It's good that no leaked keys were found in the front end code but the developer wasn't able to look at the backend where, if the quality of the front end is any indication, there are likely to be many security issues. Hopefully it's not all running on the same servers/network as anything important.