What it is
Next.js makes it easy to add headers in `next.config.js`, but the source pattern decides which routes get them. A rule that protects the homepage can still miss an API route, dashboard path, or nested page.
How it happens
Next.js applies the headers in next.config.js by matching each route against a source pattern. A pattern that covers the homepage can miss nested pages, API routes, or the dashboard, so CSP, HSTS, frame protection, and nosniff quietly disappear on the routes that hold real user data. A leftover `X-Powered-By: Next.js` banner also tells attackers which framework to target.
What an attacker gets
Header drift weakens defense-in-depth exactly where real app behavior lives: dashboards, API routes, and nested pages. Missing CSP leaves XSS with fewer guardrails, missing frame protection invites clickjacking, and framework banners give attackers cleaner fingerprinting.
// what fixvibe reports
What FixVibe reports
Runs in active scans of a domain you have verified you own, on Hobby and above. Each finding shows the affected URL or host, its severity and fix steps you can paste into your AI coding tool.
How to fix it
Set `poweredByHeader: false` and use broad `/:path*` header coverage for site-wide protections, with explicit exceptions only where needed. Verify root, nested, and API routes after deploy.
