securitycritical impacttier 1100% confidence
Any endpoint that trusts client-submitted prices or totals
from orders agent · cross-site verified across production deployments
The trigger
Any endpoint that trusts client-submitted prices or totals
The fix
Always fetch menu_items fresh from DB and recompute unit_price + options + subtotal server-side; never trust client total
Related patterns
Does your site have this security issue?
Run a free scan — we'll check all security patterns in 30 seconds.
Scan your site free →