Updates on Security Incident

Latest information about the recent security incident affecting Qikify Sticky Add to Cart & Qikify Mga Menu, Navigation.

Status: Completely resolved · Last updated: 23 July, 2026

Summary

On 22 July, 2026, we identified a security incident affecting two of our apps, Qikify Sticky Add to Cart and Qikify Mega Menu & Navigation. Based on our current investigation, a small group of stores was affected.

We immediately addressed the issue, and the fix was completed within around 6.5 hours, from 11:10 PM (22 July, 2026) to 5:40 AM (23 July, 2026) (GMT+7).

Your store is not on the affected list, but we will continue to update this page with the latest information and remain committed to keeping your store's data and security protected.

This page provides the latest information about what happened, how we responded, and what you should do next. We will keep this page updated as we learn more.

What happened

What happened with Qikify Sticky Add to Cart:
Our app includes a setting that allows merchants to use custom HTML to provide greater flexibility when customizing the cart experience. Unfortunately, we identified a security vulnerability related to this feature that allowed unauthorized third parties to inject malicious scripts into the app settings.

In some affected stores, this could cause customers who clicked the Checkout button from the cart drawer to be redirected to an external page.

What happened with Qikify Mega Menu & Navigation:
This app has a similar custom HTML setting for the menu and navigation experience, which was affected by the same type of vulnerability.

In some affected stores, this could cause customers who clicked the Add to cart button to be redirected to an external advertising page.

--------

All of our other apps were NOT affected by this incident.

How we responded

Our Support and Engineering teams immediately began investigating and resolving the issue to minimize any potential impact.

After a thorough investigation, we successfully identified the root cause and fully resolved it within the system. We also performed a comprehensive review across affected stores and have removed all malicious scripts that were identified.

Based on our investigation to date, we found NO evidence that any merchant, store, customer, or shopper data was accessed, exposed, or leaked through the Qikify system as a result of this incident.

The incident was strictly limited to two customizable HTML content fields within the apps settings:

  • For Qikify Sticky Add to Cart: Empty cart text, Sticky cart message.
  • For Qikify Mega Menu, Navigation: Item title.

No other app settings, merchant configuration, Shopify store data, customer information, order data, payment information, or Shopify account credentials were affected or compromised.

Current status

We have shared our initial investigation findings with Shopify, and Shopify has confirmed receipt as part of their review process for restoring the app.

As part of Shopify's security requirements, we are now working closely with them to complete two additional independent security reviews:

  • Incident Report (IR): A detailed report explaining the incident, its root cause, impact, and remediation actions.
  • Vulnerability Assessment & Penetration Testing (VAPT): An independent security assessment to verify that the application is secure and free from additional vulnerabilities.

We've already engaged a specialized third-party security firm to perform both reviews, and the work is currently underway.

What we ask you to do

If you use Qikify Sticky Add to Cart or Qikify Mega Menu & Navigation, even though your store was not affected, we still recommend taking a moment as a precaution to review your store and confirm everything is working as expected:

  • Open your storefront.
  • Test the Add to Cart buttons.
  • Test the Checkout button to confirm it redirects to your normal Shopify checkout.

If you notice any unexpected behavior or have any concerns, please contact our support team immediately — we will investigate your store with the highest priority.

Contact us

Our support team is ready to assist with any questions or concerns.

If you have any questions or concerns, or notice anything unusual with your store, please reach out — we will respond right away:

Email: contact@qikify.com