From a security standpoint, CGI::Carp qw(fatalsToBrowser) isn't a great idea in production. You should consider logging instead. fatalsToBrowser makes sense during development (quickly see when code fails), but in production it's just another avenue for your website's users to gather information about the internal workings of your site.
Comment on Re: Structuring a Web site and security issues