“Next.js has become a Vercel vendor lock-in disguised as an open-source framework.”

Next.js now streams page metadata after load, so crawlers that skip JavaScript miss the title and OG tags. Vercel’s fix sniffs for bots. Pinning an older version to avoid it leaves you on the CVSS 9.1 middleware bypass. The framework is open source, and the hosting it works best on is Vercel’s.