- The product type is clearly identified.
- The intended use case is clearly explained.
- The target users are defined.
- Screenshots or a live demo are available.
- Included and excluded functionality is documented.
- The product is actively maintained.
- Programming language and version are specified.
- Framework and framework version are specified.
- Database requirements are documented.
- Frontend build requirements are documented.
- Required server extensions are listed.
- Supported operating systems or hosting environments are documented.
- Third-party services and API dependencies are listed.
- Browser and mobile compatibility are explained.
- The project has a clear directory structure.
- Configuration is separated from application code.
- Secrets are not hardcoded in the repository.
- Dependencies are documented.
- Dependencies are reasonably current.
- The code follows consistent conventions.
- Error handling is implemented.
- Logging is available.
- Automated tests are included or their absence is disclosed.
- Passwords are stored securely.
- Authentication and authorization are separated correctly.
- User input is validated.
- File uploads are restricted and validated.
- Database queries are protected against injection.
- Rate limiting is available where needed.
- Sensitive values are stored in environment variables.
- Dependencies have been checked for known vulnerabilities.
- Production debug mode can be disabled.
- Security-sensitive functionality has been reviewed.
- Installation documentation is included.
- Environment variables are documented.
- Database migrations or installation scripts are included.
- File and directory permissions are documented.
- Cron jobs are documented.
- Queue workers are documented.
- Build commands are documented.
- Production deployment steps are explained.
- Backup and recovery requirements are explained.
- A getting-started guide is included.
- Configuration options are documented.
- Common errors are documented.
- API documentation is available when relevant.
- Customization instructions are included.
- Update instructions are included.
- A changelog is available.
- The license type is clearly identified.
- Commercial use is explained.
- Client-project usage is explained.
- Domain or project limitations are explained.
- Modification rights are explained.
- Resale rules are explained.
- Source-code redistribution rules are explained.
- Third-party asset licenses are documented.
- The last update date is visible.
- The update period is specified.
- The support period is specified.
- Supported communication channels are identified.
- Response-time expectations are explained.
- Installation support is explained.
- Custom development is clearly separated from standard support.
- The seller has a complete public profile.
- Previous products or projects can be reviewed.
- Support and update history are visible.
- Contact information is available.
- Reviews appear authentic and relevant.
- Product claims can be independently verified.
Do not purchase or deploy the product until all critical technical, licensing and security questions have been answered.
Any unresolved requirement should be documented before the final decision.