Next.js security checklist
Seven-item App Router checklist: dependencies, validation, secrets, server-only code, headers, centralized checks, and CI scanning.
Read guideWeb Security
Checklists and implementation guides for securing Next.js, Remix, NestJS, login pages, containers, and self-hosted deployments.
Application and framework security is the set of controls that live in the app you ship: headers, auth, logging, secret handling, container images, and the request handlers that accept untrusted input. A framework default is not a security review. Next.js, Remix, NestJS, and a Docker image each expose a different surface, but the jobs are the same: authenticate the caller, authorize the object, validate input, limit abuse, keep secrets out of the client bundle and the logs, and run the process as a non-root user on a current base image. These guides are checklists and worked examples for those jobs, not a substitute for object-level authorization in your own code.
Start with the web app security checklist as the hub. Use the Next.js or Remix checklist for the framework you run, then the login-page, Docker, and logging guides for the surfaces you actually expose. AI agent frameworks have their own security guides under AI Security.
Seven-item App Router checklist: dependencies, validation, secrets, server-only code, headers, centralized checks, and CI scanning.
Read guideRemix v2 and React Router 7: module side effects, signed cookies, CSRF, headers, validation, and uploads.
Read guideA practical web app checklist: auth, input validation, secrets, headers, dependency risk, and in-app controls.
Read guidePlan for four threats: brute force, credential stuffing, SQL injection, and session theft.
Read guidePin node:22-bookworm for builds and node:22-bookworm-slim or gcr.io/distroless/nodejs22-debian13:nonroot for the runner.
Secure NestJS 10 and 11 with @arcjet/nest v1.
Read guideAdd structured JSON logging to Next.js 15 with Pino via the Instrumentation hook or next-logger v5.
Read guideInstall Tailscale first, deny inbound except tailscale0, then install Coolify on the tailnet.
Deploy Arcjet on Fly.io with v1 config, Fly-Client-IP detection, rate limiting, and bot protection.
Read guideSecure Node.js containers with a non-root USER, Node 22 on current Debian, Distroless or Wolfi bases, a read-only root, secret scanning, and.
Read guideNode.js trusts a frozen Mozilla CA snapshot, not OrbStack's local CA.
Read guideGet the real client IP on Firebase from x-fah-client-ip after FIREBASE_CONFIG platform detection.
Read guideNEXT_PUBLIC_ env vars are inlined into the browser bundle.
Read guideTest Next.js API routes for auth gaps, abuse paths, and Arcjet decisions without flaky end-to-end suites.
Read guideTest live Arcjet rules with Newman or k6 against the same binary you deploy.
Read guide