Posts about #headers
3 posts
How to Audit a Next.js App for Security Misconfigurations and Header Leaks
Default Next.js production setups leak server runtime info, misconfigure CORS, and expose internal routes. Here's the audit — inspect headers, find env leaks, verify CORS — with code fixes for next.config.js.
We Audited 50 Popular Web Applications: The Top 4 Security Mistakes We Found
An empirical teardown of 50 real websites. 68% lacked proper CSP or HSTS, 30% leaked stack traces on malformed input, 25% had public staging endpoints, and 17% had broken TLS chains. Here's what we found and how to fix it.
The Security Headers Every AI-Built Site Needs
Missing security headers are an instant fail on any scan. Here's the exact header set for AI-built sites, what each one does, and how to set them.