DevMeth

App Router · route handlers · Supabase

The Next.js security checklist for AI-built apps

Ten things to verify before a Next.js app takes real traffic. Each item names the exact failure pattern and links the DevMeth check that automates it — so the checklist is also the scan.

1. No secrets in source, env files, or bundles

App Router makes it one prefix away from a leak: anything imported into a client component must be NEXT_PUBLIC_-safe — and AI tools get this wrong constantly.

env-file-committedhardcoded-api-keyssecrets-in-client-bundlegit-history

2. Every route handler enforces auth server-side

app/api/* handlers are public endpoints. Middleware alone is a gate, not authorization — and client-side role checks are a UI state, not security.

authless-api-routeadmin-page-openclient-side-roleidor

3. No raw queries or raw HTML from user input

Template-string $queryRaw and dangerouslySetInnerHTML are the two classic AI-generated Next.js holes.

sql-injectionraw-html-renderunvalidated-inputmass-assignment

4. Server fetches don't take user-supplied URLs

A route handler that fetches whatever URL the request names is an SSRF pivot into your internal network.

ssrf

5. Webhooks verify signatures; uploads have gates

Stripe/Resend webhooks must be verified against the raw body; upload routes need type and size limits.

webhook-signatureupload-endpoint

6. Hosted databases are policy-protected

Supabase/Postgres via Drizzle is the default AI-stack database — RLS and policies are what stand between the anon key and your rows.

supabase-rlsbrowser-direct-databasepublic-storage-bucket

7. The public surface is tightened

Wildcard CORS, live debug routes, a served /.git, stack traces with paths, missing HTTPS/HSTS — all visible to strangers the moment you deploy.

cors-wide-opendebug-endpoint-livegit-directory-exposedhttps-hstsstack-trace-leak

8. Dependencies are real, current, and mitigated

Invented imports (hallucinated packages) and framework CVEs that need a code-level fix both live below what npm audit reports.

dependency-vulnerabilityframework-cve-middlewarehallucinated-dependency

9. CI workflows can't leak secrets

pull_request_target + PR-head checkout with secrets in the same job is the pattern behind real supply-chain attacks.

ci-secret-exposure

10. Payment and cron paths are server-trusted

Amounts computed on the client and cron endpoints without auth are money bugs — literally.

payment-amountpublic-cron-endpoint

Ten items, ~40 concrete failure patterns — more than a coffee break to verify by hand, and exactly what the scan does in about two minutes.

DevMeth checks the 48 known AI-code failure patterns — not a penetration test or a security guarantee.

Check your app — free

10 Critical checks, no signup, results in about two minutes. Every finding is masked and carries a paste-ready fix prompt.

Run the free scan