Starship
starship / search / aftership

Audit report

AfterShip ‑ Track + Engage

TrustedReach : moderateSensitive Access

by AfterShip · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Trusted
Executive summary

Delight customers with branded tracking page & delivery update

Key insights

  • Built for Shopify badge present, Shopify has reviewed app against quality and performance criteria
  • Publisher AfterShip is a well-established logistics/post-purchase platform with SOC 2 Type II and ISO 27001 certifications (per publisher trust centre)
  • Strong network-layer security: HSTS, comprehensive CSP, Cloudflare WAF / bot challenge on publisher domain
  • Rating 4.5 with 1203 reviews, long-standing app, no public Shopify-side breach reports

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Delight customers with branded tracking page & delivery update

Key insights
  • Built for Shopify badge present, Shopify has reviewed app against quality and performance criteria
  • Publisher AfterShip is a well-established logistics/post-purchase platform with SOC 2 Type II and ISO 27001 certifications (per publisher trust centre)
  • Strong network-layer security: HSTS, comprehensive CSP, Cloudflare WAF / bot challenge on publisher domain
  • Rating 4.5 with 1203 reviews, long-standing app, no public Shopify-side breach reports
  • AI-powered estimated delivery dates feature implies some ML/AI processing of order/shipment data
  • One disclosed CVE-2025-58201 affects the WordPress (WooCommerce) plugin only, not the Shopify build

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Required to read order data for tracking lookups

read_fulfillments
Medium

Required to read existing fulfillments and tracking info

write_fulfillments
High

Needed to push tracking numbers / update fulfillments, justified by core feature

read_customers
High

Required for branded notifications and customer-facing tracking pages

read_shipping
Medium

Read shipping rates / zones for delivery estimates

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
aftership.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

Strict CSP with default-src 'none', nonce-based scripts, Cloudflare-managed bot challenge in front of origin. HSTS max-age 1 year with includeSubDomains.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Pass
ISO 27001 Pass
PCI DSS Fail

Privacy policy returned 403 to automated fetch (Cloudflare challenge). Trust Centre and DPA pages are public. SOC 2 Type II and ISO 27001 referenced on publisher trust centre.

Privacy policy
Track record

Publisher reputation

Publisher
AfterShip
Verified Shopify Partner
Yes
Years active
13
Other apps
5
Past incidents
  • CVE
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.