CMS
Next.js audit: App Router, metadata, and headers()
· Configuration notes, not a newsroom.
SiteRune fingerprints Next from /_next and runtime markers. The playbook treats it as a server. We skip the bootcamp speech on sites that are already elite.
Not a SPA with a framework sticker
Next.js sites fail this audit when the hero is a client component, generateMetadata is missing on money routes, and CSP never left next.config. The playbook: server-render the above-the-fold, generateMetadata on every indexable route, next/image, headers() in next.config for CSP/HSTS, app/sitemap.ts + robots.ts, a static /llms.txt route. We only mention vercel.json when response headers prove the origin is on Vercel. Next.js behind nginx is not Vercel.
We will not nag a 90
If the origin already looks elite — entity schema, llms.txt, sane cache, TLS 1.3 — we do not append a generic 'learn the App Router' bootcamp item. The brief should get shorter as the site gets better.
Run it on a live URL
The brief will name your CMS and attach the files. Three guest scans, no card.