Starship
starship / search / envios-mexico

Audit report

Envia Paqueteria

Broad accessReach : moderateSensitive Access

by Envía Paquetería · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

Shipping platform for Mexican and Colombian stores.

Key insights

  • Established shipping aggregator (DHL, FedEx, UPS, USPS, Redpack) with 454 reviews and 4.3 rating on Shopify App Store.
  • Not Built for Shopify certified.
  • Publisher operates own primary domain envia.com served behind Cloudflare with valid TLS.
  • OAuth scopes not enumerated on listing page extraction; shipping-label apps typically require read_orders, read_customers, read_shipping, and write_fulfillments.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Shipping platform for Mexican and Colombian stores.

Key insights
  • Established shipping aggregator (DHL, FedEx, UPS, USPS, Redpack) with 454 reviews and 4.3 rating on Shopify App Store.
  • Not Built for Shopify certified.
  • Publisher operates own primary domain envia.com served behind Cloudflare with valid TLS.
  • OAuth scopes not enumerated on listing page extraction; shipping-label apps typically require read_orders, read_customers, read_shipping, and write_fulfillments.
  • No public CVEs, breaches, or security incidents found attributable to Envia.com / Envia Paqueteria.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Required to fetch order details for label creation; typical for shipping apps.

read_customers
High

Needed to retrieve shipping addresses (PII) for label generation.

write_fulfillments
High

Required to mark orders fulfilled and attach tracking numbers.

read_shipping
Medium

Typical for accessing shipping zones / rates.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
envia.com
TLS grade
A
HSTS
Missing
CSP
Missing

HTTPS served via Cloudflare with valid certificate; strict-transport-security present but max-age=0 disables enforcement; no CSP header observed.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy hub exists; specific compliance certifications were not extractable from policy index page.

Privacy policy
Track record

Publisher reputation

Publisher
Envía Paquetería
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.