- Job title
- QA Tester
- Sector
- Freight
- Organization type
- 300-person organization
- Joined
- Aug 2025
- Message
- 143
Doki · KVKK compliance consulting · 2023
We are a 12-person freight and logistics startup operating in Dallas. We worked with a software agency for 10 months to build a custom web portal where our clients can review freight quotes, upload shipping documents, and track containers in real time. We spent roughly 35,000 USD on the project. Development wrapped up, we conducted acceptance testing, and our contract with the agency concluded. We took over all source code into our own Git repository.
Our newly hired senior developer, brought on to handle maintenance and new features internally, cloned the repo and ran an initial review, only to uncover alarming issues. They noticed that the database root password and third-party SMS service API keys were hardcoded as plain text inside the code files, and several open-source libraries hadn't been updated in at least two years. The portal contains a total of 45k lines of PHP and JavaScript code.
We are seriously concerned about hidden backdoors, authorization flaws, or vulnerabilities that could trigger a data breach. With just a single developer on hand, where should we begin a comprehensive secure code review, and what steps should we follow?