Looking at the code, it reads like it was written by LLM: chatty commit messages, lack of spelling/capitalization errors, bullet points galore, shit-ton of "Fix X" commits that don't read like they're increasingly-frustrated, worthless comments randomly scattered like "i + 1 // add 1 to i" without any other comments on the page.
No security review because none of the code has been reviewed and he doesn't know what's in it.
++this.
If you're already driving around with a mask and a gun kidnapping people, why not get some extra money on the side with robbery?