Audit report
ShipStation
Broad accessReach : broadSensitive Accessby ShipStation · Orders and shipping · Shopify App Store
Wherever you sell. However you ship. Exceptionally efficient.
Key insights
- ◆Built for Shopify badge present; 4.2 rating across 658 reviews indicates mainstream, well-known vendor.
- ◆Owned by Auctane (parent), with global ShipStation entities; privacy policy hosted at shipstationglobal.com.
- ◆Uses TLS for all data in transit; corporate site enforces HSTS (max-age=31536000; includeSubDomains) but only a frame-ancestors CSP.
- ◆Self-certified under EU-U.S. Data Privacy Framework and UK extension; no SOC2/ISO27001/PCI DSS attestations surfaced publicly.
Top findingsview all
- HighBroad write access to customers, products, orders, discounts and gift cards
Analysis summary
Wherever you sell. However you ship. Exceptionally efficient.
- ◆Built for Shopify badge present; 4.2 rating across 658 reviews indicates mainstream, well-known vendor.
- ◆Owned by Auctane (parent), with global ShipStation entities; privacy policy hosted at shipstationglobal.com.
- ◆Uses TLS for all data in transit; corporate site enforces HSTS (max-age=31536000; includeSubDomains) but only a frame-ancestors CSP.
- ◆Self-certified under EU-U.S. Data Privacy Framework and UK extension; no SOC2/ISO27001/PCI DSS attestations surfaced publicly.
- ◆Privacy policy discloses automated decision-making / ML for fraud, personalization, and CX automation, without naming a specific LLM provider.
- ◆No CVEs or confirmed breach incidents in public CVE databases at audit time; user-reported account takeovers exist but no platform-wide breach.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Reads customer name, email, phone, physical address and geolocation/IP - sensitive PII. |
write_customers | High | Edit access to customer records broadens blast radius beyond shipping needs. |
read_orders | High | Required for order fulfillment - reads order line items and shipping data. |
write_orders | High | Required to mark fulfillment, generate labels, update tracking - core function. |
write_products | Medium | Edit product data is broader than typically required for a shipping app. |
write_discounts | Medium | Discount edit access is not strictly required for shipping/fulfillment workflow. |
write_gift_cards | High | Gift card write access can be monetized by an attacker if the integration is compromised. |
read_shipping | Low | Required to compute rates and labels - core function. |
write_returns | Medium | Returns/exchanges category - moderate impact if abused. |
read_customersReads customer name, email, phone, physical address and geolocation/IP - sensitive PII.
write_customersEdit access to customer records broadens blast radius beyond shipping needs.
read_ordersRequired for order fulfillment - reads order line items and shipping data.
write_ordersRequired to mark fulfillment, generate labels, update tracking - core function.
write_productsEdit product data is broader than typically required for a shipping app.
write_discountsDiscount edit access is not strictly required for shipping/fulfillment workflow.
write_gift_cardsGift card write access can be monetized by an attacker if the integration is compromised.
read_shippingRequired to compute rates and labels - core function.
write_returnsReturns/exchanges category - moderate impact if abused.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- shipstation.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Enabled
HSTS enabled (max-age=31536000; includeSubDomains). CSP limited to frame-ancestors 'self' https://shippingeasy.com - no full directive set. Permissions-Policy and X-Frame-Options SAMEORIGIN set. Fronted by Cloudflare on WP Engine.
Compliance & certifications
Self-certified EU-U.S. DPF + UK extension. GDPR/CCPA aligned. No SOC2/ISO27001/PCI DSS attestations publicly listed per Rankiteo.
Privacy policyPublisher reputation
- Publisher
- ShipStation
- Verified Shopify Partner
- Yes
- Years active
- 15
- Other apps
- 0
- ●Community reports of account takeovers with unauthorized postage purchases
- ●Active phishing campaigns impersonating ShipStation targeting merchants