Starship
starship / search / abf-ltl-freight-quotes

Audit report

ABF LTL Freight Quotes

WatchReach : limited

by Eniture Technology · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Watch
Executive summary

Get accurate LTL freight quotes at checkout

Key insights

  • Publisher Eniture Technology produces multi-platform shipping/freight plugins (Shopify, WordPress, Magento)
  • A confirmed unauthenticated SQL injection CVE (CVE-2024-13485) exists in the same-named WordPress edition of this product
  • Shopify app listing has 0 reviews and is not 'Built for Shopify' certified
  • Publisher website has HSTS but no CSP

Top findingsview all

  • High
    Publisher has prior unauthenticated SQL injection CVE in sibling product
Synthesis

Analysis summary

Get accurate LTL freight quotes at checkout

Key insights
  • Publisher Eniture Technology produces multi-platform shipping/freight plugins (Shopify, WordPress, Magento)
  • A confirmed unauthenticated SQL injection CVE (CVE-2024-13485) exists in the same-named WordPress edition of this product
  • Shopify app listing has 0 reviews and is not 'Built for Shopify' certified
  • Publisher website has HSTS but no CSP
  • Privacy policy is sparse on data residency, sub-processors, and retention
  • App functionality is narrow: fetching ABF freight rate quotes at checkout, read-only shipping data use case

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Medium

Likely needed to read product weight/dimensions for freight rating; not explicitly declared in listing but inferred from shipping-rate app pattern

read_shipping
Medium

Required to register Carrier Service for real-time rate quotes at checkout (inferred; not explicitly listed)

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
eniture.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS enabled (max-age=31536000; includeSubDomains). X-Frame-Options SAMEORIGIN, X-Content-Type-Options nosniff, Permissions-Policy restrictive. No Content-Security-Policy header. Apache/2.4.62 on Amazon Linux (AWS-hosted).

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists but lacks explicit compliance certification claims, sub-processor list, retention periods, and data residency disclosures.

Privacy policy
Track record

Publisher reputation

Publisher
Eniture Technology
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
  • CVE
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.