Sample report · made-up app and data
CodeEyes security report9 issues found in app.bookly.example
Full report
- critical
Anyone can read every customer's name, email and phone number
The customer profiles table has no access rules, so the public key that ships with your app can read all of it. No login needed.
Proof
Tested: a request with no login, using only the app's public key. Result: 2,481 customer records returned (names, emails, phone numbers). Sample (redacted): J*** M****, j***@gmail.com, +44 7*** ***214
LockedHow to fix: copy-paste fix for your AI builder, included in your report
- critical
Anyone can delete bookings without logging in
The bookings table allows deletes from anyone. A stranger could wipe every booking in your app.
Proof
Tested: a delete request with no login, against one of our own test bookings. Result: the booking was removed. No other data was touched.
LockedHow to fix: copy-paste fix for your AI builder, included in your report
- high
Admin dashboard opens without a password
The /admin page is only hidden from the menu. Anyone who types the address gets in and can see all customers and payments.
Proof
Tested: opened /admin in a fresh browser with no account. Result: full admin dashboard loaded, including the customer list.
LockedHow to fix: copy-paste fix for your AI builder, included in your report
- high
Any customer can see other customers' invoices
Invoices are fetched by number with no check on who owns them. Changing the number in the address shows someone else's invoice.
Proof
Tested: signed in as test customer A, changed the invoice number in the address. Result: invoice belonging to test customer B was shown.
LockedHow to fix: copy-paste fix for your AI builder, included in your report
- high
Payments can be marked as paid without paying
The payment confirmation step doesn't check that the message really came from your payment provider, so a fake message can unlock paid features.
Proof
Tested: sent an unsigned confirmation message for a test order. Result: the test order was marked as paid.
LockedHow to fix: copy-paste fix for your AI builder, included in your report
- medium
Sign-up form reveals who has an account
Entering an existing email gives a different message from a new one, so anyone can check whether a person uses your app.
Proof
Tested: signed up with a known test email and a new one. Result: two different responses, confirming which email is registered.
LockedHow to fix: copy-paste fix for your AI builder, included in your report
- medium
Weak passwords are allowed
Accounts can be created with passwords like "123456", which are the first ones attackers try.
Proof
Tested: created a test account with the password 123456. Result: account created.
LockedHow to fix: copy-paste fix for your AI builder, included in your report
- medium
No limit on login attempts
The login form accepts unlimited guesses, so an attacker can keep trying passwords until one works.
Proof
Tested: 50 wrong passwords in a row on a test account. Result: no slowdown, lockout or warning.
LockedHow to fix: copy-paste fix for your AI builder, included in your report
- low
Missing browser security settings
The site doesn't send standard security headers, which makes some attacks (like loading your app inside another site) easier.
Proof
Tested: checked the site's response headers. Result: no Content-Security-Policy or X-Frame-Options header.
LockedHow to fix: copy-paste fix for your AI builder, included in your report
Want this for your app?
Your free scan shows how many issues you have, how bad they are, and proof of the worst one. Results in 48 hours.
Get my free scan