1. No secrets in source, env files, or bundles
App Router makes it one prefix away from a leak: anything imported into a client component must be NEXT_PUBLIC_-safe — and AI tools get this wrong constantly.
env-file-committedhardcoded-api-keyssecrets-in-client-bundlegit-history
2. Every route handler enforces auth server-side
app/api/* handlers are public endpoints. Middleware alone is a gate, not authorization — and client-side role checks are a UI state, not security.
3. No raw queries or raw HTML from user input
Template-string $queryRaw and dangerouslySetInnerHTML are the two classic AI-generated Next.js holes.
sql-injectionraw-html-renderunvalidated-inputmass-assignment
4. Server fetches don't take user-supplied URLs
A route handler that fetches whatever URL the request names is an SSRF pivot into your internal network.
5. Webhooks verify signatures; uploads have gates
Stripe/Resend webhooks must be verified against the raw body; upload routes need type and size limits.
6. Hosted databases are policy-protected
Supabase/Postgres via Drizzle is the default AI-stack database — RLS and policies are what stand between the anon key and your rows.
7. The public surface is tightened
Wildcard CORS, live debug routes, a served /.git, stack traces with paths, missing HTTPS/HSTS — all visible to strangers the moment you deploy.
cors-wide-opendebug-endpoint-livegit-directory-exposedhttps-hstsstack-trace-leak
8. Dependencies are real, current, and mitigated
Invented imports (hallucinated packages) and framework CVEs that need a code-level fix both live below what npm audit reports.
dependency-vulnerabilityframework-cve-middlewarehallucinated-dependency
9. CI workflows can't leak secrets
pull_request_target + PR-head checkout with secrets in the same job is the pattern behind real supply-chain attacks.
10. Payment and cron paths are server-trusted
Amounts computed on the client and cron endpoints without auth are money bugs — literally.
Ten items, ~40 concrete failure patterns — more than a coffee break to verify by hand, and exactly what the scan does in about two minutes.