You do not need a security background. You need to know the handful of specific mistakes that show up over and over in small applications, because they are the ones automated scanners find and strangers exploit.

1. Trusting the ID in the URL

/invoice/1042 checks you're logged in, then shows invoice 1042. Change the number, read someone else's invoice.

The fix is one line: fetch the record and check it belongs to the requesting user, in the same query. This is the most common serious flaw in vibe-coded apps and the easiest to check for.

2. Building queries with string glue

If user input ends up inside a SQL string, someone can end your query and start their own. Use parameters — WHERE id = ? with the value passed separately. Same principle for shell commands: never build one from user input.

3. Putting user text on the page unescaped

Someone submits a comment containing a script tag; it runs in every other visitor's browser. Escape on output. Modern templating does this by default — the danger is the escape hatch, anything named like innerHTML, dangerouslySetInnerHTML or |raw. Search your project for those and justify each one.

4. Secrets in the code

Covered fully in keeping keys out of your code. Environment variables, .gitignore, rotate anything that leaked.

5. Client-side checks treated as security

Hiding the delete button doesn't stop anyone. Disabling a form field doesn't stop anyone. Validating in JavaScript doesn't stop anyone. Every check that matters happens on the server, because everything else is a suggestion to a browser you don't control.

Get it reviewed

security-review.txt
Review this for the five things that actually get small apps:

<paste>

1. Routes that return a record without checking it belongs to the
   requester — try changing an ID in the URL.
2. User input reaching a query or a shell command unescaped.
3. User input reaching the page unescaped.
4. Secrets in the source, or errors leaking internals.
5. Anything enforced only in the browser.

For each: the line, what an attacker does with it, the fix. Rank by
how easy it is to exploit with no special access.

Two habits worth having

Keep dependencies updated — most of what a scanner flags is a known issue in something you installed and forgot. And put a limit on anything that costs you money per call, so a bored stranger with a loop can't spend your budget overnight.

Assume every value that arrived over the network is hostile, including the ones your own form sent. That single assumption prevents most of this list.