Starship
starship / search / netparcel

Audit report

netParcel

TrustedReach : moderateSensitive Access

by netParcel · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Trusted
Executive summary

Save up to 70% via UPS, Purolator, FedEx, and DHL.

Key insights

  • Established Canadian shipping aggregator (UPS, Purolator, DHL, Canada Post) with 4.8 stars and 171 reviews
  • Publisher domain netparcel.com is fronted by Cloudflare with valid HTTPS but no HSTS/CSP headers exposed
  • Privacy policy claims PCI-DSS compliance for payment data but is otherwise generic
  • No public record of CVE, breach, or security incident tied to netParcel

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Save up to 70% via UPS, Purolator, FedEx, and DHL.

Key insights
  • Established Canadian shipping aggregator (UPS, Purolator, DHL, Canada Post) with 4.8 stars and 171 reviews
  • Publisher domain netparcel.com is fronted by Cloudflare with valid HTTPS but no HSTS/CSP headers exposed
  • Privacy policy claims PCI-DSS compliance for payment data but is otherwise generic
  • No public record of CVE, breach, or security incident tied to netParcel
  • OAuth scopes not enumerated in App Store listing snapshot; shipping apps typically require read_orders/read_shipping/write_shipping

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Typical for shipping apps to access order data for rate calculation and label generation; scope not explicitly confirmed on listing.

read_shipping
Medium

Required to read shipping zones and rates for carrier comparison.

write_shipping
High

Likely needed to create shipping labels and update fulfillment status.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
netparcel.com
TLS grade
A
HSTS
Missing
CSP
Missing

Cloudflare-fronted WordPress site with valid HTTPS (HTTP/2, 301 to www). No HSTS or CSP headers observed in response.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Pass

Privacy policy explicitly references PCI-DSS adherence for payment data; no other certifications named.

Privacy policy
Track record

Publisher reputation

Publisher
netParcel
Verified Shopify Partner
No
Years active
13
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.