forumNew topic

We took over code left by an agency — how should a secure code review be done, and where do we start?

SSultan A***Member
Job title
QA Tester
Sector
Freight
Organization type
300-person organization
Joined
Aug 2025
Message
143

Doki · KVKK compliance consulting · 2023

#1

We are a 12-person freight and logistics startup operating in Dallas. We worked with a software agency for 10 months to build a custom web portal where our clients can review freight quotes, upload shipping documents, and track containers in real time. We spent roughly 35,000 USD on the project. Development wrapped up, we conducted acceptance testing, and our contract with the agency concluded. We took over all source code into our own Git repository.

Our newly hired senior developer, brought on to handle maintenance and new features internally, cloned the repo and ran an initial review, only to uncover alarming issues. They noticed that the database root password and third-party SMS service API keys were hardcoded as plain text inside the code files, and several open-source libraries hadn't been updated in at least two years. The portal contains a total of 45k lines of PHP and JavaScript code.

We are seriously concerned about hidden backdoors, authorization flaws, or vulnerabilities that could trigger a data breach. With just a single developer on hand, where should we begin a comprehensive secure code review, and what steps should we follow?

HHilal Z***MemberCommunity member
Joined
Dec 2024
Message
136
Most Helpful#2

Short answer: A secure code review involves scanning for known vulnerabilities and dependencies using automated static analysis tools, followed by a manual audit of critical business logic and authentication flows. Since it is impossible for a single developer to manually review 45k lines line by line, you should break the process down into three stages: automated scanning, dependency auditing, and targeted manual review.

The first step is cleaning sensitive data from the repo and auditing dependencies. Hardcoded credentials shouldn't merely be removed from files; they must be immediately rotated across the database and external services. Next, run open-source dependency scanners to identify and patch known vulnerabilities in your third-party libraries.

The second stage is deploying static application security testing (SAST) tools. These tools scan the entire codebase pre-compilation and flag foundational vulnerabilities—like SQL injection, cross-site scripting, and insecure input handling—in a matter of minutes.

The third and most critical phase is the manual business logic review. Automated tools cannot determine whether a client can view someone else's bill of lading or invoice. Your developer must manually audit user authorization, document upload handlers, and exposed public API endpoints one by one.

MMehmet M***Member
Job title
Digital marketing specialist
Sector
Education
Organization type
regional distributor
Joined
Nov 2025
Message
302
#3

Your first urgent priority should be purging the Git history. Even if you remove the credentials from the codebase and commit the change, those keys remain exposed forever in the commit log. Scan the entire history with open-source secret-scanning tools, rewrite the history to purge the secrets, and rotate those passwords on the servers immediately.

DDilara T***Member
Job title
Social media manager
Sector
Logistics
Organization type
a company within a holding
Joined
Aug 2024
Message
333
#4

Have your developer run your package manager's built-in security audit command first thing tomorrow. Libraries sitting untouched for two years almost certainly have dozens of published CVEs. Simply bumping dependencies to their latest stable releases will instantly knock out half of your exposure.

OOnur A***ExpertCommunity member
Joined
Nov 2025
Message
64
#5

We ran static code analysis on a 30k-line project we inherited last year. The tool flagged 142 potential alerts; after our developer reviewed them, 8 turned out to be real vulnerabilities that could have led directly to a database leak. Patching those 8 flaws took us just three days.

İİlknur O***Member
Job title
Courier coordinator
Sector
Livestock
Organization type
chain store
Joined
Feb 2025
Message
109
#6

Don't rely too much on automated analysis tools; you could easily drown in hundreds of false positives across a thousands-of-lines-long report. The biggest data leaks don't stem from library vulnerabilities, but from simple session control oversights where the agency dev thought "no one's gonna try that anyway." Focus heavily on manual business logic testing.

SSena S***MemberCommunity member
Joined
May 2023
Message
175
#7

an agency that hardcodes passwords prolly didn't even look at the file upload part either... test immediately if someone can sneak in an executable php file while uploading customer docs that's the most dangerous backdoor.

BBurcu E***Member
Job title
Administrative manager
Sector
Real estate
Organization type
40-person manufacturing company
Joined
Feb 2023
Message
37
#8

Document the identified findings in a formal security risk matrix. Categorize the vulnerabilities as critical, high, and medium. Keeping the system live and accessible to customers before resolving critical vulnerabilities that directly threaten database and customer confidentiality may lead to serious legal liabilities.

BBetülExpert
Job title
Management consultant
Joined
Oct 2023
Message
164
#9

Go back and review your contract with the agency. Most contracts contain an explicit or implicit warranty clause stating that the code will be delivered in accordance with industry standards and basic security practices. Hardcoding passwords into the source code is a clear defect of service; you may have the legal right to serve the agency with a formal notice to fix it.

İİlknur C***MemberCommunity member
Joined
Feb 2025
Message
18
#10

how do static code analysis tools inspect the code without actually running it? i mean how exactly can these tools tell that a function has a vulnerability without deploying it to a live server or connecting to a database?

HHalideNew member
Job title
Foundation manager
Joined
Aug 2024
Message
44
#11

I have no experience with secure code review, so I'm asking. Everything goes well for the first three months; problems arise in the fourth.

Start with a small trial; don't commit to everything at once. If you have questions, write them; I'll answer as best I can.

HHüseyin Z***MemberCommunity member
Joined
Mar 2023
Message
76
#12

i'm curious too.

İİsmail Ş***Member
Job title
System support specialist
Sector
Furniture manufacturing
Organization type
boutique agency
Joined
Apr 2024
Message
32
#13

This approach has a cost which isn't discussed. If 2FA is on, a stolen password alone is useless.

If you have questions, write them; I'll answer as best I can.

MMustafa A***Member
Job title
Regional Manager
Sector
Paper
Organization type
cooperative
Joined
Mar 2023
Message
37
#14

I was thinking the same thing. An automated scan report is not the same as a penetration test.

If I were you, I'd go this route.

EEmre K***Member
Job title
Courier coordinator
Sector
Law
Organization type
cooperative
Joined
Feb 2025
Message
1
#15

I went through the same thing. When we decide without measuring, we always end up in the same place.

That's all, sorry if I went on too long.

AAlper Ç***Member
Job title
Customer service representative
Sector
Freight
Organization type
120-person company
Joined
Jul 2024
Message
41
#16

I was thinking the same thing. If 2FA is on, a stolen password alone is useless.

Solutions that work at a small scale collapse when you grow; I learned this late. Just leaving this note, it might be useful.

MMert E***MemberCommunity member
Joined
Sep 2024
Message
28
#17

there are three things to check when doing this and people defend habits, not processes. btw resistance comes from there.

SSerkan S***MemberCommunity member
Joined
Jan 2023
Message
87
#18

Im in the same situation, thats why Im asking. anyway if permission and scope arent in writing, dont start that test.

Processes without records never improve, because you dont know what to fix. btw this is my opinion Im not claiming its absolute truth.

MMustafa M***Member
Job title
Quality control inspector
Sector
Food wholesale
Organization type
regional distributor
Joined
Feb 2024
Message
106
#19

The opposite happened to me, that's why I'm writing. Mistakes made on the secure code review side are usually reversible but expensive.

If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

BBurak Can M***Veteran
Job title
Founder · e-commerce
Organization type
20-person company
Joined
Apr 2023
Message
212
#20

My questions are cleared up, thanks. Your time to detect an issue directly determines its cost.

If you have questions, write them; I'll answer as best I can.

Reply