Starship
starship / search / nordic-shipping-options

Audit report

CSL Nordic Shipping Options

Broad accessReach : limited

by CSL Consult · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

Offer your customers GLS, PostNord and Bring pickup points.

Key insights

  • Danish publisher CSL Consult; app delivers Nordic carrier pickup points (GLS, PostNord, Bring, Dao).
  • Privacy policy is a 2022 static PDF served over HTTP, no enumerated sub-processors or retention.
  • Publisher domain csl-consult.dk is a WordPress site (PHP 8.5.6) lacking HSTS/CSP, TLS itself is valid.
  • Scope manifest not exposed on listing page; shipping-rate apps typically require carrier-service + read_shipping.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Offer your customers GLS, PostNord and Bring pickup points.

Key insights
  • Danish publisher CSL Consult; app delivers Nordic carrier pickup points (GLS, PostNord, Bring, Dao).
  • Privacy policy is a 2022 static PDF served over HTTP, no enumerated sub-processors or retention.
  • Publisher domain csl-consult.dk is a WordPress site (PHP 8.5.6) lacking HSTS/CSP, TLS itself is valid.
  • Scope manifest not exposed on listing page; shipping-rate apps typically require carrier-service + read_shipping.
  • No public CVEs, breaches, or security incidents tied to CSL Consult; not Built for Shopify.
  • No indication of LLM/AI usage in product or policy.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

undisclosed_on_listing
Info

App Store listing did not expose the OAuth scope block; typical shipping-rate apps need read_shipping and carrier_service registration.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
csl-consult.dk
TLS grade
A
HSTS
Missing
CSP
Missing

HTTPS valid (200 OK) but no HSTS or CSP; WordPress origin discloses PHP/8.5.6 via X-Powered-By; privacy policy served over plain HTTP on subdomain.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

PDF privacy notice exists but does not enumerate certifications or explicitly claim GDPR compliance in extractable text; EU-based publisher implies GDPR scope by jurisdiction.

Privacy policy
Track record

Publisher reputation

Publisher
CSL Consult
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.