Starship
starship / search / estes-ltl-freight-quotes

Audit report

Estes LTL Freight Quotes

WatchReach : moderate

by Eniture Technology · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Watch
Executive summary

Get accurate LTL freight quotes at checkout

Key insights

  • Publisher (Eniture Technology) has a publicly disclosed CVE (CVE-2026-34899) in a sibling LTL Freight Quotes product (April 2026, Missing Authorization, CVSS 5.3)
  • Shipping/carrier integration app - quote-time only, no observed write_orders scope declared on listing
  • Eniture domain has HSTS but lacks CSP header
  • Privacy policy URL is published; content not parseable in this run, so GDPR/SOC2/CCPA status remains unverified

Top findingsview all

  • High
    Missing Authorization vulnerability (CVE-2026-34899) in related Eniture LTL product
Synthesis

Analysis summary

Get accurate LTL freight quotes at checkout

Key insights
  • Publisher (Eniture Technology) has a publicly disclosed CVE (CVE-2026-34899) in a sibling LTL Freight Quotes product (April 2026, Missing Authorization, CVSS 5.3)
  • Shipping/carrier integration app - quote-time only, no observed write_orders scope declared on listing
  • Eniture domain has HSTS but lacks CSP header
  • Privacy policy URL is published; content not parseable in this run, so GDPR/SOC2/CCPA status remains unverified
  • Only 3 reviews with 5.0 rating - limited public usage signal
  • No 'Built for Shopify' badge

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_shipping
Low

LTL freight quote apps typically require shipping/carrier configuration access to register rate-quote endpoints

read_orders
Medium

Likely required to compute freight quotes from cart/order details (inferred; not explicitly declared on listing page)

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
eniture.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS max-age=31536000 with includeSubDomains; X-Frame-Options=SAMEORIGIN, X-Content-Type-Options=nosniff, Permissions-Policy locks down geo/mic/cam/payment; no Content-Security-Policy header set; Apache/2.4.62 on Amazon Linux (AWS)

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy URL published but content not parseable in this audit; certifications unverified

Privacy policy
Track record

Publisher reputation

Publisher
Eniture Technology
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
  • 2026-04-07 · CVE
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.