InfrastructureLive3 checks
Vercel Hosting Security Scanner
Audit Vercel-specific security settings, headers, and deployment configuration.
How this scan works
- Detects Vercel via server/x-vercel-id headers
- Checks for exposed deployment/preview URL patterns in headers or page source
- Checks that vercel.json / _headers-equivalent config isn't publicly fetchable with secrets
- Cross-checks the Security Headers scanner's results, since Vercel requires explicit header config
