Built your app with AI? Check these five first.
AI coding tools ship working features fast. They also skip checks a careful developer wouldn't. These are the five we look at first in every review.
1. One user can see another user's data
The most common serious bug: the app loads a record by its id without checking it belongs to the person asking, so changing a number in the address shows someone else's invoice or profile. On Supabase, look for tables without row-level security, or policies written as using (true). On Firebase, rules that only say "signed in" let any user read everyone's data. Test it: with two test accounts, try to open account A's records while signed in as B.
2. Security that only lives in the browser
Hiding an admin button isn't protection; anyone can call the server directly. Every page, API route and server action must check the user and their role on the server. In Next.js, a check in a shared layout doesn't protect the pages under it. Test it: call a protected address with no sign-in, and as a regular user.
3. Secret keys shipped to the browser
Anything in front-end code is public. A Stripe secret key, a database service-role key or an AI provider key in a variable like NEXT_PUBLIC_… or VITE_… is visible to every visitor. Test it: search your code for those prefixes and for key patterns, then rotate anything that was exposed.
4. Payments delivered from the success page
If your app unlocks the product when the customer lands on the thank-you page, anyone can type that address and skip paying. Delivery should happen from the payment provider's signed webhook, de-duplicated by event id, with the price set on the server. Test it: open the success page directly without paying.
5. No limits, no backups
Without rate limits, a sign-in form can be used to flood a customer's inbox, and an endpoint without size limits will read a request of any size. And many apps have never had a backup restored, which means they don't really have backups. Test it: submit a form a dozen times quickly, and ask when a restore was last tested.
We review apps against a 22-point checklist that covers these five and seventeen more. See a sample report (anonymized) or see the audit packages, starting with a $299 Quick Scan.