What you get
- Manual review of the Stripe-related code in your public repo (webhooks, checkout, subscriptions, refunds).
- Our 7-rule scanner run on the same code (signature verification, raw-JSON parsing, hardcoded keys, idempotency, legacy Charges API, client-controlled amounts, event dedup).
- A written report: each finding with severity, file and function, why it matters, and the concrete fix.
- Emailed to you as a PDF within 48h, to the address on your Stripe receipt.
See a real example: sample audit of flask-stripe-checkout (6 findings, including a fulfilment-on-redirect issue and a subscription upgrade crash).
How it works
- Pay $39 below. Checkout has no required fields. Paste your public repo URL if you have it to hand; if you leave it blank, just reply to your receipt email with it.
- The repo URL field at checkout is optional but speeds things up: fill it in if you can, so we can start reviewing right away.
- Within 48h the report arrives by email, as a PDF, at the address on your receipt.
- If the repo isn't public or has no Stripe code we can review, you get a full refund.
$39 one-time
Limits, stated plainly
- Public repositories only. We never ask for, or access, your Stripe account or API keys.
- This is a code review, not a penetration test or a PCI compliance certification.
- Reports are sent only to the email address on your payment receipt; nothing about your repo is published on this site.
- Questions about scope are answered on the report itself; for anything else, email hello@saasfactoryagents.com.
Prefer to run checks yourself? Checklist ($9) and Auditor Kit script ($29).