Audit report
AfterShip ‑ Track + Engage
TrustedReach : moderateSensitive Accessby AfterShip · Orders and shipping · Shopify App Store
Delight customers with branded tracking page & delivery update
Key insights
- ◆Built for Shopify badge present, Shopify has reviewed app against quality and performance criteria
- ◆Publisher AfterShip is a well-established logistics/post-purchase platform with SOC 2 Type II and ISO 27001 certifications (per publisher trust centre)
- ◆Strong network-layer security: HSTS, comprehensive CSP, Cloudflare WAF / bot challenge on publisher domain
- ◆Rating 4.5 with 1203 reviews, long-standing app, no public Shopify-side breach reports
Top findings
Analysis summary
Delight customers with branded tracking page & delivery update
- ◆Built for Shopify badge present, Shopify has reviewed app against quality and performance criteria
- ◆Publisher AfterShip is a well-established logistics/post-purchase platform with SOC 2 Type II and ISO 27001 certifications (per publisher trust centre)
- ◆Strong network-layer security: HSTS, comprehensive CSP, Cloudflare WAF / bot challenge on publisher domain
- ◆Rating 4.5 with 1203 reviews, long-standing app, no public Shopify-side breach reports
- ◆AI-powered estimated delivery dates feature implies some ML/AI processing of order/shipment data
- ◆One disclosed CVE-2025-58201 affects the WordPress (WooCommerce) plugin only, not the Shopify build
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Required to read order data for tracking lookups |
read_fulfillments | Medium | Required to read existing fulfillments and tracking info |
write_fulfillments | High | Needed to push tracking numbers / update fulfillments, justified by core feature |
read_customers | High | Required for branded notifications and customer-facing tracking pages |
read_shipping | Medium | Read shipping rates / zones for delivery estimates |
read_ordersRequired to read order data for tracking lookups
read_fulfillmentsRequired to read existing fulfillments and tracking info
write_fulfillmentsNeeded to push tracking numbers / update fulfillments, justified by core feature
read_customersRequired for branded notifications and customer-facing tracking pages
read_shippingRead shipping rates / zones for delivery estimates
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- aftership.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Enabled
Strict CSP with default-src 'none', nonce-based scripts, Cloudflare-managed bot challenge in front of origin. HSTS max-age 1 year with includeSubDomains.
Compliance & certifications
Privacy policy returned 403 to automated fetch (Cloudflare challenge). Trust Centre and DPA pages are public. SOC 2 Type II and ISO 27001 referenced on publisher trust centre.
Privacy policyPublisher reputation
- Publisher
- AfterShip
- Verified Shopify Partner
- Yes
- Years active
- 13
- Other apps
- 5
- ●CVE