Audit report
ShippingEasy
Broad accessReach : broadSensitive Accessby ShippingEasy · Orders and shipping · Shopify App Store
Best rates. Easy set up. Endless support.
Key insights
- ◆ShippingEasy is owned by Auctane/Stamps.com, a major US shipping platform.
- ◆Primary domain shippingeasy.com uses HSTS (max-age=31536000; includeSubDomains) and several hardening headers.
- ◆No CSP header detected on root domain.
- ◆Privacy policy URL is published but inaccessible to automated retrieval (403).
Top findings
Analysis summary
Best rates. Easy set up. Endless support.
- ◆ShippingEasy is owned by Auctane/Stamps.com, a major US shipping platform.
- ◆Primary domain shippingeasy.com uses HSTS (max-age=31536000; includeSubDomains) and several hardening headers.
- ◆No CSP header detected on root domain.
- ◆Privacy policy URL is published but inaccessible to automated retrieval (403).
- ◆No CVEs or publicly disclosed breaches tied to ShippingEasy were found.
- ◆Rating 4.3/5 with 334 reviews; not 'Built for Shopify' certified.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Required to import orders for shipping label generation |
write_orders | High | Needed to update orders with tracking/fulfillment status |
read_customers | High | Required to obtain customer shipping addresses |
read_fulfillments | Medium | Needed to read existing fulfillment state |
write_fulfillments | High | Creates fulfillments and tracking on the store |
read_products | Medium | Needed to map SKU/weight info to label generation |
read_ordersRequired to import orders for shipping label generation
write_ordersNeeded to update orders with tracking/fulfillment status
read_customersRequired to obtain customer shipping addresses
read_fulfillmentsNeeded to read existing fulfillment state
write_fulfillmentsCreates fulfillments and tracking on the store
read_productsNeeded to map SKU/weight info to label generation
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- shippingeasy.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Missing
HSTS enabled with includeSubDomains, X-Frame-Options SAMEORIGIN, X-Content-Type-Options nosniff, Referrer-Policy strict-origin, Permissions-Policy set. Cloudflare-fronted. CSP header missing on root.
Compliance & certifications
Privacy policy URL published but returned 403 during automated fetch; compliance certifications not validated from public sources.
Privacy policyPublisher reputation
- Publisher
- ShippingEasy
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0