Your front-end bundle is public. Check what's in it.
Secrets leak into JavaScript bundles through one misnamed environment variable or one wrong import. Checking takes a single command.
In Next.js, any environment variable prefixed NEXT_PUBLIC_ is inlined into the browser bundle at build time. Name a secret that way once and it's on every visitor's machine. The other common path is a server-only module imported, a few files deep, by a client component.
After a production build we grep the output that actually gets served:
npm run build
grep -rEo 'sk_live_[0-9A-Za-z]{10,}|service_role|-----BEGIN [A-Z ]*PRIVATE KEY' .next/static | sort -uAnd we make the mistake impossible to repeat. A module that touches secrets gets one line at the top, and the build fails if a client component ever imports it:
import "server-only";
const stripe = new Stripe(process.env.STRIPE_SECRET_KEY!);We also check whether production source maps are publicly reachable. They're not a vulnerability on their own, but they hand an attacker your original source, comments included.
This comes from our security review & hardening work.