Skip to content
Innovation & Growth

Vinext 1.0 shows the hard part of cloning a framework is behavior, not code

Cloudflare's AI-built Next.js runtime is in production. The work that remains is verification.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Vinext 1.0 shows the hard part of cloning a framework is behavior, not code

Photo: Jan van der Wolf / Pexels

Key finding

Compatibility on customer-requested features: Above 99% (Source: Cloudflare, Vinext 1.0 announcement (September 28, 2026). Cloudflare's figure covers most important customer-requested features, not all of Next.js.)

Writing code that looks like a framework has become cheap. Writing code that behaves like one has not. That is the lesson in Cloudflare's Vinext 1.0 announcement, and it applies to any organisation that is starting to buy, or build, software that AI helped produce. The difficulty did not decrease. It relocated, from authoring to verification.

What Cloudflare announced

On September 28, 2026, Cloudflare released Vinext 1.0. It takes a Next.js application, built for either the Pages or App Router, and makes it portable to other platforms, including Cloudflare Workers, Netlify and AWS Lambda. Cloudflare says the project began in February as a week-long, AI-driven experiment by one engineer to replicate Next.js on top of Vite. It now says customers run Vinext in production for high-traffic, dynamic applications.

This is a vendor's account of its own product, and it should be read that way. The figures below are Cloudflare's claims, not independent measurements.

Above 99%
Compatibility on customer-requested features
Source: Cloudflare, Vinext 1.0 announcement (September 28, 2026). Cloudflare's figure covers most important customer-requested features, not all of Next.js.

Where the difficulty went

Cloudflare's own description of the work is instructive. Creating a substitute for a function such as revalidatePath is simple, it says. The difficulty is making sure the function correctly affects rendered pages, cache entries and future requests. In its words, "It is not good enough to imitate functions with the same name."

That is the point for a budget-holder. A model can produce plausible code quickly. Whether the code does the same thing under load, in a cache, after a revalidation, is a separate question, and it was the community's scrutiny that exposed gaps the initial tests missed. Cloudflare says that tracing requests through the application to replicate the behavior was the most challenging part.

The lesson here is that the cost of AI-generated software sits in the test suite. Cloudflare now runs thousands of focused tests across both routers, both server modes and two deployment targets. It also runs the Next.js end-to-end test suite against Vinext every night. The asset is not the code. It is the instrument that says whether the code is faithful.

Agents watching agents

Cloudflare describes how it keeps the project current. Next.js canary receives new commits daily. Each morning an agent reviews the changes and opens tracking issues for anything that could affect Vinext. When a test reveals a gap, agents identify the change across both codebases, build a reproduction, port the relevant tests and propose a fix. Cloudflare says this review has caught missing cases, unsafe caching behaviors, and differences between development and production servers.

Human maintainers, Cloudflare says, are left with the issues that need judgement about how Next.js behavior should map onto Vite. Automation narrows the stream and people decide the remainder. For an executive, that is the operating model to look for in any AI-assisted supplier: not whether agents are used, but where a person is accountable.

What the WebPulse data adds

The subject matters because of how widely Next.js is deployed among the sites WebPulse detects. In its September 2026 scan of the Tranco top 10,000 domains, 7,064 responded and a platform was detected on 2,491. Next.js accounted for 791 of those detections.

791 (31.8%)
Next.js share of detected sites, Tranco top 10,000
Source: WebPulse scan of Tranco top-10,000 domains (September 2026). Percentage of sites where a platform was detected.

The NIST NVD profile that WebPulse refreshed on September 29, 2026 lists 56 CVEs for Next.js in total, 32 of them in the last 12 months, and one in CISA's Known Exploited Vulnerabilities catalog. Those counts describe Next.js. They say nothing about Vinext, which is a separate codebase, and they are not evidence for or against it. They do frame a question: when upstream fixes a flaw, how quickly does a reimplementation absorb it, and who confirms that it did?

32 of 56
Next.js CVEs in the last 12 months
Source: NIST NVD, CPE-matched, via WebPulse (refreshed September 29, 2026)

Questions to put to your team

First, which Next.js features does each of our applications depend on? Cloudflare says Vinext has only limited support for the "use cache" directive behind Cache Components, because most teams it spoke to did not use them. If you do, that gap is yours.

Second, what is the process for upstream security fixes? Ask the vendor how a Next.js patch reaches Vinext, and how you would know.

Third, can we run our own end-to-end tests against a converted build before any traffic moves? Cloudflare's own deployment process uploads a new Worker version at 0% of production traffic, then requests pages from it. That is a sound pattern to demand of any migration.

Fourth, does our observability carry over? Cloudflare says existing OpenTelemetry and Sentry setups continue to work.

Portability is attractive, and Cloudflare says a migration takes two commands. The commands are the easy part. Whatever the code's provenance, what you are buying is the evidence that it behaves.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Cloudflare.

Share this insight