Audit report
Shippo
Broad accessReach : broadSensitive Accessby Shippo · Orders and shipping · Shopify App Store
Cheap and Easy Shipping - Get Live in Five Minutes!
Key insights
- ◆Shippo (Popout, Inc.) is a well-established multi-carrier shipping platform serving USPS, UPS, DHL Express, FedEx.
- ◆Publisher domain goshippo.com is served via Cloudflare with valid TLS; privacy portal is hosted separately at privacy.goshippo.com.
- ◆No CVE entries found in NVD/Snyk for the Shippo NPM client or platform.
- ◆No formally disclosed breach; one unverified Trustpilot complaint about a support-side data disclosure.
Top findings
Analysis summary
Cheap and Easy Shipping - Get Live in Five Minutes!
- ◆Shippo (Popout, Inc.) is a well-established multi-carrier shipping platform serving USPS, UPS, DHL Express, FedEx.
- ◆Publisher domain goshippo.com is served via Cloudflare with valid TLS; privacy portal is hosted separately at privacy.goshippo.com.
- ◆No CVE entries found in NVD/Snyk for the Shippo NPM client or platform.
- ◆No formally disclosed breach; one unverified Trustpilot complaint about a support-side data disclosure.
- ◆App Store rating 4.2 over ~300 reviews; categorized under Shipping; not Built for Shopify.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Required to import orders for label creation; exposes customer/order PII. |
write_orders | High | Needed to update fulfillment status back to the store. |
read_customers | High | Needed for ship-to addresses and contact info. |
read_fulfillments | Medium | Reads existing fulfillment state. |
write_fulfillments | High | Creates fulfillments after label purchase; legitimate but write-class. |
read_shipping | Medium | Reads store shipping configuration. |
read_products | Low | Used to determine package weight/dimensions for rating. |
read_ordersRequired to import orders for label creation; exposes customer/order PII.
write_ordersNeeded to update fulfillment status back to the store.
read_customersNeeded for ship-to addresses and contact info.
read_fulfillmentsReads existing fulfillment state.
write_fulfillmentsCreates fulfillments after label purchase; legitimate but write-class.
read_shippingReads store shipping configuration.
read_productsUsed to determine package weight/dimensions for rating.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- goshippo.com
- TLS grade
- A
- HSTS
- Missing
- CSP
- Missing
Fronted by Cloudflare with HTTP/2 and valid TLS; no HSTS or CSP headers observed on root HEAD response.
Compliance & certifications
Privacy notice hosted at privacy.goshippo.com but page content not extractable via fetch; certifications unverified from public privacy page snippet.
Privacy policyPublisher reputation
- Publisher
- Shippo
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0