FixVibe

// probes / spotlight

Next.js Header Configuration Drift

Headers set on `/` do not always protect nested routes.

What it is

Next.js makes it easy to add headers in `next.config.js`, but the source pattern decides which routes get them. A rule that protects the homepage can still miss an API route, dashboard path, or nested page.

How it happens

Next.js applies the headers in next.config.js by matching each route against a source pattern. A pattern that covers the homepage can miss nested pages, API routes, or the dashboard, so CSP, HSTS, frame protection, and nosniff quietly disappear on the routes that hold real user data. A leftover `X-Powered-By: Next.js` banner also tells attackers which framework to target.

What an attacker gets

Header drift weakens defense-in-depth exactly where real app behavior lives: dashboards, API routes, and nested pages. Missing CSP leaves XSS with fewer guardrails, missing frame protection invites clickjacking, and framework banners give attackers cleaner fingerprinting.

// what fixvibe reports

What FixVibe reports

Runs in active scans of a domain you have verified you own, on Hobby and above. Each finding shows the affected URL or host, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Set `poweredByHeader: false` and use broad `/:path*` header coverage for site-wide protections, with explicit exceptions only where needed. Verify root, nested, and API routes after deploy.

// run it on your own app

Terus rilis sementara FixVibe yang berjaga.

Verify you own the domain, then run active checks alongside the passive ones.

Probe aktif
138
tes yang dijalankan di kategori ini
modules
58
check probe aktif khusus
verified domains
130+
active checks after verification
Verify your domain →

// latest checks · practical fixes · ship with confidence

Next.js Header Configuration Drift: what it is and how to fix it · FixVibe