Audit report
MyParcel BE
Broad accessReach : broadSensitive Accessby MyParcel · Orders and shipping · Shopify App Store
Voordelig en gemakkelijk pakketten versturen met SendMyParcel
Key insights
- ◆Carrier/shipping label app for Belgium operated by MyParcel (Dutch/Belgian carrier integrator).
- ◆Low review volume (10 reviews, rating 4.3) suggesting niche regional usage.
- ◆Publisher primary domain is sendmyparcel.be (WordPress on nginx, PHP 8.1.34).
- ◆App Store page links the generic Shopify privacy URL rather than a publisher-specific privacy page.
Top findings
Analysis summary
Voordelig en gemakkelijk pakketten versturen met SendMyParcel
- ◆Carrier/shipping label app for Belgium operated by MyParcel (Dutch/Belgian carrier integrator).
- ◆Low review volume (10 reviews, rating 4.3) suggesting niche regional usage.
- ◆Publisher primary domain is sendmyparcel.be (WordPress on nginx, PHP 8.1.34).
- ◆App Store page links the generic Shopify privacy URL rather than a publisher-specific privacy page.
- ◆No publicly disclosed Shopify-app-specific breaches or CVEs found for MyParcel BE.
- ◆One historical CVE exists for the same publisher's WordPress plugin (reflected XSS, fixed in 4.24.2).
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Required to create shipping labels for Shopify orders; gives visibility to customer PII (name/address). |
write_orders | High | Needed to attach tracking numbers/fulfillments; allows modifying orders. |
read_customers | High | Address details required for label printing - PII exposure. |
write_fulfillments | Medium | Required to mark orders fulfilled after label creation. |
read_products | Low | Needed for item weight/dimensions on customs declarations. |
read_ordersRequired to create shipping labels for Shopify orders; gives visibility to customer PII (name/address).
write_ordersNeeded to attach tracking numbers/fulfillments; allows modifying orders.
read_customersAddress details required for label printing - PII exposure.
write_fulfillmentsRequired to mark orders fulfilled after label creation.
read_productsNeeded for item weight/dimensions on customs declarations.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- sendmyparcel.be
- TLS grade
- A
- HSTS
- Missing
- CSP
- Missing
HTTPS valid (HTTP/2 200, nginx). No HSTS or CSP headers detected on root page. x-powered-by leaks PHP/8.1.34.
Compliance & certifications
EU/BE operator, DPA referenced in consolidated policy page; explicit SOC2/ISO27001/PCI certifications not advertised.
Privacy policyPublisher reputation
- Publisher
- MyParcel
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0