IS NETLIFY SAFE?
Netlify makes deployment effortless but ships with minimal security defaults. Missing headers, exposed environment variables, and unprotected serverless functions are common in Netlify projects. This guide covers what you need to lock down before going live.
TOP SECURITY RISKS
Missing Security Headers
Netlify does not add Content-Security-Policy, Strict-Transport-Security, or X-Frame-Options by default. Without these headers, your site is vulnerable to XSS, clickjacking, and man-in-the-middle attacks.
Environment Variables Exposed in Build Logs
Build logs can accidentally print environment variables during the build process. If your CI pipeline echoes commands or a misconfigured script logs its environment, secrets become visible to anyone with deploy access.
Unauthenticated Serverless Functions
Netlify Functions are publicly accessible by default at /.netlify/functions/. Without explicit authentication checks, any attacker can invoke your backend logic directly, bypassing your frontend entirely.
Open Redirects via Redirect Rules
Misconfigured redirect rules in _redirects or netlify.toml can create open redirect vulnerabilities. Attackers use these to craft phishing URLs that appear to originate from your trusted domain.
No Rate Limiting on Functions
Netlify does not provide built-in rate limiting for serverless functions. Without external protection, attackers can abuse your endpoints with automated requests, running up costs and degrading service.
SECURITY CHECKLIST
SCAN YOUR NETLIFY APP
Start with a bounded public check. The currently enabled Deep Scan has up to 702 configured checks after current ownership proof. Free entry point, no credit card required.
Run free security scanFREQUENTLY ASKED QUESTIONS
Does Netlify add security headers automatically?
No. Netlify does not set Content-Security-Policy, HSTS, or X-Frame-Options by default. You must add them manually via a _headers file or netlify.toml. UNPWNED assesses its configured security-header set and reports observed gaps. Paid reports add configuration guidance.
How do I protect my Netlify serverless functions?
Add authentication checks at the top of every function - verify JWTs, API keys, or session tokens before processing requests. UNPWNED checks common public function paths for reachability, exposed response data, bounded rate-limit, CORS, and error-disclosure signals. Authentication, JWT, API-key, and session validation require direct review.
Can my Netlify environment variables leak?
Yes, through build logs, client-side bundles with NEXT_PUBLIC_ or REACT_APP_ prefixed vars, and misconfigured function responses. Scope variables to production only when possible. UNPWNED checks client-accessible bundles and responses for supported exposed-secret and environment-variable patterns; it does not inspect private build logs.
How do I add rate limiting to Netlify?
Netlify has no built-in rate limiting. Use Netlify Edge Functions with an in-memory counter, or place Cloudflare or another WAF in front of your site. UNPWNED checks bounded externally observable rate-limit signals on tested paths; it does not prove application-wide enforcement.
Are Netlify deploy previews a security risk?
They can be. Deploy previews are publicly accessible by default and may expose unreleased features or staging data. Enable branch deploy protection and avoid using production secrets in preview environments. UNPWNED can assess each production or preview URL that is separately submitted with authorization; it does not enumerate every deployment URL.
Data based on 447+ website scans. Statistics reflect aggregate findings across all scanned websites, not Netlify exclusively.
