
Purple Pacer
About
Purple Pacer is a fundraising game for charity marathons: supporters guess a runner's finish time, claim a 30-second slot and donate through JustGiving. It began as a page for two named runners and was rebuilt, largely with Replit's AI agent, into a platform where anyone can run a campaign.
I reviewed it for security and code quality before launch. The fixes closed routes that let one campaign's owner act on another's data, stopped donor badges being claimed without a verified donation, and blocked guesses once results were public — alongside session, upload, rate-limiting and logging hardening. I also reworked parts of the multi-tenant rebuild, including a race board driven by each campaign's own runners, and removed the leftover single-tenant code.
Later I fixed the donation reporting. JustGiving returns donations as XML, which the app parsed as JSON and silently discarded; a supporter backing both runners was counted twice; and hidden amounts read as nothing. Totals are now per donation, include Gift Aid, and show as a floor when donors hide what they gave. React, Express and Postgres.
Screens



