What it is
Vercel makes every deployment easy to preview. That convenience becomes a risk when a staging build, branch deployment, or generated fallback URL is shared externally, indexed, or archived without Deployment Protection.
How it happens
Every Vercel deployment gets a generated `*.vercel.app` URL, and preview deployments get one per branch or commit. Unless Deployment Protection is on, anyone who has one of those URLs can open the deployment, and the URLs travel: they end up in shared links, pull-request comments, search indexes, and web archives. Your custom production domain can be locked down while a generated URL still serves the same app, sometimes with staging data or weaker settings.
What an attacker gets
Public generated deployment URLs can expose staging routes, unreleased UI, debug-only integrations, test data, preview callbacks, or weaker environment settings. Even when production is safe on a custom domain, an unprotected preview can become the path attackers and search engines remember.
// what fixvibe reports
What FixVibe reports
Runs on every URL scan: paste your app's URL, nothing to install. The free preview shows your top findings; Hobby and above unlock the full report. Each finding shows the affected URL or host, its severity and fix steps you can paste into your AI coding tool.
How to fix it
Enable Vercel Deployment Protection for preview and generated deployment URLs using Vercel Authentication, SSO, or password protection. Keep public traffic on a custom production domain, remove `*.vercel.app` URLs from public links and metadata, block indexing on generated deployments, and keep strong HTTP security headers in Vercel or Next.js config.
