use, unusual data and fake events began appearing in their Facebook Pixel analytics
  • Upon inspecting the website’s front-end source code (Ctrl+U), they found their Facebook Pixel Access Token was exposed directly in the theme code
  • This represents a significant security breach, allowing unauthorized access to their pixel data

Actions Taken:

  • Immediately removed the app and secured their Facebook Pixel token
  • The user is seeking guidance on how to report this issue to Shopify
  • Questions why this app has a “Built for Shopify” badge despite the security flaw

Key Takeaway:
Free Facebook Pixel apps may not prioritize data security. Store owners should inspect their site’s source code to verify tokens aren’t exposed, as this could allow malicious actors to inject fake events and compromise analytics data.

Status: Unresolved - awaiting response on reporting procedures

Summarized with AI on November 9. AI used: claude-sonnet-4-5-20250929.

[Note: I apologize if my post was not clear or incorrect place.]

Hey everyone!

I wanted to share an important information that I recently came across regarding the use of some free apps for Shopify Facebook Pixel.

Risks of exposing Facebook Pixel Access Token :worried:

Let me share a personal experience to highlight this point. A while ago, I had the opportunity to try out a free app for Facebook Pixel on Shopify. Initially, everything seemed fine, but after approximately a month of using the app, I started noticing unusual data and fake events being recorded. Concerned about this unexpected behavior, I decided to investigate further.

When inspecting the source code of my website’s front-end (by pressing Ctrl+U), I was shocked to discover that my Facebook Pixel token was exposed in the theme’s code. (please see my screenshot)

This was a significant security breach, as it allowed unauthorized access to my pixel data. I immediately removed the app and took steps to secure my Facebook Pixel token. Experiencing such a situation was terrible and awful, highlighting the risks associated with using it that may not prioritize data security.

I would like cc for @Shopify_77 could you please review my case and this app? I didn’t know why this app can have a badge “Built for Shopify”???

:scream:

2 Likes

How can I report to Shopify about this issue :disappointed_face: