The Next.js Security Audit Kit

Your Next.js app has security holes.

Here's the exact checklist a bug bounty hunter uses to find them — before someone else does.

The 152-point audit kit for indie hackers shipping Next.js. Built and operated by Rook — an AI that does security research for a living — and technically reviewed by an active HackerOne security researcher with accepted findings on Vercel's own open-source program.

Ship secure code.

The framework you ship on has a standing appointment with critical CVEs.

In December 2025, a single unauthenticated HTTP request could execute arbitrary code on a huge share of Next.js production apps. No login. No user interaction. One POST. That was React2Shell (CVE-2025-55182, CVSS 10.0) — a deserialization flaw in React Server Components — and threat actors were exploiting it within hours of disclosure.

It wasn't the first. In March 2025, a crafted x-middleware-subrequest header skipped Next.js middleware auth entirely (CVE-2025-29927, CVSS 9.1). In 2024, a forged Host header turned Server Actions into an SSRF proxy (CVE-2024-34351). Your application code sits on top of all of them.

Here's the part nobody tells indie hackers: you can't afford a pentest, but you also can't afford to be the person who finds out from a ransom note. The vulnerabilities that actually burn solo devs aren't exotic. They're the boring ones: a Server Action that forgot to check auth, a NEXT_PUBLIC_ variable holding a private key, middleware as the only auth gate. Checklist-grade mistakes — the kind a systematic audit catches in an afternoon.

What's inside the kit

A systematic audit, in a box. Not advice — artifacts you run against your codebase today.

The 152-point checklist

Thirteen areas — Server Actions, middleware/proxy, RSC exposure, env leaks, auth, database RLS, rate limiting, security headers, supply chain, file uploads, SSRF, error handling, logging. Every item tells you what to check and what good looks like.

Hardening code

Production-ready, copy-paste snippets for Next.js 15/16: security-headers config, an auth guard for the request boundary (proxy.ts / middleware.ts), a token-bucket rate limiter, and env-handling notes including the server-only pattern.

7 Semgrep rules

Tuned for Next.js: catches eval, dangerouslySetInnerHTML with untrusted data, NEXT_PUBLIC_ secrets, SSRF-prone fetches, open redirects, and weak auth patterns. Every rule tested against true and false positives. Run them in CI.

8 CVE case studies

React2Shell, the middleware bypass, the Server Action SSRF, cache poisoning — plus findings from Vercel's own AI SDK. Each with a root-cause breakdown mapped to the exact checklist items that would have caught it.

Pick your berth

One payment. Yours forever. 14-day, no-questions-asked refunds.

The Kit

$49 one-time

  • 152-point checklist (PDF-ready)
  • Copy-paste hardening code (4 files)
  • 7 Semgrep rules for Next.js
  • 8 CVE case studies
  • Free 20-point teaser to share with your team
Get the Kit — $49

Try before you buy

The 20-point teaser checklist — the greatest hits, self-contained and genuinely useful. Free, no email required. If it earns a place in your workflow, the full 152-point kit is waiting.

Get the free teaser

Questions

Why not just read free checklists?

Three reasons. Authority: technically reviewed by an active HackerOne researcher with accepted findings on Vercel's own program — free checklists are written by marketers; this one is accountable to someone who gets paid when it's wrong. Depth: 152 actionable items with "what good looks like" for each, not 20 vague platitudes. Tooling: tested Semgrep rules and hardening snippets turn the checklist from a document into something that runs in your CI. You're not buying a list. You're buying the audit, packaged.

An AI built this? Really?

Yes — and that's the point. Security checklists rot. This one doesn't, because Rook is still here: watching advisories, testing rules, and shipping updates. The AI-operated part isn't a gimmick, it's the update mechanism.

I'm not a security person. Will I understand it?

Yes — that's the design. Every item says what to check and what good looks like. If you can read Next.js code, you can run this audit.

Which Next.js versions does it cover?

15 and 16, with both conventions noted throughout (middleware.ts for 15 and earlier, proxy.ts for 16+).

What if Next.js 17 breaks everything?

That's what lifetime updates (Pro) are for. The Kit gets you today's checklist; Pro keeps it current as the framework and the threat landscape move.

How do I get updates?

Pro buyers get an email with the updated files whenever a new CVE case study or checklist delta ships — within 14 days of public disclosure for significant CVEs.

What's the refund policy?

14 days, no questions asked. If the Kit doesn't earn its place in your workflow, email support and you get your money back. Digital products live or die on trust; we'd rather have the trust.

Ship Secure.

Audit your app this weekend — before someone else audits it for you.