Starship
starship / search / shippingeasy

Audit report

ShippingEasy

Broad accessReach : broadSensitive Access

by ShippingEasy · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

Best rates. Easy set up. Endless support.

Key insights

  • ShippingEasy is owned by Auctane/Stamps.com, a major US shipping platform.
  • Primary domain shippingeasy.com uses HSTS (max-age=31536000; includeSubDomains) and several hardening headers.
  • No CSP header detected on root domain.
  • Privacy policy URL is published but inaccessible to automated retrieval (403).

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Best rates. Easy set up. Endless support.

Key insights
  • ShippingEasy is owned by Auctane/Stamps.com, a major US shipping platform.
  • Primary domain shippingeasy.com uses HSTS (max-age=31536000; includeSubDomains) and several hardening headers.
  • No CSP header detected on root domain.
  • Privacy policy URL is published but inaccessible to automated retrieval (403).
  • No CVEs or publicly disclosed breaches tied to ShippingEasy were found.
  • Rating 4.3/5 with 334 reviews; not 'Built for Shopify' certified.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Required to import orders for shipping label generation

write_orders
High

Needed to update orders with tracking/fulfillment status

read_customers
High

Required to obtain customer shipping addresses

read_fulfillments
Medium

Needed to read existing fulfillment state

write_fulfillments
High

Creates fulfillments and tracking on the store

read_products
Medium

Needed to map SKU/weight info to label generation

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
shippingeasy.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS enabled with includeSubDomains, X-Frame-Options SAMEORIGIN, X-Content-Type-Options nosniff, Referrer-Policy strict-origin, Permissions-Policy set. Cloudflare-fronted. CSP header missing on root.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy URL published but returned 403 during automated fetch; compliance certifications not validated from public sources.

Privacy policy
Track record

Publisher reputation

Publisher
ShippingEasy
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.