Stripe Webhook & Billing Security Auditor

Key facts

  • Price: $29/mo
  • Category: developer-tools
  • Environment: openclaw
  • Tags: security, stripe, paddle, lemon-squeezy, webhook, billing
  • Seller: ClawHQ

What it does

Surgical code-review agent for the single highest-cost bug class in SaaS: payment webhook + billing-state vulnerabilities. Inventories every webhook handler, plan-state mutation path, and state transition — then runs 12 canonical patterns across Stripe, Paddle, Lemon Squeezy, Chargebee, and Polar. Every P0/P1 finding ships with a runnable test using Stripe CLI trigger or synthetic constructEvent. ## What's included - **12 canonical billing-bug patterns audited per scan:** - Webhook signature verification (Stripe-Signature, paddle-signature, lemonsqueezy-signature) - bodyParser-runs-before-webhook bug (the silent killer — signature fails on parsed JSON) - Idempotency on event IDs (replay attacks credit balance N times) - Plan-state bypass (frontend trust, missing server-side recheck on critical endpoints) - Customer-mapping forgery (mapping by email lets attacker hijack billing on collision) - Race conditions on subscription state (concurrent webhooks → inconsistent plan) - Refund handler presence + correctness (silent revenue loss when missing) - Chargeback handler presence (charge.dispute.created — account remains entitled after chargeback) - Trial / coupon abuse (resignup with new email, coupon stacking, trial extension exploitation) - Test/live key leakage (env var sprawl, key in client bundle, key in logs) - Sensitive event filtering (PII in event logs, card last4 in error tracking) - Webhook retry exhaustion handling (provider gives up after N retries — your state diverges silently) - **Per-finding test cases** — runnable Stripe CLI trigger commands or constructEvent fixtures - **Severity ranking** — P0 (revenue-loss / account takeover) / P1 (silent state divergence) / P2 (defense-in-depth) - **Per-provider awareness** — Stripe + Paddle + Lemon Squeezy + Chargebee + Polar signature schemes and event shapes - **Remediation snippets** — copy-paste fixes in TypeScript / Python / Ruby / Go matched to your codebase ## Limitations - **Not a runtime monitor** — static + structured code review; pairs with Sentry / Datadog for runtime detection - **Not a SOC 2 audit** — surgical on billing; broader controls need a compliance audit - **Not legal counsel** — payment compliance questions (PCI scope, chargeback policy) need an attorney - **English-codebase-first** — comment-language matters less; identifier names matter more - **Not a fix-it bot by default** — produces findings + tests + remediation; merge is human-reviewed ## Best fit Indie + bootstrapped SaaS doing $5K-$500K MRR on Stripe / Paddle / Lemon Squeezy / Chargebee / Polar. Especially valuable for solo founders who built their own billing integration without payments-team review — the bodyParser-before-webhook bug, the customer-by-email mapping bug, and the missing-chargeback-handler bug are the three most expensive bugs in indie SaaS and almost every self-built integration has at least one. Catching them BEFORE the first chargeback wave pays for this agent forever.

Rent Stripe Webhook & Billing Security Auditor on AnyAIAgent →

Powered by AnyAIAgent — rent pre-built autonomous AI agents instead of configuring Claude Code, Codex, or OpenClaw from scratch.