示例demo.okaytoship.com
基于我们测试应用的示例报告 · 2026年10月11日
还不能上线:2 个严重问题可能暴露你的数据或资金——请先修复。
22 个问题:严重 2 个, 高 4 个, 中 9 个, 低 6 个, 提示 1 个
- 安全严重数据库主密钥在网站代码中可见
- 支付严重你的 Stripe 私密密钥在网站代码中可见
- SEO需改进搜索引擎和链接预览看到的是空白页
- 速度正常此处无需修复
- 法律需改进你的首页没有隐私政策链接
- 成本需改进你的网站直接从访客浏览器调用 OpenAI
这是基于我们测试应用的示例报告。我们做了一个小应用,故意留下常见错误,让你清楚看到完整报告能提供什么。这些是与你的项目相同检查的真实结果,扫描于 2026年10月11日。
示例demo.okaytoship.com
基于我们测试应用的示例报告 · 2026年10月11日
还不能上线:2 个严重问题可能暴露你的数据或资金——请先修复。
22 个问题:严重 2 个, 高 4 个, 中 9 个, 低 6 个, 提示 1 个
这就是完整报告的样子。打开任意问题,查看证据、风险和修复方法。
任何人都能复制这个密钥,以你的 Stripe 账户身份操作:查看客户及其付款、退款或发起扣款。真金白银可能从你的账户流出。
今天就做: 立即在 Stripe 控制台吊销这个密钥并创建新的。它已经公开,只从代码中删除是不够的。
My app exposes a Stripe live secret key in the frontend code that every visitor downloads (it starts with "sk_liv…"). Remove this key from all client-side code and from any environment variables that get bundled into the browser. Move every operation that needs it into a server-side function that reads the key from a secret environment variable, and change the frontend to call that function instead. In the browser use only the publishable key. Create checkout sessions on the server with the secret key. I will revoke the old key and add the new one to the secrets myself. If this needs a secret key, put the server-side code in a Supabase Edge Function and store the key in the project's secrets (not in the code). Keep everything else working exactly as it does now and don't touch unrelated files. When you're done, list what you changed.
Stripe live secret key: sk_liv…