- Code is easy to understand and conforms with Prettier & eslint configs
- Incomplete code is marked with TODOs
- Code is suitably instrumented with logging and metrics
- Documentation has been updated as appropriate
- Manifest has been updated and version incremented correctly
- OWASP Top 10 have been considered