← All projects

Security Review of a React & Stripe Shopping Cart

Pre-launch code and security review of a React, Express, MongoDB and Stripe shopping-cart app, with prioritized findings written for a non-technical owner.

Client
Web-app owner
Year
2026
Category
Other
Stack
  • React
  • Redux Toolkit
  • Vite
  • Node.js
  • Express
  • MongoDB
  • Stripe
  • JWT

The problem

The owner had a working shopping-cart app from another developer and wanted to know if it was safe to take real payments. They needed a clear answer, not a list of jargon.

What I did

  • Full code review of the React/Redux client and the Express/MongoDB API, including auth, cart and Stripe checkout.
  • Critical finding: checkout trusted the price sent by the browser, so a user could change it before the Stripe session was created. The fix is to look up prices on the server.
  • Auth findings: no login rate limiting, weak password rules, and a forgot-password flow that revealed which emails had accounts.
  • Hardening gaps: detailed error messages returned to users, missing security headers, and no logging or health check.
  • Design issues: carts stored inside the user document, which won’t scale, and no automated tests.
  • Launch plan: fixes ranked into “before anyone pays”, “before going live” and “later”, with each issue linked to the file that needs work.
  • Plain-English report: every issue explained by its real-world impact, so the owner could make decisions without reading code.