TECHNOLOGIES: REMIX & REACT ROUTER

Remix and React Router Testing

A Remix or React Router action runs for any POST request, with no built-in check on where it came from. We test that gap, plus session cookies, environment exposure and resource routes. CREST-certified testers, fixed price from £2,520 for a 2-day single-application scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Remix and React Router Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
No CSRF

Remix and React Router leave a request’s origin unchecked, so stopping a forged cross-site POST, PUT, PATCH or DELETE from reaching an action is something your own code has to add.

Why a Remix or React Router action trusts every request that reaches it

A route’s loader runs on every GET request to fetch the data that route needs, and a route’s action is a server-only function that runs instead of the loader whenever a DELETE, PATCH, POST or PUT request arrives, which lets the data read, the component and the data write for one screen live in the same route module. A route file with no default export becomes a Resource Route instead: a GET to it returns only that route’s own loader response and skips every parent loader that would normally run for the page, and a POST calls its action the same way. We test every loader, action and resource route in scope against the request method it responds to and the data it is allowed to touch.

What was going to be Remix’s third major version shipped instead as React Router v7, which absorbed Remix’s full-stack framework mode, including server-side loaders, actions and server-side rendering, on top of the client-side routing React Router already handled. An app upgrading from Remix v2 keeps the same loader, action, session and resource route model under React Router’s framework mode, so we test the two as one stack: the same loader and action data flow, the same session and cookie handling, and the same environment variable boundary, whichever package name your app currently imports it from.

A route’s action is only as safe as the checks written inside it. Sessions built with createCookieSessionStorage read and write httpOnly, signed cookies that must stay under the browser’s 4KB size limit, and every loader or action that changes the session has to commit a fresh Set-Cookie header itself; nothing in the framework checks that a POST reaching an action actually originated from your own form, so cross-site request forgery protection on a state-changing action is left to the application. Environment variables follow the same server-first rule: the documented approach is to keep every value, secret or not, on the server and hand only what the browser genuinely needs back through a root loader into window.ENV, rather than bundling a variable into the client build directly.

SCOPE

What we pen test on a Remix or React Router application

RR-01

Loader Data Exposure and Route Access Control

A loader runs on every GET request to that route and returns whatever data the component needs, with params, request and context available to it, but nothing inside the loader model enforces who is allowed to call it. We test every loader in scope for data it returns to a session that should not be able to reach it.

RR-02

Action Functions and the Missing CSRF Check

An action is the server-only function that runs for a DELETE, PATCH, POST or PUT request to a route, and neither Remix nor React Router checks where that request actually came from. We test whether a state-changing action can be triggered by a request that did not originate from your own form.

RR-03

Resource Routes Without a Default Export

A route file with no default export becomes a Resource Route: a GET to it returns only that route’s own loader response and skips every parent loader that would normally run for the page, and a POST calls its action instead. We test whether an access check living in a parent loader is actually enforced again on the resource route sitting beneath it.

RR-04

Session Cookie Configuration via createCookieSessionStorage

createCookieSessionStorage reads and writes session data through cookie options including httpOnly, secure, sameSite, an expiry or maxAge, and a secrets array used to sign the cookie, all of which must fit within the browser’s 4KB cookie size limit. We test which of these flags is actually set against what the session is meant to protect.

RR-05

Cookie Session Storage Has No Server-Side Revocation

With createCookieSessionStorage the session data lives inside the cookie itself rather than in a database, so destroySession clears it on the client but there is no server-side store to revoke a single session early; rotating the secrets array is the only way to invalidate every existing session at once. We test how a logout, password change or compromised-session scenario is actually handled given that constraint.

RR-06

What Actually Reaches the Client Bundle

Loaders and actions run only on the server and are never bundled into the client-side JavaScript, which is what makes it safe to read a server secret with process.env inside one. We test the built client bundle for any server-only value, connection string or key that ended up in it regardless.

RR-07

Environment Variables Exposed via window.ENV

The documented pattern for giving the browser an environment variable is to return it from the root loader and attach it to window.ENV, so only the specific keys a developer chose to forward, such as a publishable API key, are ever exposed. We test what is actually returned through window.ENV against what the browser genuinely needs.

RR-08

Fetcher Submissions to Loaders and Actions

A fetcher submits to a loader or action without a page navigation or new browser history entry, using the same route module as a full-page Form submission would. We test whether an action reachable only through a fetcher enforces the same authentication and validation as the one reached from the page’s own form.

RR-09

Remix v2 and React Router v7 Framework Mode Together

Since React Router v7 absorbed Remix’s full-stack framework mode, an app’s loaders, actions, sessions and resource routes follow the same model whether it currently imports from Remix v2 or from React Router directly. We test that model as one stack and confirm which package and version the app is actually running.

RR-10

React Router’s Client-Side Routing Outside Framework Mode

React Router can also run in a plain client-rendered React application with no loaders, actions or server at all, just declarative or data-mode routing in the browser. Where that is how your app uses it, the routing itself carries a different risk profile, and the wider React application around it falls under our dedicated React review.

OUR PROCESS

Remix and React Router Applications Penetration Testing: From Scope to Attestation

01

Scope, Router and Session Mapping

We agree the app’s repository or environment, whether it runs Remix v2 or React Router’s framework mode, every loader, action and resource route in scope, and how sessions and cookies are configured.

02

Loader and Action Testing

We test every loader’s data exposure and every action’s request handling, including whether a state-changing action can be triggered without originating from your own form.

03

Manual Testing

A CREST-certified tester manually tests session cookie handling, environment variable exposure to the client bundle, resource routes and fetcher-based submissions.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Remix and React Router pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Remix and React Router Applications Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,520–£3,760
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£6,120–£9,180
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Remix and React Router Applications Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Remix or React Router app?

We need the app URL or repository access, test accounts for each session or role in scope, and read access to your loader and action code if you want environment variable exposure checked from source as well as from the running app.

Will testing touch our live data?

We test read-only against production by default. Where an action creates, updates or deletes real records, we agree a sandbox environment or specific test data with you first, and anything we create during testing is documented and removed afterwards.

How long does a Remix or React Router security review take?

A single application sits in our 2-day single-application scope, with a report typically landing around 5 working days after kickoff. Multiple applications in a monorepo, or a large number of resource routes, extend that scope.

Do you test Remix v2 and React Router v7 apps the same way?

Yes. Since React Router v7 absorbed Remix’s full-stack framework mode, the same loader, action, session and resource route model applies to both, and we test it the same way regardless of which package name your app currently imports.

What is out of scope?

The infrastructure hosting the application and any separate backend or API service your loaders and actions call are scoped and quoted separately. We test the loaders, actions, sessions, resource routes and client bundle you have built.

Do you need our source code?

No. Testing is black-box against the running application by default. A grey-box option, where we review the relevant loader, action and session-handling code alongside testing, is available for faster or deeper coverage of specific findings.

Does Remix or React Router have a customer penetration-testing policy?

Remix and React Router are open-source libraries with no testing policy of their own. Where the app is hosted on a serverless, edge or managed platform, we confirm that host’s current terms during scoping before testing begins.

Do you specifically test for CSRF?

Yes. Since neither framework includes built-in CSRF protection, we test whether each state-changing action can be triggered by a cross-site request, and whether session and cookie settings such as SameSite actually reduce that risk.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Remix or React Router application

A Remix or React Router action runs for any POST request, with no built-in check on where it came from. We test that gap, plus session cookies, environment exposure and resource routes. CREST-certified testers, fixed price from £2,520 for a 2-day single-application scope, quoted within 24 hours.