May 2026
next-secure-check
Published open-source CLI and web demo for running deterministic security sanity checks on Next.js projects.
Checks for .env leaks, hardcoded secrets, unsafe API routes, missing rate limits, XSS risks, raw SQL interpolation, upload endpoint issues, and security header problems. The v0.2 series added context-aware scanning, presets, and AST-assisted rule checks.
Status
v0.2.1 published on npm · v0.3 quality work
My role
Product scope, rule engine, CLI flow, npm publishing, preset system, AST-assisted checks, tests, and documentation
- +Published next-secure-check v0.2.1 on npm.
- +Added context-aware scanning, presets, and AST-assisted rule checks.
- +374 tests pass across packages and the web demo.
Next step: v0.3 benchmark fixture suite · XSS/auth/middleware signal improvements · user feedback