Looks Like This Service Is On Hold

I will do a secure code review of your ai generated web app with a fix report

Germany

I speak Chinese, English, German

Backend Reliability Engineer, Idempotent Webhooks, ETL and LLM Evals

I'm a backend engineer who fixes the failures that cost money: duplicate webhook charges, ETL jobs that drop or double rows, and LLM features that hallucinate in production. What sets me apart: every...
About this Gig

Your app shipped fast (v0, Cursor, Lovable, Supabase). That speed hides security holes a quick test won't catch.


I am an ex-penetration-tester. I do a READ-ONLY secure code review of a snapshot you send (zip or read-only repo) and return a prioritized fix-it report covering what AI code-generators commonly ship:


- Leaked API / service-role keys in code

- IDOR and broken access control

- Missing DB access rules (e.g. Supabase RLS)

- SSRF, stored XSS, weak JWT handling

- Vulnerable, outdated dependencies


Per finding you get severity (CVSS, OWASP Top 10, CWE), the exact file and line, the business impact, and an exact code-fix - plus a P0-P3 roadmap. Higher tiers apply the key fixes on a branch and add a CI security gate (SAST + secret + dependency scan) that goes red on the bug and green once fixed.


See the proof first: a public, runnable demo where the same CI gate is red on the vulnerable code and green on the hardened, with the full report.


Boundary: a read-only review of code you provide - NOT a penetration test. No live system is tested, and you keep every key.

Development technology:

JavaScript

Expertise:

Clean Code

Code efficiency

Design patterns