How to audit a Next.js app in 2026
Is .env.local being served?
Deeper than a manual audit or a tool. At the scale AI agents attack.
The audit starts after signup. $49 for one month. Your report stays in your account.
- Next.js fingerprint
- Known CVEs
- Env files
- Headers and static files
01 / 08·running
Public surface
Other hosts and open ports
Signals
- Next.js fingerprintBuild and cache headers that name Next.js, and the version when it is there.
- Known CVEsPublished holes when that version is visible.
- Env files.env.local and .env.production sitting where the site can serve them.
- Headers and static filesMissing security headers, open static folders, and the image optimizer.
How the Next.js audit runs
What else is on this domain
Other hostnames on the same domain, then the ports those servers leave open, before anything Next.js-specific.
Subdomains
Staging, old admin hosts, and the other names on your domain.
Live hosts
Which of those names actually answer.
Open ports
What is listening, including the version when the server says it.
On your Next.js
Whether this is Next.js, which version the headers reveal, and whether env files or directory listings are being served.
Next.js fingerprint
Build and cache headers that name Next.js, and the version when it is there.
Known CVEs
Published holes when that version is visible.
Env files
.env.local and .env.production sitting where the site can serve them.
Headers and static files
Missing security headers, open static folders, and the image optimizer.
A report you can act on
Each issue names the host, shows the evidence, and says what to fix. Anything we could not confirm stays marked that way.
Evidence
The URL or file that proved it.
CVE ids
Only when we saw the version the advisory is about.
Account
The report opens after the $49 month is paid.
Questions about a Next.js audit
What the run covers, and when the report opens in the account.
Contact usAudit Next.js from the outside.
Deeper than a manual audit or a tool. At the scale AI agents attack.