Next.js security checklist
Next.js is the most common framework behind AI-built apps, from v0 to Cursor projects. It gives you good building blocks, but security headers, cookie settings and what ends up in the client bundle are up to you.
Common security risks in Next.js apps
1. Secrets in NEXT_PUBLIC_ variables
Anything prefixed
NEXT_PUBLIC_is inlined into the client bundle at build time. A secret stored that way is public, even if no page displays it.2. No security headers
Next.js sends no Content-Security-Policy or HSTS by default. Add them with the
headers()option innext.config, or inproxy.ts(calledmiddleware.tsbefore Next.js 16), which a nonce-based CSP needs.3. Production source maps
With
productionBrowserSourceMapsenabled, your original source is downloadable by anyone.4. Route handlers and server actions without checks
Route handlers and server actions are public endpoints. Each one has to verify the session and the user's permission, not just the page that calls it.
5. Loose cookies and caching of private pages
Auth cookies need Secure, HttpOnly and SameSite. Pages with private data should not be cached by a CDN.
What a FixPrompt scan checks
Passive checks on your public site, the same way a visitor's browser loads it. No attacks, no logins, no data queried.
- Content-Security-Policy strength, HSTS (age and subdomains), X-Frame-Options / frame-ancestors, nosniff, Referrer-Policy and Permissions-Policy
- Secret key patterns in the client bundle, including values that leaked through public env vars
- Public source maps
- Session cookie flags and caching headers on login pages
- API paths that answer anonymous requests and missing rate-limit headers
Copy-paste fix prompt
Paste this into Claude Code, Cursor, Codex or any coding agent with access to your repository. A scan gives you a prompt tailored to the issues found on your live site.
Fix prompt
Harden this Next.js app: 1. List every NEXT_PUBLIC_ environment variable. Move any secret to a server-only variable, use it only in server code, and tell me which keys to rotate. 2. Add security headers in proxy.ts (middleware.ts before Next.js 16): a nonce-based Content-Security-Policy, Strict-Transport-Security with includeSubDomains, frame-ancestors 'none', X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin and a restrictive Permissions-Policy. 3. Make sure productionBrowserSourceMaps is off. 4. In every route handler and server action, verify the session and the user's permission before reading or changing data. 5. Set auth cookies with Secure, HttpOnly and SameSite=Lax, and mark private pages as no-store. Explain each change and how to check it in the browser's network tab.
FAQ
- Does Next.js add security headers by default?
- No. Content-Security-Policy, HSTS and the other security headers have to be configured. It does send X-Powered-By: Next.js by default, which you can remove with poweredByHeader: false.
- Are NEXT_PUBLIC_ variables safe for API keys?
- Only for keys that are designed to be public, such as a Supabase anon key or an analytics ID. Secret keys must stay in server-only variables.
- Does FixPrompt work with Next.js on Vercel, Netlify or Cloudflare?
- Yes. The scan looks at the deployed site, and the report tells your coding agent where headers are configured for the host it detects.
Check your Next.js app in minutes
Paste your URL and get a plain-English report with prioritized risks and a fix prompt for your AI. Your first scan is free.
Scan my app free