Ilya Shkura
EN UK RU

Notes · October 2026

A shop that looked finished: 28 problems off the normal path.

A knitwear shop was built with Claude Code from 17 messages in plain words, the way an owner would describe what they want: a catalogue, checkout by card or bank transfer, returns, an admin with reports, installation on a phone. The owner never read the code. After the last message the shop looked like a real brand's shop, and it worked in a normal walk-through.

The shop is fictional and holds test data; it was built for this check. Every finding below is a real run.

What the builder said, and what was there

  • It wrote "Orders can't be placed twice". That held. But the key that made it hold, kept on the device for 12 hours, handed one customer's order to the next person ordering on the same device after a dropped connection.
  • It wrote that "a customer's orders and addresses are removed from the device when they sign out". After signing out, the device still opened the customer's order, with name, street, email and phone.
  • It wrote that the dashboard, reports and stock all agree with the orders, and that it had checked each. Refunds for "last 30 days" came to €5,619.79 on the dashboard and €5,483.80 in the reports: both right for their own window, under the same label.

The four that mattered

  • Any new account could read guests' orders. Making an account took a minute. With it, any order placed without an account opened by its number: name, address, email, phone, what was bought. Order numbers ran in sequence, and about four in ten orders were guest orders.
  • Someone else's order after a dropped connection. The next customer on the same device pressed "Place order · €53.99" and was shown the previous customer's order for €29.99, with that customer's address.
  • A refund of any size. The owner could record €500 refunded on a €29.99 order, and the customer was emailed that €500 was on its way.
  • Paid for a cancelled order. The owner cancelled an order while the customer was on the card payment page. The customer paid €27.99; the shop recorded no payment and sent nothing back.

None of the four shows up while clicking through the shop as intended. Each needs one step off the normal path: a number typed into the address bar, a connection that drops at the wrong second, a digit too many, two people acting at once.

What held

Prices and stock were set by the database, not by the page. The totals of all 2,059 orders added up to the cent, and the reports matched an independent recount. Nobody without an account could read customers' data. Forged payment notices were refused.

What I take from it

"Finished" is the builder's word, and a builder checks the path it built. The problems live next to that path. So every problem found becomes a test that fails first: on this shop 42 of 51 such tests failed as received, and none after the fixes. And every fix is checked again before the next one, because part of what turned up later was brought by the fixes themselves.

Four things to try on your own app in ten minutes:

  • Sign up as a new user and open someone else's order or record by changing the number in the address.
  • Cut the connection right after pressing the button that takes money, then order again as someone else on the same device.
  • Cancel an order while its payment page is open in another tab, then pay.
  • Type an amount that is too large, and one in the format your customers' country uses (1.234,56).

Before the shop went live, one more came up: the newsletter form would send the shop's email to any address, any number of times. It is fixed, and the fixed shop is live: open it yourself with a demo login from the case page.

The full case, with pictures before and after and the 22-page report: An online shop built with AI, checked and fixed.