NEXT_PUBLIC Is Not a Vault: Frontend Environment Variables Are Not Secrets
A myth-busting audit for Next.js, Vite, source maps, and build artifacts: how to detect and remediate credentials accidentally shipped to browsers.
Insights
Honest takes on AI-generated code, website obligations, privacy, hosting, and technical strategy for small businesses.
Audiences
Local sectors with sensitive contact points get their own entry pages and clear technical scope boundaries.
49 posts
Filter by category
A myth-busting audit for Next.js, Vite, source maps, and build artifacts: how to detect and remediate credentials accidentally shipped to browsers.
How an outdated WordPress site became a modern Next.js website with clearer positioning, protected customer access, web dictation, CI and controlled VPS deployment.
Why green backup jobs do not prove recoverability — and how a realistic restore test validates data, configuration, and operational readiness.
Why a contact file does not fix vulnerabilities by itself — and which processes make sure reports are received, assessed, and resolved.
Why publicly reachable test environments can create indexing, privacy, and security problems — and how to protect them properly.
Unclear validation errors lose qualified leads and exclude users. Learn how to audit forms for understandable, accessible error recovery.
A technical red-flag audit for SPF, DKIM, DMARC, and the deliverability of forms, password resets, and transactional email.
Seven red flags reveal whether account recovery safely restores access or quietly creates support cost, abandonment, and security exposure.
Why domain ownership, renewal, registrar access, and transfer locks belong in every website operations review.
Why automated TLS renewal still needs external monitoring, escalation, and a practical recovery runbook.
How the Reporting API exposes CSP violations, deprecated features, and other silent browser failures—and why it complements rather than replaces monitoring.
Five common mistakes involving hero images, responsive delivery, and lazy loading that hurt mobile speed, stability, and conversions.
How incorrect cache rules, stale HTML, and deleted assets create inconsistent releases and silent conversion failures after deployments.
How a third-party script inventory, CSP, and Subresource Integrity expose security, privacy, and performance risks.
How noindex, robots.txt, incorrect canonicals, and broken sitemaps can make entire sections disappear after deployment.
Why uptime checks and error tracking miss silent conversion failures, and how synthetic checkout tests expose lost revenue earlier.
Why faster code generation without clear review rules accelerates technical debt, security gaps, and maintenance risk.
Why a polished relaunch without a proper redirect map loses rankings, links, and conversions—and how to catch the most important failures before launch.
Why npm audit alone is not a supply-chain strategy, and how lockfiles, dependency review, and a lightweight SBOM inventory improve incident response.
How a growing VPS moved from heavyweight app orchestration to CI artifacts, PM2, Doppler and Caddy without risking live services in a big-bang cutover.
A website is not properly handed over when the client only receives an admin login. This checklist covers ownership, access, documentation, and operational independence.
Why a .env file is not a vault and how secrets leak through builds, containers, logs, and frontend bundles.
A form can show a success message while still losing enquiries. These checks reveal delivery, UX, and monitoring gaps.
Why a green backup status does not prove that your website can actually recover after an outage.
A practical security check for Docker-based websites, SaaS projects, and agency deployments.
HTTP security headers such as CSP, HSTS, and Referrer-Policy are small configurations with large impact. Website teams should treat them as maintenance, not as a one-time scan.
Interaction to Next Paint shows whether a website really responds quickly after loading. Website teams should review real user flows, JavaScript work, and form interactions.
Since the European Accessibility Act and national implementation laws, shops, booking flows, and digital services should treat accessibility as an ongoing website check, not a one-time redesign task.
Interaction to Next Paint is part of Core Web Vitals and shows whether a website actually responds after loading. Website owners, agencies, and dev teams should include INP in maintenance, QA, and performance audits.
Contact forms, booking flows, and transactional emails need clean DNS and sender configuration. SPF, DKIM, and DMARC belong in every website check.
Cookie banners, Consent Mode, and tag managers must be checked together. The key question is not only whether a banner is visible, but whether scripts really wait for the right consent state.
WordPress plugins are useful, but every plugin is also a dependency, attack surface, and maintenance task. Website teams should review, reduce, and document plugins regularly.
The EU Data Act puts more attention on switching cloud and data processing services. Website teams should use this as a practical reason to check hosting, backups, exports, and vendor lock-in.
AI-generated text, images, and summaries need provenance, review, and technical documentation. For website teams, this is less a plugin problem and more a workflow problem.
AI-generated and AI-assisted website content needs provenance, review, and clean data hygiene. For website owners, this is a practical workflow topic.
Many website risks are not caused by spectacular hacks, but by undocumented plugins, missing update routines, and unclear responsibility. Here is how Website-Pflichtencheck creates technical clarity.
Contact forms, reports, newsletters, and invoices quickly end up in spam when DNS and sending paths are messy. SPF, DKIM, DMARC, and one-click unsubscribe belong in website checks.
Google keeps third-party cookies in Chrome manageable through user settings. For website owners, that is not an all-clear: tracking, consent, and third-party scripts still need regular checks.
Since June 2025, new accessibility requirements apply to certain digital products and services in the EU. Website teams should treat accessibility as part of maintenance, QA, and relaunch workflows.
Additional transparency requirements under the EU AI Act become relevant in August 2026. Here is what website owners, agencies, and software teams should prepare now.
The first reporting obligations under the EU Cyber Resilience Act apply from September 2026. Software teams should document vulnerabilities, updates, incident paths, and product responsibility now.
Why website audit prices vary so much, what should actually be included, and when a small scan is enough.
The next phases of the EU AI Act increase transparency and documentation expectations. Here's what website owners, agencies, and software teams should prepare today.
Maps, fonts, booking tools, tracking, and widgets are useful, but they become risky when nobody checks what they load.
When a cookie banner becomes technically relevant, why the answer is not about the banner itself, and which mistakes small businesses often miss.
The EU Data Act makes cloud switching and data portability more concrete. For websites, SaaS, and agency projects, exit strategy, data exports, and provider dependencies need documentation.
The EU rules for general-purpose AI models are now in motion. For small software teams, model choice, data flows, and responsibilities need practical documentation.
AI tools accelerate development, but they also introduce new risks to code security and data. What do companies need to consider for ISO 27001 and compliance?
AI tools speed up prototypes, but they also create hidden liabilities. When is AI-generated code worth it — and when does it become a risk?
Start with a technical check. If the findings are minor, you can stop there, hand the report to your existing team, or book targeted fixes later.
Technical audit and implementation, not legal advice. I check visible signals, integrations, and delivery issues; legal texts and binding legal assessments remain the work of lawyers or privacy consultants.