1 Architecture Issues
| # | Issue | Severity | Details |
|---|---|---|---|
| 1 | Monolithic architecture | High | Frontend, backend API, and database logic are all in a single Next.js 12 app. No separation of concerns. |
| 2 | Sanity CMS misused as primary database | Critical | User accounts (with passwords!) are stored in Sanity — a CMS not designed for transactional data. No indexing, no relations, rate-limited writes. |
| 3 | Custom server disables Next.js optimizations | Medium | server.js uses createServer manually, which disables Automatic Static Optimization and ISR benefits. |
| 4 | No proper backend service | High | Business logic (auth, payments) lives in Next.js API routes — not scalable, not independently deployable. |
2 Security Vulnerabilities
| # | Issue | Severity | Details |
|---|---|---|---|
| 1 | Sanity token exposed to client | Critical | NEXT_PUBLIC_SANITY_TOKEN — the NEXT_PUBLIC_ prefix exposes this write-capable token in the browser bundle. Anyone can read/write to the Sanity dataset. |
| 2 | No input validation | High | API routes (login.ts, register.ts) accept raw req.body without any validation or sanitization. SQL injection equivalent via GROQ queries with string interpolation. |
| 3 | GROQ injection | High | Pages like [category]/index.tsx use *[_type=='product'&& category[0]=="${category}"] — direct string interpolation of user-controlled URL params into queries. |
| 4 | No rate limiting | Medium | Login/register endpoints have no brute-force protection. |
| 5 | JWT with no refresh mechanism | Medium | Tokens expire in 30 days with no refresh flow. If compromised, attacker has 30-day access. |
| 6 | Synchronous bcrypt | Low | bcrypt.compareSync() blocks the Node.js event loop during password verification. |
| 7 | Insecure signup fallback | Critical | In signUp.tsx, if Sanity returns a 500 error, the code logs the user in anyway and stores their data in cookies — completely bypassing authentication. |
3 Code Quality Issues
| # | Issue | Details |
|---|---|---|
| 1 | No tests | Zero test files. No unit, integration, or e2e tests. |
| 2 | Hardcoded data everywhere | Categories, banners, brands, benefits, slider content — all in /mock/ files. Not manageable by non-developers. |
| 3 | Inconsistent TypeScript | Mix of .js and .tsx files. any types used frequently (state: any). No strict mode. |
| 4 | Dead/incomplete features | Search bar is purely cosmetic (no functionality — has a TODO comment). |
| 5 | Broken state management | clearCart reducer does state = initialState which doesn't work in Redux Toolkit (Immer) — cart can never be cleared. Same bug in favorite-slice.ts. |
| 6 | No error boundaries | No React error boundaries. A single component crash takes down the entire page. |
| 7 | Commented-out code | Multiple instances of commented code left in production files. |
| 8 | Hardcoded Sanity project ID | 3c4n15ly is hardcoded in lib/config.ts and lib/client.ts instead of using environment variables. |
4 Performance Issues
| # | Issue | Details |
|---|---|---|
| 1 | Outdated Next.js (v12) | Missing React Server Components, App Router, streaming, and modern optimizations from v13/14. |
| 2 | No caching strategy | No ISR revalidation configured. getStaticProps has no revalidate property — pages are only rebuilt on full redeploy. |
| 3 | All products loaded at once | Homepage fetches ALL products (*[_type=='product']) with no pagination. Will degrade as catalog grows. |
| 4 | Redux for everything | 11 Redux slices for simple UI state (mega menu open/close, sidebar toggle). Overkill — causes unnecessary re-renders. |
| 5 | No image optimization strategy | Relies entirely on Sanity CDN. No responsive image sizes, no blur placeholders, no lazy loading strategy. |
5 Missing Features (for a production e-commerce platform)
❌
Order management system
❌
Inventory tracking
❌
Admin panel / dashboard
❌
Product search (UI exists but non-functional)
❌
Pagination / infinite scroll
❌
Email notifications
❌
Password reset flow
❌
User profile management
❌
Order history
❌
Shipping/address management
❌
Proper payment flow (Stripe integration is minimal)
❌
Webhook handling for payment confirmation
❌
SEO metadata per page (only a static <title>ZiShop</title>)
❌
Accessibility (no ARIA labels, no keyboard navigation support)
❌
Logging / monitoring
6 Dependency Concerns
| Package | Issue |
|---|---|
| next@12.1.6 | 2+ major versions behind, known vulnerabilities |
| @sanity/client@3.3.0 | Sanity v2 is deprecated |
| react-query@3.38.1 | Renamed to @tanstack/react-query v4/v5 |
| @zeit/next-css | Deprecated package (Zeit → Vercel) |
| next-connect@0.12.2 | Outdated API middleware |
| npm audit reports | 20 moderate, 11 high, 3 critical vulnerabilities |
Core Evaluation Summary
This project is a prototype/MVP-level application, not production-ready. The most critical issues are:
- Security — exposed API tokens, no input validation, authentication bypass on error
- Architecture — CMS used as a database, no backend separation, no scalability path
- Reliability — no tests, broken state management, no error handling
- Missing features — no orders, no search, no admin, no proper payments
Final Recommendation
Recommendation: A full rebuild using the target tech stack (Next.js 14, NestJS/Route Handlers, PostgreSQL, Prisma, Auth.js, Stripe) is the correct approach. Attempting to incrementally upgrade this codebase would be more expensive than starting fresh due to the fundamental architectural issues.