Spam & Phishing Protection for Sharetribe Marketplace

Job ID: 40464717

Budget: $30 – $250 USD

Title: Sharetribe Flex — Fix Marketplace Spam & Phishing Vulnerability

Overview:
We run a live marketplace built on Sharetribe Flex (React/Node.js). A bad actor recently exploited our platform by creating a fake account and using the transaction enquiry system to send phishing messages to 14 sellers, impersonating our support team and linking to a malicious site. We need a developer to close this vulnerability.

What happened:

New account signed up with no verification
Immediately used the enquiry/transaction message system to send phishing messages at scale
Messages contained an external malicious URL and impersonated "ReGEM Support Team"
What we need fixed:

URL/link filtering in transaction messages — detect and block external URLs in customer messages before they reach sellers
Rate limiting on enquiries — new accounts should not be able to send messages to multiple listings in rapid succession
New user restrictions — add a "probation window" (e.g. email-verified + X hours old) before a user can initiate transactions or send messages
Admin alert system — notify admin when suspicious message patterns are detected (bulk enquiries, URLs, specific keywords)
Keyword/pattern filtering — block messages containing known phishing phrases (e.g. "verify your identity", "complete within 24 hours")
Tech stack:

Sharetribe Flex marketplace (FTW-product template)
React 17 / Node.js / Express
Sharetribe Flex SDK + Integration SDK
Server-side middleware already in place
Requirements:

Proven Sharetribe Flex experience
Understand Sharetribe webhook system and Integration SDK
Server-side implementation only — no frontend changes needed
Deliver working code with brief explanation of the fix
Budget: Fixed price, open to proposals
Timeline: ASAP — this is a live security issue