Skip to content
78

Contents

Awesome Node.js Security resources

3k stars314 forks131 entriesLast push Aug 14, 2026 (1 month ago)License none

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Web Framework Hardening

Helmet

Helmet helps you secure your Express apps by setting various HTTP headers.

In 2 lists

koa-helmet

koa-helmet helps you secure your Koa apps by setting various HTTP headers.

blankie

CSP plugin for hapi.

fastify-helmet

fastify-helmet helps you secure your fastify apps by setting important security headers.

nis2-express-middleware

Comprehensive Express.js middleware for EU NIS2 compliance (logging, active defense, and secure defaults).

nuxt-security

🛡 Security Module for Nuxt based on OWASP Top 10 and Helmet.

reporting-api

Express middleware to collect CSP, COOP/COEP, Permissions-Policy, NEL, crash and deprecation reports (Reporting API v0/v1 and legacy report-uri).

GitHub Actions and CI/CD Security

New dependencies advisor

GitHub Action adding comments to pull requests with package health information about newly added npm dependencies.

In 15 listsDetails

Static Code Analysis

eslint-plugin-security

ESLint rules for Node Security. This project will help identify potential security hotspots, but finds a lot of false positives which need triage by a human.

tslint-plugin-security

TSLint rules for Node Security. This project will help identify potential security hotspots, but finds a lot of false positives which need triage by a human.

safe-regex

detect potentially catastrophic exponential-time regular expressions by limiting the star height to 1.

vuln-regex-detector

This module lets you check a regex for vulnerability. In JavaScript, regular expressions (regexes) can be "vulnerable": susceptible to catastrophic backtracking. If your application is used on the client side, this can be a performance issue. On the server side, this can expose you to Regular…

regolith

Regex library for TypeScript made to prevent ReDoS attacks I made TypeScript bindings for the Rust Regex library to prevent Regular Expression Denial of Service attacks.

git-secrets

Prevents you from committing secrets and credentials into git repositories.

In 5 listsDetails

DevSkim

DevSkim is a set of IDE plugins and rules that provide security "linting" capabilities. Also has support for CLI so it can be integrated into CI/CD pipeline.

In 5 listsDetails

ban-sensitive-files

Checks filenames to be committed against a library of filename rules to prevent storing sensitive files in Git. Checks some files for sensitive contents (for example authToken inside .npmrc file).

NodeJSScan

A static security code scanner for Node.js applications. Including neat UI that can point where the issue is and how to fix it.

In 2 lists

NodeSecure CLI

Node.js CLI that allow you to deeply analyze the dependency tree of a given npm package or a directory.

Trust But Verify

TBV compares an npm package with its source repository to ensure the resulting artifact is the same.

lockfile-lint

lint lockfiles for improved security and trust policies to keep clean from malicious package injection and other insecure configurations.

In 3 lists

pkgsign

A CLI tool for signing and verifying npm and yarn packages.

semgrep

Open-source, offline, easy-to-customize static analysis for many languages. Some others on this list (NodeJSScan) use semgrep as their engine.

In 4 listsDetails

npm-scan

An extensible, heuristic-based vulnerability scanning tool for installed npm packages.

js-x-ray

JavaScript and Node.js SAST scanner capable of detecting various well-known malicious code patterns (Unsafe import, Unsafe stmt, Unsafe RegEx, encoded literals, minified and obfuscated codes).

cspscanner

CSP Scanner helps developers and security experts to easily inspect and evaluate a site’s Content Security (CSP).

In 2 lists

eslint-plugin-anti-trojan-source

ESLint plugin to detect and prevent Trojan Source attacks from entering your codebase.

sdc-check

Small tool to inform you about potential risks in your project dependencies list

fix-lockfile-integrity

A CLI tool to fix weak integrity hash (sha1) to a more secure integrity hash (sha512) in your npm lockfile.

Bearer

A CLI tool to find and help you fix security and privacy risks in your code according to OWASP Top 10.

In 6 listsDetails

GuardDog

GuardDog is a CLI tool to Identify malicious PyPI and npm packages

In 2 lists

repolyze

Analyze a git source code repository for health signals and project vitals

Dynamic Application Security Testing

PurpleTeam

A security regression testing SaaS and CLI, perfect for inserting into your build pipelines. You don’t need to write any tests yourself. purpleteam is smart enough to know how to test, you just need to provide a Job file which tells purpleteam what you want tested.

Input Validation & Output Encoding

node-esapi

node-esapi is a minimal port of the ESAPI4JS (Enterprise Security API for JavaScript) encoder.

escape-html

Escape string for use in HTML.

js-string-escape

Escape any string to be a valid JavaScript string literal between double quotes or single quotes.

validator

An npm library of string validators and sanitizers.

In 3 lists

xss-filters

Just sufficient output filtering to prevent XSS!

DOMPurify

a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG.

In 5 listsDetails

envalid

Envalid is a small library for validating and accessing environment variables in Node.js.

data-guardian

data-guardian is a tiny, highly customizable lib which can mask sensitive data in arbitrary entities and can help with OWASP Protect Data everywhere.

is-path-inside-secure

is-path-inside-secure is a symlink-aware implementation of the popular is-path-inside npm package, designed to help prevent path-traversal vulnerabilities.

spotlighting-datamarking

spotlighting-datamarking provides a lightweight implementation of the Spotlighting paper’s techniques, offering data delimiting, datamarking, and optional Base64 encoding to help separate data from instructions and reduce susceptibility to indirect prompt-injection attacks.

promptpurify

structural prompt firewall for LLM apps, with a trained classifier for prompt-injection and jailbreak inputs.

Secure Composition

pug-plugin-trusted-types

Pug template plugin makes it easy to securely compose HTML from untrusted inputs and provides CSP & CSRF automagic.

safesql

A tagged template (mysql`...`) that understands Postgres's & MySQL's query grammar to prevent SQL injection.

sh-template-tag

A tagged template (sh`...`) that understands Bash syntax so prevents shell injection.

CSRF

csurf

Node.js CSRF protection middleware.

crumb

CSRF crumb generation and validation for hapi.

fastify-csrf

A plugin for adding CSRF protection to fastify.

Vulnerabilities and Security Advisories

npq

Safely install packages with npm or yarn by auditing them as part of your install process.

snyk

Snyk helps you find, fix and monitor known vulnerabilities in Node.js npm, Ruby and Java dependencies, both on an ad hoc basis and as part of your CI (Build) system.

node-release-lines

Introspection API for Node.js release metadata. Provides information about release lines, their relative status along with details of each release.

auditjs

Audits an NPM package.json file to identify known vulnerabilities using the OSSIndex.

npm-audit

Runs a security audit based on your package.json using npm.

In 2 lists

npm-audit-resolver

Manage npm-audit results, including options to ignore specific issues in clear and auditable way.

gammaray

Runs a security audit based on your package.json using the Node.js Security Working Group vulnerability data.

patch-package

Allows app authors to create fixes for npm dependencies (in node_modules) without forking or waiting for merged PRs, by creating and applying patches.

check-my-headers

Fast and simple way to check any HTTP Headers.

clawsearch-guard

Pre-install security check for AI agent skills and npm packages. Runs Trust Score analysis before installation to detect malicious patterns, data exfiltration, and prompt injection.

is-website-vulnerable

finds publicly known security vulnerabilities in a website's frontend JavaScript libraries.

In 2 lists

joi-security

Detect security flaws in Joi validation schemas.

confused

Tool to check for dependency confusion vulnerabilities in multiple package management systems. See Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies for reference on the reasoning for this tool.

nodejs-cve-checker

A simple tool that validates CVEs were published to NVD after a Node.js Security Release.

zizmor

Static analysis for GitHub Actions and CI/CD workflows.

In 4 listsDetails

releaserun

Scan project dependencies for end-of-life runtimes, known CVEs, and version health grades across 300+ products.

In 3 lists

CVE PoC Search

Search public GitHub proof-of-concept repositories by CVE identifier.

In 4 listsDetails

cve-lite-cli

OWASP Lab Project that scans npm, pnpm, Yarn, and Bun lockfiles locally against the OSV database, classifies findings as direct or transitive, and generates copy-and-run upgrade commands.

Security Hardening

hijagger

Checks all maintainers of all npm and PyPI packages for hijackable packages through domain re-registration.

snync

Mitigate security concerns of Dependency Confusion supply chain security risks.

In 2 lists

NopPP - No Prototype Pollution

Tiny helper to protect against Prototype Pollution vulnerabilities in your application regardless if they introduced in your own code or in 3rd-party code.

anti-trojan-source

Detect trojan source attacks that employ unicode bidi attacks to inject malicious code.

express-limiter

Rate limiting middleware for Express applications built on redis.

limits

Simple express/connect middleware to set limit to upload size, set request timeout etc.

rate-limiter-flexible

Fast, flexible and friendly rate limiter by key and protection from DDoS and brute force attacks in process Memory, Cluster, Redis, MongoDb, MySQL, PostgreSQL at any scale. Express and Koa examples included.

tor-detect-middleware

Tor detect middleware for express

express-enforces-ssl

Enforces SSL for Express based Node.js projects. It is however highly advised that you handle SSL and global HTTP rules in a front proxy.

bourne

JSON.parse() drop-in replacement with prototype poisoning protection.

sigcli

Authentication layer for AI agents. Local MITM proxy on 127.0.0.1 intercepts HTTPS and injects credentials (cookies, bearer tokens, custom headers) transparently — AI agents authenticate without ever seeing secrets. AES-256-GCM encrypted storage, browser SSO, 4 auth strategies.

fastify-rate-limit

A low overhead rate limiter for your routes.

secure-json-parse

JSON.parse() drop-in replacement with prototype poisoning protection.

express-brute

A brute-force protection middleware for express routes that rate-limits incoming requests, increasing the delay with each request in a fibonacci-like sequence.

allowed-scripts

Execute allowed npm install lifecycle scripts.

In 2 lists

ses

A shim for Hardened JavaScript, a language mode that mitigates prototype pollution attacks and supports safely confining multiple tenants in a single JavaScript realm, endowing each other with hardened API objects.

lavamoat

Mitigates supply chain attacks using ses to confine third-party dependencies and limit their access to host powers based on policies generated by trust-on-first-use static analysis.

moddable

Implements Hardened JavaScript as the security model for embedded systems.

is-my-node-vulnerable

package that checks if your Node.js installation is vulnerable to known security vulnerabilities.

@lavamoat/preinstall-always-fail

npm package to assert if preinstall or postinstall scripts are running in your npm or yarn workflows.

FCaptcha

Self-hosted CAPTCHA with behavioral analysis that detects bots, vision AI agents, and headless browsers. Includes Node.js server with SHA-256 proof of work.

In 3 lists

are-scripts-enabled

npm package to assert if preinstall or postinstall scripts are running in your npm or yarn workflows.

@w-r-l/verify

Verify cryptographic integrity of WACZ web archive bundles. Checks Ed25519 signatures and RFC 3161 timestamps.

pompelmi

Local-first file upload scanning for Node.js to inspect untrusted files before storage.

In 5 listsDetails

verifyfetch

SRI-based integrity verification and resumable downloads for large files. Protects against CDN compromise and supply chain attacks in the browser.

In 4 listsDetails

Data Sources

resource

A structured list of all the Node.js versions, the binary builds, the dependencies they include (npm, zlib, openssl) along with their versions, whether the release is a security release and whether it is an LTS.

resource

The nodejs/secuirty-wg GitHub repository maintains a /vuln/core directory with all the CVEs applied to Node.js runtime versions.

Protestware supply chain security issues

PyPI package author of atomicwrites deletes his own code

left-pad

2022's Techcrunch protestware review

2022's Snyk protestware types

npm and JavaScript specific security incidents and supply chain security issues

npm zoo

is an archive keeping track of the original malicious packages source code for educational purposes.

Newsletters

Node.js Security newsletter

JavaScript & web security insights, latest security vulnerabilities, hands-on secure code insights, npm ecosystem incidents, Node.js runtime feature updates, Bun and Deno runtime updates, secure coding best practices, malware, malicious packages, and more.

Articles

A Roadmap for Node.js Security

(original domain https://nodesecroadmap.fyi/ not available. See #42)

10 npm security best practices

OWASP Cheat Sheet Series - Node.js Security Cheat Sheet

What is a backdoor? Let’s build one with Node.js

The Anatomy of a Malicious Package

Why npm lockfiles can be a security blindspot for injecting malicious modules

Malicious code can be injected into npm projects via lockfiles (package-lock.json or yarn.lock) because these large, machine-generated files are rarely reviewed thoroughly.

In 2 lists

GitHub Actions to securely publish npm packages

Top 11 Node.js security best practices | Sqreen.com

A Tale of (prototype) Poisoning

Securizing your GitHub org

Research Case Study: Supply Chain Security at Scale – Insights into NPM Account Takeovers

npm Security Best Practices

The Documentation Attack Surface: How npm Libraries Teach Insecure Patterns

Analysis of how popular npm libraries with secure defaults teach insecure patterns in their README examples, covering 4 packages with 180M+ combined weekly downloads.

Research Papers

Deep dive into Visual Studio Code extension security vulnerabilities

VS Code extensions have vulnerabilities (command injection, path traversal, zip slip) that can compromise developer machines.

In 2 lists

Books

Secure Your Node.js Web Application: Keep Attackers Out and Users Happy

by Karl Duuna, 2016

Essential Node.js Security

by Liran Tal, 2017 - Hands-on and abundant with source code for a practical guide to Securing Node.js web applications.

Securing Node JS Apps

by Ben Edmunds, 2016 - Learn the security basics that a senior developer usually acquires over years of experience, all condensed down into one quick and easy handbook.

Web Developer Security Toolbox

Bundled Node.js and Web Security Books.

Thomas Gentilhomme

book: Become a Node.js Developer

Node.js Secure Coding: Defending Against Command Injection Vulnerabilities

Node.js Secure Coding: Prevention and Exploitation of Path Traversal Vulnerabilities

Master secure coding in Node.js with real-world vulnerable dependencies and experience firsthand secure coding techniques against Path Traversal vulnerabilities.

In 2 lists

Node.js Secure Coding: Mitigate and Weaponize Code Injection Vulnerabilities

Roadmaps

Node.js Developer Roadmap

Companies

Snyk

A developer-first solution that automates finding & fixing vulnerabilities in your dependencies.

In 14 listsDetails

Datadog ASM

Application security monitoring with real-time threat detection and protection (formerly Sqreen, acquired 2021).

NodeSource

Mission-critical Node.js applications. Provides N|Solid and Node Certified Modules.

GuardRails

A GitHub App that gives you instant security feedback in your Pull Requests.

In 3 lists

NodeSecure

An organization of developers building free and open source JavaScript/Node.js security tools.

Hacking Playground

OWASP NodeGoat

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.

In 4 lists

OWASP Juice Shop

The OWASP Juice Shop is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws.

In 3 lists

DomGoat

Client XSS happens when untrusted data from sources ends up in sinks. Information and excercises on different sources, different sinks and example of XSS occuring due to them in the menu on the left-hand side.

In 2 lists
See category
92

Awesome Docker

veggiemonk/awesome-docker

:whale: A curated list of Docker resources and projects

Fresh★ 37k389 entriesPushed 17 days ago
92

Awesome GraphQL

chentsulin/awesome-graphql

Awesome list of GraphQL

Fresh★ 15k483 entriesPushed yesterday
91

Awesome-Kubernetes

ramitsurana/awesome-kubernetes

A curated list for awesome kubernetes sources :ship::tada:

Fresh★ 16k47 entriesPushed 8 days ago
91

Awesome Quant

wilsonfreitas/awesome-quant

A curated list of insanely awesome libraries, packages and resources for Quants (Quantitative Finance)

Fresh★ 30k678 entriesPushed today
89

Awesome Django

wsvincent/awesome-django

A curated list of awesome things related to Django

Fresh★ 11k326 entriesPushed 13 days ago
89

Awesome Terraform

shuaibiyy/awesome-tf

Curated list of resources on HashiCorp's Terraform and OpenTofu

Fresh★ 6.6k472 entriesPushed 2 days ago