Security Review of a React & Stripe Shopping Cart
Pre-launch code and security review of a React, Express, MongoDB and Stripe shopping-cart app, with prioritized findings written for a non-technical owner.
The problem
The owner had a working shopping-cart app from another developer and wanted to know if it was safe to take real payments. They needed a clear answer, not a list of jargon.
What I did
- Full code review of the React/Redux client and the Express/MongoDB API, including auth, cart and Stripe checkout.
- Critical finding: checkout trusted the price sent by the browser, so a user could change it before the Stripe session was created. The fix is to look up prices on the server.
- Auth findings: no login rate limiting, weak password rules, and a forgot-password flow that revealed which emails had accounts.
- Hardening gaps: detailed error messages returned to users, missing security headers, and no logging or health check.
- Design issues: carts stored inside the user document, which won’t scale, and no automated tests.
- Launch plan: fixes ranked into “before anyone pays”, “before going live” and “later”, with each issue linked to the file that needs work.
- Plain-English report: every issue explained by its real-world impact, so the owner could make decisions without reading code.