Audit report
Envia Paqueteria
Broad accessReach : moderateSensitive Accessby Envía Paquetería · Orders and shipping · Shopify App Store
Shipping platform for Mexican and Colombian stores.
Key insights
- ◆Established shipping aggregator (DHL, FedEx, UPS, USPS, Redpack) with 454 reviews and 4.3 rating on Shopify App Store.
- ◆Not Built for Shopify certified.
- ◆Publisher operates own primary domain envia.com served behind Cloudflare with valid TLS.
- ◆OAuth scopes not enumerated on listing page extraction; shipping-label apps typically require read_orders, read_customers, read_shipping, and write_fulfillments.
Top findings
Analysis summary
Shipping platform for Mexican and Colombian stores.
- ◆Established shipping aggregator (DHL, FedEx, UPS, USPS, Redpack) with 454 reviews and 4.3 rating on Shopify App Store.
- ◆Not Built for Shopify certified.
- ◆Publisher operates own primary domain envia.com served behind Cloudflare with valid TLS.
- ◆OAuth scopes not enumerated on listing page extraction; shipping-label apps typically require read_orders, read_customers, read_shipping, and write_fulfillments.
- ◆No public CVEs, breaches, or security incidents found attributable to Envia.com / Envia Paqueteria.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Required to fetch order details for label creation; typical for shipping apps. |
read_customers | High | Needed to retrieve shipping addresses (PII) for label generation. |
write_fulfillments | High | Required to mark orders fulfilled and attach tracking numbers. |
read_shipping | Medium | Typical for accessing shipping zones / rates. |
read_ordersRequired to fetch order details for label creation; typical for shipping apps.
read_customersNeeded to retrieve shipping addresses (PII) for label generation.
write_fulfillmentsRequired to mark orders fulfilled and attach tracking numbers.
read_shippingTypical for accessing shipping zones / rates.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- envia.com
- TLS grade
- A
- HSTS
- Missing
- CSP
- Missing
HTTPS served via Cloudflare with valid certificate; strict-transport-security present but max-age=0 disables enforcement; no CSP header observed.
Compliance & certifications
Privacy policy hub exists; specific compliance certifications were not extractable from policy index page.
Privacy policyPublisher reputation
- Publisher
- Envía Paquetería
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0