Starship
starship / search / fancourier-integration-by-webshopassist

Audit report

FanCourier Integration

Broad accessReach : moderateSensitive Access

by wsassist · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

Automatically creates and tracks FanCourier AWBs

Key insights

  • Small, niche Romania/EU-focused shipping integration publisher with one Shopify app since 2018; low public profile and no known breaches or CVEs.
  • Sits behind Cloudflare with HTTPS, HSTS, x-frame-options=SAMEORIGIN, x-content-type-options=nosniff, but no CSP header was returned.
  • Privacy policy is GDPR-oriented (EU/EEA-first storage) with explicit SCC mention for transfers; no AI/LLM usage declared.
  • Scope surface is moderate (customer PII + Online Store scripts), broader than the minimum needed for label printing.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Automatically creates and tracks FanCourier AWBs

Key insights
  • Small, niche Romania/EU-focused shipping integration publisher with one Shopify app since 2018; low public profile and no known breaches or CVEs.
  • Sits behind Cloudflare with HTTPS, HSTS, x-frame-options=SAMEORIGIN, x-content-type-options=nosniff, but no CSP header was returned.
  • Privacy policy is GDPR-oriented (EU/EEA-first storage) with explicit SCC mention for transfers; no AI/LLM usage declared.
  • Scope surface is moderate (customer PII + Online Store scripts), broader than the minimum needed for label printing.
  • No verified Shopify Partner badge or Built for Shopify badge; small review count (6) limits social signal.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Customer name, email, phone, address, IP and browser/OS info, sensitive PII relevant to a shipping app but broad.

read_orders
High

Order, fulfillment and shipping details required to print AWB labels.

write_fulfillments
High

Creates fulfillments and writes tracking numbers back to the store.

read_products
Medium

Reads products/inventory for package weight and dimensions.

read_inventory
Medium

Reads stock/inventory for shipment preparation.

read_shipping
Medium

Reads shipping zones and rates to drive label creation.

read_script_tags
Medium

Access to Online Store scripts; broader than strictly needed for an AWB integration.

read_staff_information
Low

Store owner contact info used for account setup and support.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
webshopassist.com
TLS grade
unknown
HSTS
Enabled
CSP
Missing

HTTPS via Cloudflare with HSTS max-age=15552000 (no includeSubDomains/preload), x-frame-options=SAMEORIGIN, x-content-type-options=nosniff, referrer-policy=strict-origin-when-cross-origin. No Content-Security-Policy header observed.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy references Regulation 679/2016 (GDPR) and Standard Contractual Clauses for transfers outside EU/EEA. No SOC2/ISO27001/PCI/HIPAA attestations declared.

Privacy policy
Track record

Publisher reputation

Publisher
wsassist
Verified Shopify Partner
No
Years active
8
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.