Two-sided marketplaces — Etsy-style storefronts, Airbnb-style booking platforms, freelance and gig platforms, food and grocery delivery — all do something a single-seller app never has to: hold and split money between two parties who've never met. AI builders wire up Stripe Connect payment splits, seller payouts, and dispute flows fast, but the same 45% AI-code vulnerability rate (Veracode) and the row-level security gaps behind Lovable's CVE-2025-48757 apply directly to the shared orders and payouts table every seller on your platform reads from.
A marketplace is two apps in a trench coat — a buyer-facing storefront and a seller-facing payout system — sharing one database. Here's where AI-built marketplaces typically fall short.
Every marketplace transaction moves money between a buyer and a seller who have never met, usually through Stripe Connect or a similar split-payment API. AI builders wire up the "charge card, hold funds, release to seller" flow to work on the happy path, but skip the edge cases — partial refunds, failed payouts, orders canceled mid-transfer — that decide who's actually holding the money when something goes wrong.
Stripe Connect and similar platforms push identity verification onto the marketplace operator, not the processor. AI-generated onboarding flows commonly skip required Connect fields, business-type checks, or verification wait states, letting a seller start accepting payments before you actually know who they are — a gap that becomes your liability the moment a stolen identity or shell account starts collecting payouts.
Refund and dispute flows touch three balances at once — buyer, seller, and platform — and AI-scaffolded logic rarely gets all three right. Double refunds, refunds that never reverse the seller's payout, or chargebacks that silently drain the platform's own Stripe balance are common outcomes of code tested against the "refund works" case and nothing else.
Escape.tech's October 2025 scan of 5,600+ vibe-coded apps found 400+ exposed secrets sitting in client-side code or public repos. A leaked Stripe Connect secret key doesn't just expose your account — it can expose every connected seller account's balance and payout details behind it.
Lovable's CVE-2025-48757 found row-level security disabled in roughly 70% of the apps it affected, letting anyone query the database with the public anon key. On a marketplace, that same default means Seller A's login — or an unauthenticated request — can pull Seller B's order history, customer list, and payout totals straight out of the shared orders/payouts table.
Stripe and similar processors sign every webhook event so you can confirm it actually came from them. AI-generated webhook handlers routinely skip signature verification entirely, since the endpoint "works" without it — leaving payout-confirmation and dispute-resolution logic open to anyone who can guess the URL and POST a fake event.
Fee and commission math — splitting an order into an 85/15 seller/platform cut, minus processor fees, minus tax — is exactly the kind of multi-step arithmetic AI-generated code gets subtly wrong under refunds or partial cancellations. On top of that, most US states now have marketplace facilitator laws requiring the platform itself, not the seller, to collect and remit sales tax once you cross that state's revenue threshold — an obligation that has nothing to do with your code being secure and everything to do with it being unbuilt.
| What you built | Hidden risk |
|---|---|
| Two-sided storefront (Etsy-style) | Row-level security gaps expose other sellers' orders and payouts |
| Stripe Connect payment split | Miscalculated commission; unverified webhook signatures |
| Seller onboarding / KYC flow | Weak identity verification before payouts begin |
| Dispute / refund center | Refund logic breaks the seller's payout and the platform's balance alike |
| Booking or gig marketplace (2-sided scheduling) | Buyer and provider PII queryable across accounts |
| Admin / ops dashboard | Over-broad access to every seller's financials at once |
Four things we check on every marketplace audit, regardless of which payment processor or database you're running.
Funds held and released correctly across full payments, partial refunds, and canceled orders — with a reconciled ledger, not just a Stripe dashboard that looks fine.
Every seller verified before their first payout, with Stripe Connect's required onboarding fields enforced, not skipped to keep signup frictionless.
Row-level security tested so one seller's login can never return another seller's orders, customers, or payout history.
Refund, chargeback, and cancellation logic that keeps buyer, seller, and platform balances in sync, with webhook signatures verified on every event.
Not automatically. Stripe Connect keeps raw card data out of your servers, which helps your PCI scope, but it doesn't check your onboarding flow, your database access controls, or your webhook handling. A marketplace can be fully tokenized for cards and still leak every seller's payout history through a missing row-level security policy.
Yes, if row-level security isn't enabled and enforced on your orders and payouts tables. Lovable's CVE-2025-48757 found this exact misconfiguration in roughly 70% of the apps it affected, and a marketplace's shared orders table is precisely the kind of data that pattern exposes.
If your platform collects payment on behalf of sellers, most US states now legally treat you as a "marketplace facilitator" and require you — not the individual seller — to collect and remit sales tax once you cross that state's revenue or transaction threshold. It's a tax-law question, not a code bug, but it's one most AI-built marketplaces never get configured for.
Yes, regardless of size. An unverified webhook endpoint will process any POST request that matches its expected shape, meaning anyone who finds the URL can fake a "payment succeeded" or "payout completed" event. We check this in every marketplace audit because it's commonly skipped and easy to fix once found.
No. We work inside what's already built and with whatever processor you're already using — Stripe Connect or otherwise. The scan and audit tell us exactly what to fix, and remediation keeps your existing marketplace, sellers, and transaction history intact.
The scan is free. A full audit starts, scoped to exactly what the scan finds.
Get a free scan of your marketplace, booking platform, or gig app — plain-English results, no obligation.
Start With a Free Scan →