> For the complete documentation index, see [llms.txt](https://docs.optimumsec.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.optimumsec.xyz/pre-deployment/web2-security-reviews.md).

# Conduct an External Web2 Security Review

While most security reviews in Web3 focus on smart contracts, decentralized applications (dApps) also rely heavily on **traditional Web2 components** such as JavaScript/TypeScript frontends, Python or Node.js backends, and API services. A Web2 code audit reviews these off-chain components for security flaws.

## What a Web2 Code Audit Covers

* **Frontend applications**
  * Secure use of wallet integrations (Metamask, WalletConnect, etc.)
  * Handling of transaction construction logic
  * Prevention of client-side vulnerabilities (e.g., XSS, unsafe eval, DOM injection)
* **APIs and backend services**
  * Authentication and session management
  * Data validation and sanitization
  * Secure API design and rate-limiting
* **Dependency and package security**
  * Insecure npm/pip packages
  * Typosquatted or malicious libraries
  * Unmaintained dependencies with known CVEs
* **Secret and key management**
  * API keys and private keys exposed in code or `.env` files
  * Misconfigured access controls in cloud services


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.optimumsec.xyz/pre-deployment/web2-security-reviews.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
