Remix and React Router Testing
A Remix or React Router action runs for any POST request, with no built-in check on where it came from. We test that gap, plus session cookies, environment exposure and resource routes. CREST-certified testers, fixed price from £2,520 for a 2-day single-application scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Remix and React Router leave a request’s origin unchecked, so stopping a forged cross-site POST, PUT, PATCH or DELETE from reaching an action is something your own code has to add.
Why a Remix or React Router action trusts every request that reaches it
A route’s loader runs on every GET request to fetch the data that route needs, and a route’s action is a server-only function that runs instead of the loader whenever a DELETE, PATCH, POST or PUT request arrives, which lets the data read, the component and the data write for one screen live in the same route module. A route file with no default export becomes a Resource Route instead: a GET to it returns only that route’s own loader response and skips every parent loader that would normally run for the page, and a POST calls its action the same way. We test every loader, action and resource route in scope against the request method it responds to and the data it is allowed to touch.
What was going to be Remix’s third major version shipped instead as React Router v7, which absorbed Remix’s full-stack framework mode, including server-side loaders, actions and server-side rendering, on top of the client-side routing React Router already handled. An app upgrading from Remix v2 keeps the same loader, action, session and resource route model under React Router’s framework mode, so we test the two as one stack: the same loader and action data flow, the same session and cookie handling, and the same environment variable boundary, whichever package name your app currently imports it from.
A route’s action is only as safe as the checks written inside it. Sessions built with createCookieSessionStorage read and write httpOnly, signed cookies that must stay under the browser’s 4KB size limit, and every loader or action that changes the session has to commit a fresh Set-Cookie header itself; nothing in the framework checks that a POST reaching an action actually originated from your own form, so cross-site request forgery protection on a state-changing action is left to the application. Environment variables follow the same server-first rule: the documented approach is to keep every value, secret or not, on the server and hand only what the browser genuinely needs back through a root loader into window.ENV, rather than bundling a variable into the client build directly.
SCOPE
What we pen test on a Remix or React Router application
Loader Data Exposure and Route Access Control
A loader runs on every GET request to that route and returns whatever data the component needs, with params, request and context available to it, but nothing inside the loader model enforces who is allowed to call it. We test every loader in scope for data it returns to a session that should not be able to reach it.
Action Functions and the Missing CSRF Check
An action is the server-only function that runs for a DELETE, PATCH, POST or PUT request to a route, and neither Remix nor React Router checks where that request actually came from. We test whether a state-changing action can be triggered by a request that did not originate from your own form.
Resource Routes Without a Default Export
A route file with no default export becomes a Resource Route: a GET to it returns only that route’s own loader response and skips every parent loader that would normally run for the page, and a POST calls its action instead. We test whether an access check living in a parent loader is actually enforced again on the resource route sitting beneath it.
Session Cookie Configuration via createCookieSessionStorage
createCookieSessionStorage reads and writes session data through cookie options including httpOnly, secure, sameSite, an expiry or maxAge, and a secrets array used to sign the cookie, all of which must fit within the browser’s 4KB cookie size limit. We test which of these flags is actually set against what the session is meant to protect.
Cookie Session Storage Has No Server-Side Revocation
With createCookieSessionStorage the session data lives inside the cookie itself rather than in a database, so destroySession clears it on the client but there is no server-side store to revoke a single session early; rotating the secrets array is the only way to invalidate every existing session at once. We test how a logout, password change or compromised-session scenario is actually handled given that constraint.
What Actually Reaches the Client Bundle
Loaders and actions run only on the server and are never bundled into the client-side JavaScript, which is what makes it safe to read a server secret with process.env inside one. We test the built client bundle for any server-only value, connection string or key that ended up in it regardless.
Environment Variables Exposed via window.ENV
The documented pattern for giving the browser an environment variable is to return it from the root loader and attach it to window.ENV, so only the specific keys a developer chose to forward, such as a publishable API key, are ever exposed. We test what is actually returned through window.ENV against what the browser genuinely needs.
Fetcher Submissions to Loaders and Actions
A fetcher submits to a loader or action without a page navigation or new browser history entry, using the same route module as a full-page Form submission would. We test whether an action reachable only through a fetcher enforces the same authentication and validation as the one reached from the page’s own form.
Remix v2 and React Router v7 Framework Mode Together
Since React Router v7 absorbed Remix’s full-stack framework mode, an app’s loaders, actions, sessions and resource routes follow the same model whether it currently imports from Remix v2 or from React Router directly. We test that model as one stack and confirm which package and version the app is actually running.
React Router’s Client-Side Routing Outside Framework Mode
React Router can also run in a plain client-rendered React application with no loaders, actions or server at all, just declarative or data-mode routing in the browser. Where that is how your app uses it, the routing itself carries a different risk profile, and the wider React application around it falls under our dedicated React review.
OUR PROCESS
Remix and React Router Applications Penetration Testing: From Scope to Attestation
Scope, Router and Session Mapping
We agree the app’s repository or environment, whether it runs Remix v2 or React Router’s framework mode, every loader, action and resource route in scope, and how sessions and cookies are configured.
Loader and Action Testing
We test every loader’s data exposure and every action’s request handling, including whether a state-changing action can be triggered without originating from your own form.
Manual Testing
A CREST-certified tester manually tests session cookie handling, environment variable exposure to the client bundle, resource routes and fetcher-based submissions.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Remix and React Router pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Remix and React Router Applications Penetration Testing Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 5 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Remix and React Router For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Remix and React Router Applications Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Remix or React Router app?
We need the app URL or repository access, test accounts for each session or role in scope, and read access to your loader and action code if you want environment variable exposure checked from source as well as from the running app.
Will testing touch our live data?
We test read-only against production by default. Where an action creates, updates or deletes real records, we agree a sandbox environment or specific test data with you first, and anything we create during testing is documented and removed afterwards.
How long does a Remix or React Router security review take?
A single application sits in our 2-day single-application scope, with a report typically landing around 5 working days after kickoff. Multiple applications in a monorepo, or a large number of resource routes, extend that scope.
Do you test Remix v2 and React Router v7 apps the same way?
Yes. Since React Router v7 absorbed Remix’s full-stack framework mode, the same loader, action, session and resource route model applies to both, and we test it the same way regardless of which package name your app currently imports.
What is out of scope?
The infrastructure hosting the application and any separate backend or API service your loaders and actions call are scoped and quoted separately. We test the loaders, actions, sessions, resource routes and client bundle you have built.
Do you need our source code?
No. Testing is black-box against the running application by default. A grey-box option, where we review the relevant loader, action and session-handling code alongside testing, is available for faster or deeper coverage of specific findings.
Does Remix or React Router have a customer penetration-testing policy?
Remix and React Router are open-source libraries with no testing policy of their own. Where the app is hosted on a serverless, edge or managed platform, we confirm that host’s current terms during scoping before testing begins.
Do you specifically test for CSRF?
Yes. Since neither framework includes built-in CSRF protection, we test whether each state-changing action can be triggered by a cross-site request, and whether session and cookie settings such as SameSite actually reduce that risk.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Remix or React Router application
A Remix or React Router action runs for any POST request, with no built-in check on where it came from. We test that gap, plus session cookies, environment exposure and resource routes. CREST-certified testers, fixed price from £2,520 for a 2-day single-application scope, quoted within 24 hours.



