What to look for.
CORRECTNESS
Does it do what it claims?
Are edge cases handled: empty, missing, very long, unexpected?
What happens on failure?
SECURITY
Is every input validated on the server? Are queries parameterised? Is output escaped for its context? Is authorisation checked on the record, not only authentication? Are secrets absent from the code?
ACCESSIBILITY
Native elements used where possible? Keyboard operable? Focus visible and managed? Names on interactive elements? Contrast adequate?
PERFORMANCE
Anything large added? New dependencies justified? Images sized and optimised? Queries inside loops?
MAINTAINABILITY
Clear names? Reasonable size? Anything duplicated that should be shared?
WHAT NOT TO SPEND TIME ON
Formatting, which a tool should handle.
WHAT TO AUTOMATE BEFORE REVIEW
Formatting, linting, type checking, tests.
WHY
So review addresses what only a person can judge.