
1. Search for secrets and committed environment files
Check the full repository and history for .env files, tokens, API keys, database passwords and private keys. If a real secret was committed, revoke it before cleaning the repository.
2. Test authentication and ownership
Authentication answers who the user is; authorisation answers what that user may do. Verify both on the server for every protected read and write, including direct API requests that bypass the interface.
3. Review database security rules
Firebase and Supabase defaults can become dangerous when broad development rules reach production. Confirm that rules are deployed, Row Level Security is enabled where required, and policies cover read, create, update and delete operations.
4. Verify payment boundaries
Calculate prices on the server, verify webhook signatures, make processing idempotent, and never trust product IDs, amounts or account ownership supplied only by the browser.
5. Check dependencies and production setup
Review known vulnerabilities, lockfiles, production URLs, CORS, security headers, error handling and monitoring. Test the actual built application, not only the development server.
Frequently asked questions
Is a checklist enough to secure an application?
No. It creates consistency, but higher-risk products also need threat modelling, testing, monitoring and expert review.
Should checks run once or continuously?
Run them before launch and again after changes to authentication, payments, data access, dependencies or deployment configuration.