Audit report
CSL Nordic Shipping Options
Broad accessReach : limitedby CSL Consult · Orders and shipping · Shopify App Store
Offer your customers GLS, PostNord and Bring pickup points.
Key insights
- ◆Danish publisher CSL Consult; app delivers Nordic carrier pickup points (GLS, PostNord, Bring, Dao).
- ◆Privacy policy is a 2022 static PDF served over HTTP, no enumerated sub-processors or retention.
- ◆Publisher domain csl-consult.dk is a WordPress site (PHP 8.5.6) lacking HSTS/CSP, TLS itself is valid.
- ◆Scope manifest not exposed on listing page; shipping-rate apps typically require carrier-service + read_shipping.
Top findings
Analysis summary
Offer your customers GLS, PostNord and Bring pickup points.
- ◆Danish publisher CSL Consult; app delivers Nordic carrier pickup points (GLS, PostNord, Bring, Dao).
- ◆Privacy policy is a 2022 static PDF served over HTTP, no enumerated sub-processors or retention.
- ◆Publisher domain csl-consult.dk is a WordPress site (PHP 8.5.6) lacking HSTS/CSP, TLS itself is valid.
- ◆Scope manifest not exposed on listing page; shipping-rate apps typically require carrier-service + read_shipping.
- ◆No public CVEs, breaches, or security incidents tied to CSL Consult; not Built for Shopify.
- ◆No indication of LLM/AI usage in product or policy.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
undisclosed_on_listing | Info | App Store listing did not expose the OAuth scope block; typical shipping-rate apps need read_shipping and carrier_service registration. |
undisclosed_on_listingApp Store listing did not expose the OAuth scope block; typical shipping-rate apps need read_shipping and carrier_service registration.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- csl-consult.dk
- TLS grade
- A
- HSTS
- Missing
- CSP
- Missing
HTTPS valid (200 OK) but no HSTS or CSP; WordPress origin discloses PHP/8.5.6 via X-Powered-By; privacy policy served over plain HTTP on subdomain.
Compliance & certifications
PDF privacy notice exists but does not enumerate certifications or explicitly claim GDPR compliance in extractable text; EU-based publisher implies GDPR scope by jurisdiction.
Privacy policyPublisher reputation
- Publisher
- CSL Consult
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0