AI platforms · AI UI and app generator (Vercel)
Is my v0 app secure?
v0 writes very good Next.js. The risk is in what it does not add: route handlers without authorisation checks, secrets exposed through NEXT_PUBLIC_, and no security headers because next.config.js was never touched.
Audit my v0 app free → Scan the code too
What v0 usually leaves open
Typical stack: Next.js App Router, server actions and route handlers, deployed on Vercel, often with Supabase or Neon.
- Secret exposed through a browser-public env prefix (Code Scan)A key stored as NEXT_PUBLIC_something. Vercel ships every NEXT_PUBLIC_ variable to the browser.
- Content Security Policy (CSP)No Content-Security-Policy, HSTS or frame protection: Next.js does not emit them unless you add headers() in next.config.js.
- CORS allows any origin (Code Scan)Route handlers that return Access-Control-Allow-Origin: * to make a demo client work.
- SQL built by string concatenation (Code Scan)Raw SQL built with template strings in a server action.
- Redirect target taken from the request (Code Scan)A redirect to a 'next' query parameter after login, usable for phishing.
How to fix it in v0
Run the scan, then paste this into v0 together with the Kavach report. It tells the assistant exactly what to do and what not to touch.
Audit this Next.js app for launch. 1) List every NEXT_PUBLIC_ variable; move any secret to a server-only variable and call the service from a route handler. 2) Add security headers in next.config.js: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy. 3) Replace any Access-Control-Allow-Origin: * with an explicit origin list. 4) Convert raw SQL in server actions to parameterised queries. 5) Validate redirect targets against an allow-list. Explain each change.Re-scan when it is done. The grade and the findings list show whether the change took, and monitoring tells you if a later prompt reopens anything.
Questions about v0 security
Does Vercel add security headers for me?
No. Vercel terminates TLS, but Content-Security-Policy, HSTS and the rest come from your next.config.js or middleware. Kavach's Fix Pack gives the exact headers() block to paste.
Why does Kavach flag my NEXT_PUBLIC_ variable?
Because the prefix tells Next.js to embed the value in the client bundle. That is fine for a public Supabase anon key and dangerous for anything that should stay on the server.
Can Kavach scan a v0 project before I deploy?
Yes. Export the code, zip it and upload it to Code Scan. The external audit runs once there is a public URL, including a Vercel preview URL you are authorised to test.
Will the scan slow down or break my site?
No. Every check is read-only and rate-limited. Nothing is submitted, fuzzed or brute-forced.
Other platforms
Lovable · Bolt · Replit Agent · Cursor · Claude Code · Supabase · Firebase · Vibe coding security scanner
Kavach reports observations from read-only checks, not guarantees; see the disclaimer. v0 is a trademark of its owner; Kavach is not affiliated with it.