Next.js & Vercel security footguns — client/server secret leakage via NEXTPUBLIC, unauthenticated Server Actions and Route Handlers, middleware auth bypass, SSRF in server fetches. Apply when reviewing, building, or shipping a Next.js or Vercel app.
Stripe security footguns — unverified webhook signatures, trusting price/amount from the client, secret key exposure, missing idempotency, fulfilling on the wrong event. Apply when reviewing, building, or shipping payment or billing flows with Stripe.