Audit report
Shipping Rates Calculator Plus
TrustedReach : moderateSensitive Accessby Code Black Belt · Store design · Shopify App Store
A shipping rates calculator with geolocation on your cart page
Key insights
- ◆Built for Shopify badge present (4.7 stars, 231 reviews) indicates Shopify-vetted quality + perf standards
- ◆Read-only scopes only; no write_* permissions requested
- ◆Publisher domain on Shopify-hosted site behind Cloudflare with HSTS + CSP headers
- ◆Data automatically deleted 30 days after app uninstall
Top findings
Analysis summary
A shipping rates calculator with geolocation on your cart page
- ◆Built for Shopify badge present (4.7 stars, 231 reviews) indicates Shopify-vetted quality + perf standards
- ◆Read-only scopes only; no write_* permissions requested
- ◆Publisher domain on Shopify-hosted site behind Cloudflare with HSTS + CSP headers
- ◆Data automatically deleted 30 days after app uninstall
- ◆No CVEs, breaches, or security incidents found in public sources for Code Black Belt
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers_geolocation_ip | Medium | Geolocation + IP used to compute carrier shipping rates for the cart visitor; functionally necessary for the app |
read_shop_owner_info | Medium | Store owner name/email/phone/address, declared but broader than strictly required for shipping-rate display |
read_orders_shipping | Medium | Order shipping information needed to compute and display real-time rates |
read_themes | Low | Required to inject the cart widget into the storefront theme |
read_locales | Low | Locales and translations used for multi-language storefronts |
read_customers_geolocation_ipGeolocation + IP used to compute carrier shipping rates for the cart visitor; functionally necessary for the app
read_shop_owner_infoStore owner name/email/phone/address, declared but broader than strictly required for shipping-rate display
read_orders_shippingOrder shipping information needed to compute and display real-time rates
read_themesRequired to inject the cart widget into the storefront theme
read_localesLocales and translations used for multi-language storefronts
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- web.codeblackbelt.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Enabled
Cloudflare-fronted Shopify storefront; HSTS max-age ~91 days; CSP includes frame-ancestors 'none' + block-all-mixed-content + upgrade-insecure-requests; X-Frame-Options DENY
Compliance & certifications
Privacy policy explicitly claims GDPR + CCPA do not apply because the app allegedly does not process personal data; no SOC2/ISO27001/PCI/HIPAA attestation claimed. Data retention: auto-deleted 30 days after uninstall.
Privacy policyPublisher reputation
- Publisher
- Code Black Belt
- Verified Shopify Partner
- Yes
- Years active
- 9
- Other apps
- 8