Can another person reproduce the build?
Start from a clean clone and follow the documented setup. Note missing steps, unpinned dependencies, and undocumented environment variables. Keep actual secret values out of documentation.
A short, evidence-based pass for a solo founder or small team. Record what you checked, what happened, and who owns any remaining action. A checked box is not proof of security by itself.
Start from a clean clone and follow the documented setup. Note missing steps, unpinned dependencies, and undocumented environment variables. Keep actual secret values out of documentation.
Walk through sign-up or sign-in, the core action, an expected failure, and sign-out on the supported browser and viewport sizes.
With two test accounts, create a record as B and try to request it as A. Also try the relevant update or delete path. A hidden button is not an authorization check.
Try empty, malformed, too-long, and out-of-range values on important forms and API requests. Confirm validation happens on the server for security-sensitive actions.
Run the package manager’s audit or alert workflow, identify affected production dependencies, and choose a tested update or a documented mitigation. A clean scanner result is not a complete security assessment.
Trigger a safe test failure. Confirm the team can find it and that logs do not expose passwords, tokens, session cookies, or unnecessary personal information.
If the app stores important data, confirm backups exist and follow a restore procedure in a safe environment. A successful backup job alone does not prove recoverability.
Write down how to roll back the deployment and what happens to database changes or queued work. Avoid assuming that reverting application code reverses data migrations.
Check required production configuration by name, confirm test credentials are not production credentials, and remove stale deploy keys or broad access that is no longer needed.
After release, confirm the expected version is live, exercise one safe smoke check, and name who receives reports and decides whether to roll back.
This checklist is educational guidance, not a penetration test, certification, legal opinion, or guarantee. Adapt it to the app’s risks. For identity and authorization tests, use synthetic data and accounts you control.