1
2 Comments

How do you test a web app before calling it production ready?

For those shipping web apps to clients or pushing to production, I am curious about your process.

Before you call something production ready, how do you validate security beyond basic scans?

In many projects I have reviewed, small issues pass unnoticed:

• An endpoint returns more data than expected
• Role checks are inconsistent across routes
• APIs expose internal assumptions
• Sessions can be reused in unintended flows

Individually these look minor.
Together they can create a path to real access or data exposure.

Static scans often flag isolated findings, but they do not show how weaknesses connect.

So I am interested in your approach.

Do you rely on:
• Automated scanners?
• Manual review?
• Threat modeling?
• External pentests?
• Nothing formal?

What does your “ready for production” security checklist look like?

posted to Icon for group Developers
Developers
on February 12, 2026
  1. 1

    Hello @nautillo, Our web developers can help you with this. Contact us today

    1. 1

      Appreciate it, but this is exactly the gap I am pointing to.
      Most dev shops help build and fix features. Security usually ends at scans or checklist reviews.
      The issue is not missing tools. It is missing context on how issues connect.

Trending on Indie Hackers
Agencies charge $5,000 for a 60-second product demo video. I make mine for $0. Here's the exact workflow. User Avatar 126 comments I wasted 6 months building a failed startup. Built TrendyRevenue to validate ideas in 10 seconds. User Avatar 55 comments I've been building for months and made $0. Here's the honest psychological reason — and it's not what I expected. User Avatar 51 comments Your files aren’t messy. They’re just stuck in the wrong system. User Avatar 28 comments Why Direction Matters More Than Motivation in Exam Preparation User Avatar 14 comments I built a health platform for my family because nobody has a clue what is going on User Avatar 13 comments