web/nextjs

Free catalog · v0.0.14

Reviews Next.js configuration for unsafe remote content, exposed source maps, and framework boundary risks.

Checks

RuleSeverityScans for
nextjs.build-errors-ignoredMediumType and lint errors suppressed at build time
nextjs.framework-control-flow-caughtHighA broad catch can consume a framework-owned signal from redirect, permanentRedirect, or notFound
nextjs.middleware-auth-bypassCriticalAuth enforced in middleware on a Next.js version vulnerable to the middleware bypass
nextjs.production-sourcemapsMediumBrowser source maps enabled for production builds
nextjs.public-env-secretHighSecret-shaped values exposed through NEXT_PUBLIC_ env vars
nextjs.wildcard-imagesMediumImage optimizer remote patterns wildcarded

More from the registry