Starship
starship / search / orderlyprint

Audit report

OrderlyPrint

Broad accessReach : broadSensitive Access

by FORSBERG+two · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

Pick, pack, invoice and fulfill faster.

Key insights

  • Established Danish vendor (FORSBERG+two ApS) operating since 2012 with strong rating (4.8/5, 70 reviews).
  • Bulk order processing app with broad access to customer PII, order data, and editing permissions.
  • Publisher domain hosted on Shopify with strong network security: HSTS (max-age ~91 days), CSP with frame-ancestors none, upgrade-insecure-requests, X-Content-Type-Options, X-Frame-Options DENY.
  • Data residency split between US and Denmark; GDPR-aligned for EU clients via DPA.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Pick, pack, invoice and fulfill faster.

Key insights
  • Established Danish vendor (FORSBERG+two ApS) operating since 2012 with strong rating (4.8/5, 70 reviews).
  • Bulk order processing app with broad access to customer PII, order data, and editing permissions.
  • Publisher domain hosted on Shopify with strong network security: HSTS (max-age ~91 days), CSP with frame-ancestors none, upgrade-insecure-requests, X-Content-Type-Options, X-Frame-Options DENY.
  • Data residency split between US and Denmark; GDPR-aligned for EU clients via DPA.
  • No known CVEs, breaches, or security incidents tied to FORSBERG+two or OrderlyPrint.
  • No 'Built for Shopify' badge; no SOC2/ISO27001 certifications publicly disclosed.
  • Good data minimization: 30-day product data retention, 60-day analytics retention.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Required to read order data for bulk invoice/packing slip generation.

write_orders
High

Listing indicates order editing permissions for tagging and fulfillment workflows.

read_customers
High

Accesses customer names, emails, and addresses for invoice rendering.

read_products
Medium

Needed for product line items on invoices and pick lists.

read_fulfillments
Medium

Needed for packing slips, shipping labels and fulfillment workflows.

write_fulfillments
High

Required to mark orders fulfilled in bulk.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
forsbergplustwo.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

HSTS max-age ~91 days; CSP includes frame-ancestors 'none', block-all-mixed-content, upgrade-insecure-requests; X-Frame-Options DENY; X-Content-Type-Options nosniff; site fronted by Cloudflare/Shopify.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR compliance claimed via DPA for EU customers; no SOC2/ISO27001/PCI/HIPAA certifications publicly disclosed.

Privacy policy
Track record

Publisher reputation

Publisher
FORSBERG+two
Verified Shopify Partner
No
Years active
14
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.