跳到正文
OkayToShip

示例报告

这是基于我们测试应用的示例报告。我们做了一个小应用,故意留下常见错误,让你清楚看到完整报告能提供什么。这些是与你的项目相同检查的真实结果,扫描于 2026年10月11日。

示例demo.okaytoship.com

基于我们测试应用的示例报告 · 2026年10月11日

得分 23(满分 100)

还不能上线:2 个严重问题可能暴露你的数据或资金——请先修复。

22 个问题:严重 2 个, 高 4 个, 中 9 个, 低 6 个, 提示 1 个

  • 安全严重数据库主密钥在网站代码中可见
  • 支付严重你的 Stripe 私密密钥在网站代码中可见
  • SEO需改进搜索引擎和链接预览看到的是空白页
  • 速度正常此处无需修复
  • 法律需改进你的首页没有隐私政策链接
  • 成本需改进你的网站直接从访客浏览器调用 OpenAI

22 个问题,全部展开

这就是完整报告的样子。打开任意问题,查看证据、风险和修复方法。

  • 任何人都能复制这个密钥,以你的 Stripe 账户身份操作:查看客户及其付款、退款或发起扣款。真金白银可能从你的账户流出。

    今天就做: 立即在 Stripe 控制台吊销这个密钥并创建新的。它已经公开,只从代码中删除是不够的。

    如何修复
    1. 立即在 Stripe 控制台吊销这个密钥并创建新的。它已经公开,只从代码中删除是不够的。
    2. 新密钥只放在服务器端:从私密环境变量读取它的 Edge Function、API 路由或后端。绝不要给它加 VITE_、NEXT_PUBLIC_ 或 REACT_APP_ 这样的公开前缀。
    3. 让页面调用你的服务器函数,而不是直接使用密钥。
    4. 浏览器中只使用 publishable 密钥。在服务器上用私密密钥创建支付会话。
    5. 重新发布网站并运行这次扫描,确认密钥已消失。

    My app exposes a Stripe live secret key in the frontend code that every visitor downloads (it starts with "sk_liv…"). Remove this key from all client-side code and from any environment variables that get bundled into the browser. Move every operation that needs it into a server-side function that reads the key from a secret environment variable, and change the frontend to call that function instead. In the browser use only the publishable key. Create checkout sessions on the server with the secret key. I will revoke the old key and add the new one to the secrets myself. If this needs a secret key, put the server-side code in a Supabase Edge Function and store the key in the project's secrets (not in the code). Keep everything else working exactly as it does now and don't touch unrelated files. When you're done, list what you changed.

    我们发现了什么
    https://demo.okaytoship.com/assets/index-D6yG_D9G.jsStripe live secret key: sk_liv…