For complete security with Express Check, you will need some kind of server language. The express order is not intended to be used only with HTTP POST and GET requests because your API credentials are required, which can be viewed in POST / GET.
But express check essentially has 3 API calls, Set, Get, Do.
Digital Goods Express Checkout , Express Checkout, , iframes -.