Your non-technical friend built something in Lovable last weekend. It works. They want to charge for it. They don't know their API keys are in the client bundle, their database is public, and they have zero error monitoring.
howbadis.it: they paste the URL, get a score. A few stack questions cover what the URL scan can't see.
What checks should I add?