Starship
starship / search / shipup

Audit report

Shipup

Broad accessReach : broadSensitive Access

by Shipup · Marketing · Shopify App Store

Marketing
Risk level
Broad access
Executive summary

Shipping notifications and Tracking Page

Key insights

  • French publisher (Shipup SAS) with EU/GDPR-first privacy framing.
  • Frontend hosted behind Cloudflare with HSTS enabled (max-age=31536000).
  • No known public CVEs, breaches, or security incidents attributed to Shipup.
  • Low review count (9) on Shopify App Store suggests smaller install base relative to category leaders.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Shipping notifications and Tracking Page

Key insights
  • French publisher (Shipup SAS) with EU/GDPR-first privacy framing.
  • Frontend hosted behind Cloudflare with HSTS enabled (max-age=31536000).
  • No known public CVEs, breaches, or security incidents attributed to Shipup.
  • Low review count (9) on Shopify App Store suggests smaller install base relative to category leaders.
  • No Built for Shopify badge; no public mention of LLM/AI usage.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
Medium

L'application doit consulter les commandes pour associer les notifications d'expedition au bon achat, ce qui expose des donnees de commande. Ceci est induit de la fonction declaree de l'app.

read_customers
Medium

L'envoi de notifications d'expedition suppose d'acceder aux coordonnees des clients, donnees personnelles. Ceci est induit de la fonction declaree de l'app.

read_fulfillments
Medium

Le suivi des colis necessite de lire les informations de traitement et d'expedition des commandes. Ceci est induit de la fonction declaree de l'app.

read_shipping
Low

La page de suivi et les notifications s'appuient sur les donnees d'expedition et de transporteurs. Ceci est induit de la fonction declaree de l'app.

write_script_tags
Medium

L'affichage d'une page de suivi peut requerir l'injection de scripts dans la vitrine, ce qui modifie le comportement du magasin. Ceci est induit de la fonction declaree de l'app.

read_marketing_events
Low

Classee en Marketing, l'application peut consulter les evenements marketing lies aux communications d'expedition. Ceci est induit de la fonction declaree de l'app.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
shipup.co
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS present (max-age=31536000) via Cloudflare; no Content-Security-Policy header observed on root document.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR-aligned (EU Regulation 2016/679 cited). 3-year inactivity deletion. No formal SOC2/ISO27001/PCI DSS certification disclosed.

Privacy policy
Track record

Publisher reputation

Publisher
Shipup
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.