Audit report
OrderlyPrint
Broad accessReach : broadSensitive Accessby FORSBERG+two · Orders and shipping · Shopify App Store
Pick, pack, invoice and fulfill faster.
Key insights
- ◆Established Danish vendor (FORSBERG+two ApS) operating since 2012 with strong rating (4.8/5, 70 reviews).
- ◆Bulk order processing app with broad access to customer PII, order data, and editing permissions.
- ◆Publisher domain hosted on Shopify with strong network security: HSTS (max-age ~91 days), CSP with frame-ancestors none, upgrade-insecure-requests, X-Content-Type-Options, X-Frame-Options DENY.
- ◆Data residency split between US and Denmark; GDPR-aligned for EU clients via DPA.
Top findings
Analysis summary
Pick, pack, invoice and fulfill faster.
- ◆Established Danish vendor (FORSBERG+two ApS) operating since 2012 with strong rating (4.8/5, 70 reviews).
- ◆Bulk order processing app with broad access to customer PII, order data, and editing permissions.
- ◆Publisher domain hosted on Shopify with strong network security: HSTS (max-age ~91 days), CSP with frame-ancestors none, upgrade-insecure-requests, X-Content-Type-Options, X-Frame-Options DENY.
- ◆Data residency split between US and Denmark; GDPR-aligned for EU clients via DPA.
- ◆No known CVEs, breaches, or security incidents tied to FORSBERG+two or OrderlyPrint.
- ◆No 'Built for Shopify' badge; no SOC2/ISO27001 certifications publicly disclosed.
- ◆Good data minimization: 30-day product data retention, 60-day analytics retention.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Required to read order data for bulk invoice/packing slip generation. |
write_orders | High | Listing indicates order editing permissions for tagging and fulfillment workflows. |
read_customers | High | Accesses customer names, emails, and addresses for invoice rendering. |
read_products | Medium | Needed for product line items on invoices and pick lists. |
read_fulfillments | Medium | Needed for packing slips, shipping labels and fulfillment workflows. |
write_fulfillments | High | Required to mark orders fulfilled in bulk. |
read_ordersRequired to read order data for bulk invoice/packing slip generation.
write_ordersListing indicates order editing permissions for tagging and fulfillment workflows.
read_customersAccesses customer names, emails, and addresses for invoice rendering.
read_productsNeeded for product line items on invoices and pick lists.
read_fulfillmentsNeeded for packing slips, shipping labels and fulfillment workflows.
write_fulfillmentsRequired to mark orders fulfilled in bulk.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- forsbergplustwo.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Enabled
HSTS max-age ~91 days; CSP includes frame-ancestors 'none', block-all-mixed-content, upgrade-insecure-requests; X-Frame-Options DENY; X-Content-Type-Options nosniff; site fronted by Cloudflare/Shopify.
Compliance & certifications
GDPR compliance claimed via DPA for EU customers; no SOC2/ISO27001/PCI/HIPAA certifications publicly disclosed.
Privacy policyPublisher reputation
- Publisher
- FORSBERG+two
- Verified Shopify Partner
- No
- Years active
- 14
- Other apps
- 0