"What simpleCart(js) Does Not Do:
Is Not: Foolproof
Clever hackers can change prices of simpleCart(js) items before checkout. This is a known security flaw that exists with ALL javascript shopping carts. It is highly recommended that all orders be checked upon receiving or backend security checks be put in place (View Tutorial.)"
For simple, small online stores, I think this could be a nice option.
Then on your confirmation page, just have a nice "Thank you for your donation. Unfortunately, you won't be receiving any goods. Please see our TOS for details."
Probably illegal though >_>
Why would the creator have overlooked such an important factor?
server-side + js = node
Just because it's JavaScript doesn't mean it should be in npm, similar to just because a project is written in ruby doesn't mean it should be in rubygems. A lot of the time, there's no reason for a ruby project to be bundled as a gem - it just ends up polluting an already crowded package management ecosystem. I wasn't sure if there was something I might have missed about npm. To me, it seems like it would be something that would be better managed with Bower ( http://twitter.github.com/bower/ ) given you don't (and shouldn't!) need npm in order to use it.
In that context, my reply means that since hayksaakian started with the assumption that it was server side, it's only logical that he would conclude the js to be a node module since server-side javascript's most popular implementation is node. Of course, looking back I see that I may have misread hayksaakian's reply.