This site looks like a copy of the official Next.js website, but it's hosted on a generic edge domain with no verifiable ownership and no history. The missing about page and outdated security settings make it hard to trust, especially for a site that could be used to collect logins or personal information. I'd steer clear until there's proof of who runs it.
What you should do now
Don't panic. These steps limit the damage, and the sooner you take them the better.
1
Don't enter any details
No passwords, card numbers or personal information β even if the site looks professional.
2
Close the tab
Especially if you got here from an email, text message or social media ad.
3
Already paid? Call your bank
Contact your bank or card provider right away. They can often stop or reverse a recent payment.
4
Warn others
Report the site and share this check with anyone who sent you the link.
Cross-referenced 32 live signals from Google Safe Browsing, VirusTotal, WHOIS and more on Aug 24, 2026.How we score β
Where the score comes from
We look at six areas. Here's how yelping-pink-yt3xeevk-dp4tafnpk3hn.edgeone.dev did in each.
50
Security
A valid SSL certificate and clean Google Web Risk check are good, but the site accepts outdated TLS versions and lacks basic browser protections like clickjacking blocking. The heavy count of external scripts also raises questions about what's being loaded.
30
Identity
This domain has no about page, no business disclosure, and no history in the Wayback Machine. The site is a subdomain of edgeone.dev, not the official Next.js domain, making it impossible to verify who actually runs it.
40
Reputation
The site isn't blacklisted and isn't known to Google as a threat, but it has no web archive history and no track record at all. That's normal for a brand new site, but combined with the fake-looking branding it's a concern.
50
Transparency
Contact info and social media links are present, but they appear to copy the official Next.js branding without any original about page or team information. It's unclear if the operators are who they claim to be.
60
Compliance
Privacy policy and terms of service are available, which is good. A legal entity disclosure is missing, but for a site that seems to be a marketing page rather than a storefront, that's a minor gap.
50
Infrastructure
The site loads quickly and resolves reliably, but DNSSEC is off, email records are absent, and no security headers are set. The hosting on Tencent's EdgeOne platform is fine, but the overall configuration is basic.
What we checked
The 32 signals behind this report.
Security & Transport
Certificate Issuer
DigiCert, Inc.
External Scripts
22 scripts
Google Web Risk
Clean
Legacy TLS
Accepted
SSL Certificate
Valid
Security Headers
0 of 6
Server
edgeone-pages
TLS Version
TLS 1.3
Identity & WHOIS
About Page
Not found
Branding
Complete
Business Disclosure
Not found
Contact Info
Found
Legal Pages
Privacy & Terms found
WHOIS
Unable to check
Infrastructure & DNS
DNS Blacklists
Clean
DNS Resolution
2 IP(s)
DNSSEC
Not enabled
Email (MX Records)
None
Hosting Network (ASN)
AS139341 ACE-AS-AP ACE
Page Load Time
272ms
Reputation & Reach
Page Description
Next.js by Vercel is the full-stack React framework for the web.
Page Heading
The React Framework for the Web
Page Language
en
Page Title
Next.js by Vercel - The React Framework
Sitemap
Not found
Social Media Presence
1 platforms
Structured Data
None found
Tranco Rank
Not ranked
Trustpilot
No Trustpilot profile
Web Archive History
No archive found
Website Status
Online
robots.txt
Present
Think this verdict is wrong?
Site owners can request a fresh scan. Scores update automatically as signals change.
When you land on a page that looks exactly like the official Next.js site but the URL is a random subdomain of edgeone.dev, your first instinct should be to ask who's behind it. This site has no about page, no business disclosure, and zero history in the Wayback Machine β meaning it could have popped up yesterday. While the SSL certificate is valid and Google hasn't flagged it, the site accepts outdated TLS versions and loads 22 external scripts, which is more than you'd expect from a simple marketing page. For a project that claims to be used by major companies, the lack of transparency is a red flag. If you're thinking of using this site to deploy an app or sign in, remember that the real Next.js lives at nextjs.org. Until the operators of yelping-pink-yt3xeevk-dp4tafnpk3hn.edgeone.dev show their identity and a clear purpose, treat it as unverified.