Starship
starship / search / shipstation

Audit report

ShipStation

Broad accessReach : broadSensitive Access

by ShipStation · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

Wherever you sell. However you ship. Exceptionally efficient.

Key insights

  • Built for Shopify badge present; 4.2 rating across 658 reviews indicates mainstream, well-known vendor.
  • Owned by Auctane (parent), with global ShipStation entities; privacy policy hosted at shipstationglobal.com.
  • Uses TLS for all data in transit; corporate site enforces HSTS (max-age=31536000; includeSubDomains) but only a frame-ancestors CSP.
  • Self-certified under EU-U.S. Data Privacy Framework and UK extension; no SOC2/ISO27001/PCI DSS attestations surfaced publicly.

Top findingsview all

  • High
    Broad write access to customers, products, orders, discounts and gift cards
Synthesis

Analysis summary

Wherever you sell. However you ship. Exceptionally efficient.

Key insights
  • Built for Shopify badge present; 4.2 rating across 658 reviews indicates mainstream, well-known vendor.
  • Owned by Auctane (parent), with global ShipStation entities; privacy policy hosted at shipstationglobal.com.
  • Uses TLS for all data in transit; corporate site enforces HSTS (max-age=31536000; includeSubDomains) but only a frame-ancestors CSP.
  • Self-certified under EU-U.S. Data Privacy Framework and UK extension; no SOC2/ISO27001/PCI DSS attestations surfaced publicly.
  • Privacy policy discloses automated decision-making / ML for fraud, personalization, and CX automation, without naming a specific LLM provider.
  • No CVEs or confirmed breach incidents in public CVE databases at audit time; user-reported account takeovers exist but no platform-wide breach.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Reads customer name, email, phone, physical address and geolocation/IP - sensitive PII.

write_customers
High

Edit access to customer records broadens blast radius beyond shipping needs.

read_orders
High

Required for order fulfillment - reads order line items and shipping data.

write_orders
High

Required to mark fulfillment, generate labels, update tracking - core function.

write_products
Medium

Edit product data is broader than typically required for a shipping app.

write_discounts
Medium

Discount edit access is not strictly required for shipping/fulfillment workflow.

write_gift_cards
High

Gift card write access can be monetized by an attacker if the integration is compromised.

read_shipping
Low

Required to compute rates and labels - core function.

write_returns
Medium

Returns/exchanges category - moderate impact if abused.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
shipstation.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

HSTS enabled (max-age=31536000; includeSubDomains). CSP limited to frame-ancestors 'self' https://shippingeasy.com - no full directive set. Permissions-Policy and X-Frame-Options SAMEORIGIN set. Fronted by Cloudflare on WP Engine.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Self-certified EU-U.S. DPF + UK extension. GDPR/CCPA aligned. No SOC2/ISO27001/PCI DSS attestations publicly listed per Rankiteo.

Privacy policy
Track record

Publisher reputation

Publisher
ShipStation
Verified Shopify Partner
Yes
Years active
15
Other apps
0
Past incidents
  • Community reports of account takeovers with unauthorized postage purchases
  • Active phishing campaigns impersonating ShipStation targeting merchants
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.