Verifying a donation?

I got a “ProcessBits()” function that processes any Bit event from PubSub. What if someone edits the javascript code to make it get called frequently (e.g. each second)? This is going to send the correct the UserID and the fake information.