Ways and Means Technology Pvt. Ltd. Logo
Audited By Ways and Means Technology Pvt. Ltd.
waysandmeanstechnology.com →
Independent Technical Audit

Project Review Report

Shopping Platform (Legacy)

Status Summary Rebuild Recommended

1 Architecture Issues

# Issue Severity Details
1 Monolithic architecture High Frontend, backend API, and database logic are all in a single Next.js 12 app. No separation of concerns.
2 Sanity CMS misused as primary database Critical User accounts (with passwords!) are stored in Sanity — a CMS not designed for transactional data. No indexing, no relations, rate-limited writes.
3 Custom server disables Next.js optimizations Medium server.js uses createServer manually, which disables Automatic Static Optimization and ISR benefits.
4 No proper backend service High Business logic (auth, payments) lives in Next.js API routes — not scalable, not independently deployable.

2 Security Vulnerabilities

# Issue Severity Details
1 Sanity token exposed to client Critical NEXT_PUBLIC_SANITY_TOKEN — the NEXT_PUBLIC_ prefix exposes this write-capable token in the browser bundle. Anyone can read/write to the Sanity dataset.
2 No input validation High API routes (login.ts, register.ts) accept raw req.body without any validation or sanitization. SQL injection equivalent via GROQ queries with string interpolation.
3 GROQ injection High Pages like [category]/index.tsx use *[_type=='product'&& category[0]=="${category}"] — direct string interpolation of user-controlled URL params into queries.
4 No rate limiting Medium Login/register endpoints have no brute-force protection.
5 JWT with no refresh mechanism Medium Tokens expire in 30 days with no refresh flow. If compromised, attacker has 30-day access.
6 Synchronous bcrypt Low bcrypt.compareSync() blocks the Node.js event loop during password verification.
7 Insecure signup fallback Critical In signUp.tsx, if Sanity returns a 500 error, the code logs the user in anyway and stores their data in cookies — completely bypassing authentication.

3 Code Quality Issues

# Issue Details
1 No tests Zero test files. No unit, integration, or e2e tests.
2 Hardcoded data everywhere Categories, banners, brands, benefits, slider content — all in /mock/ files. Not manageable by non-developers.
3 Inconsistent TypeScript Mix of .js and .tsx files. any types used frequently (state: any). No strict mode.
4 Dead/incomplete features Search bar is purely cosmetic (no functionality — has a TODO comment).
5 Broken state management clearCart reducer does state = initialState which doesn't work in Redux Toolkit (Immer) — cart can never be cleared. Same bug in favorite-slice.ts.
6 No error boundaries No React error boundaries. A single component crash takes down the entire page.
7 Commented-out code Multiple instances of commented code left in production files.
8 Hardcoded Sanity project ID 3c4n15ly is hardcoded in lib/config.ts and lib/client.ts instead of using environment variables.

4 Performance Issues

# Issue Details
1 Outdated Next.js (v12) Missing React Server Components, App Router, streaming, and modern optimizations from v13/14.
2 No caching strategy No ISR revalidation configured. getStaticProps has no revalidate property — pages are only rebuilt on full redeploy.
3 All products loaded at once Homepage fetches ALL products (*[_type=='product']) with no pagination. Will degrade as catalog grows.
4 Redux for everything 11 Redux slices for simple UI state (mega menu open/close, sidebar toggle). Overkill — causes unnecessary re-renders.
5 No image optimization strategy Relies entirely on Sanity CDN. No responsive image sizes, no blur placeholders, no lazy loading strategy.

5 Missing Features (for a production e-commerce platform)

❌ Order management system
❌ Inventory tracking
❌ Admin panel / dashboard
❌ Product search (UI exists but non-functional)
❌ Pagination / infinite scroll
❌ Email notifications
❌ Password reset flow
❌ User profile management
❌ Order history
❌ Shipping/address management
❌ Proper payment flow (Stripe integration is minimal)
❌ Webhook handling for payment confirmation
❌ SEO metadata per page (only a static <title>ZiShop</title>)
❌ Accessibility (no ARIA labels, no keyboard navigation support)
❌ Logging / monitoring

6 Dependency Concerns

Package Issue
next@12.1.6 2+ major versions behind, known vulnerabilities
@sanity/client@3.3.0 Sanity v2 is deprecated
react-query@3.38.1 Renamed to @tanstack/react-query v4/v5
@zeit/next-css Deprecated package (Zeit → Vercel)
next-connect@0.12.2 Outdated API middleware
npm audit reports 20 moderate, 11 high, 3 critical vulnerabilities

Core Evaluation Summary

This project is a prototype/MVP-level application, not production-ready. The most critical issues are:

  • Security — exposed API tokens, no input validation, authentication bypass on error
  • Architecture — CMS used as a database, no backend separation, no scalability path
  • Reliability — no tests, broken state management, no error handling
  • Missing features — no orders, no search, no admin, no proper payments
Final Recommendation

Recommendation: A full rebuild using the target tech stack (Next.js 14, NestJS/Route Handlers, PostgreSQL, Prisma, Auth.js, Stripe) is the correct approach. Attempting to incrementally upgrade this codebase would be more expensive than starting fresh due to the fundamental architectural issues.