Skip to content

Scan rule · RSC-ARC-016

A setting was missing when you deployed

Architecture & SEOSeverity: High

Finds addresses in the shipped code that contain the word “undefined” or “null” instead of your database or server — the setting behind them was not set when you deployed.

Why this matters

The address of your database or server is not in the code but in a setting inserted at deploy time. If it is missing, the build inserts the word “undefined” — `https://${PROJECT}.supabase.co` becomes `https://undefined.supabase.co`.

That address does not exist. Login, loading data and forms fail for every user, often without a visible error.

We only report addresses that start with “undefined” or “null” or carry the word as host. Library error messages (“got undefined/null”) and type checks do not count.

Scan tier

External scan (anonymous)

How to fix it

Set the missing environment variable in the hosting dashboard (Vercel, Netlify, Lovable …) and redeploy. Check at startup that all required values are present instead of silently carrying on.

Scan your own app for free