I will do a security review of your next js or react web app

B
bele_tech
B
bele_tech
Yan

About this gig

Built your app fast with Lovable, Bolt, Cursor or by hand, and now real users are coming? Before they do, let someone look at it the way an attacker would.


WHAT I CHECK

- Secrets in the repo and Git history (.env, API keys, tokens)

- Authentication and sessions: cookies, JWT, expiry, revocation

- Access control on API routes and server actions: can a user reach what isn't theirs?

- Input validation and injection (SQL, XSS, SSRF)

- Security headers, CORS, CSP, rate limiting

- Dependencies with known vulnerabilities

- Error handling: what leaks to the browser


WHAT YOU GET

- A written report ranked critical / high / medium / low, with file, line, concrete risk and the fix

- Steps to reproduce each finding

- Premium: fixes delivered as pull requests you review, one per finding


HOW I WORK

Read-only unless you order fixes. No production access, no real user data. Fixed scope and price, written exclusions. Replies within 24 h.


Background: I run a production health-data app (Next.js, Postgres, Docker) with end-to-end encryption, WAF, monitoring and tested backups.


Not sure which package fits? Send me the repo size and stack, I'll tell you honestly.

Get to know Yan

Yan

Supabase RLS App Security Auditor Web Developer

  • FromFrance
  • Member sinceSep 2026
  • Languages

    French, English
I audit and fix the security of web apps built fast (Lovable, Bolt, Supabase, Next.js). Specialty: Row Level Security and data isolation. I test whether user A can really read or edit user B's data by calling the API directly, and hand you a reproducible test suite you keep. Cybersecurity & networks background; I run a production health-data app with end-to-end encryption, WAF and tested backups. You get a written report (critical to low, file, line, fix). No changes without your OK, no real user data needed. Fixed prices, written scope.