Vercel
Cost
Security & compliance
Performance
Overly broad image remotePatterns wildcard
Part of the Caching & cost check · fix arrives as a guide
What it is
The image configuration allows remote patterns broad enough to match arbitrary hosts — a wildcard hostname or an over-permissive protocol and path.
Why it matters
Anyone can then pass any URL through your image optimiser, so you pay to fetch and transform images for content that is not yours. It is a straightforward way to run up a bill on someone else's account.
How to fix it
Replace the wildcard with the specific hostnames and path prefixes your images actually come from. Each entry should name a host you control or a CDN you deliberately use.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.