davisjam / vuln-regex-detector
Detect vulnerable regexes in your project. REDOS, catastrophic backtracking.
☆320Updated 3 years ago
Alternatives and similar repositories for vuln-regex-detector:
Users that are interested in vuln-regex-detector are comparing it to the libraries listed below
- ☆144Updated 2 years ago
- Detect possibly catastrophic, exponential-time regular expressions☆176Updated 2 years ago
- Find security vulnerabilities in open source npm packages while you code☆205Updated 2 years ago
- ☆343Updated this week
- A browser API to prevent DOM-Based Cross Site Scripting in modern web applications.☆614Updated last month
- node.js bindings for RE2: fast, safe alternative to backtracking regular expression engines.☆510Updated 5 months ago
- Content released at NorthSec 2018 for my talk on prototype pollution☆519Updated 8 months ago
- JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.☆231Updated 2 weeks ago
- Express.js middleware for "Host" and "Referer" header validation to protect against DNS rebinding attacks.☆191Updated 2 years ago
- njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.☆386Updated 3 months ago
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆234Updated 3 months ago
- A list of ReDoS vulnerabilities in npm modules found by the Software Lab at TU Darmstadt. For each vulnerability, there is a proof-of-con…☆59Updated 7 years ago
- RegEx Denial of Service (ReDos) Scanner☆162Updated 7 years ago
- WebAppSec Content Security Policy☆215Updated 2 weeks ago
- ESLint security plugin for Node.js☆103Updated last year
- Lint an npm or yarn lockfile to analyze and detect security issues☆791Updated 5 months ago
- An extensible, heuristic-based vulnerability scanning tool for installed npm packages☆50Updated 3 years ago
- Low interaction honeypot that displays real time attacks☆370Updated 4 years ago
- Node.js Ecosystem Security Working Group☆513Updated last week
- A stream implementation that does more by doing less☆250Updated 8 months ago
- A minimal port of the old, publicly archived "owasp-esapi-js" (Enterprise Security API for JavaScript) encoder.☆135Updated 2 years ago
- Audits an NPM package.json file to identify known vulnerabilities.☆225Updated 3 months ago
- JSON.parse() drop-in replacement with prototype poisoning protection☆228Updated 2 weeks ago
- A Node.js vulnerability finding tool.☆95Updated 4 years ago
- Vulnerabilities discovered in npm packages [Berkeley PL & Security Research]☆44Updated 7 months ago
- a javascript static security analysis tool☆589Updated 9 years ago
- Delightful Node.js packages useful for penetration testing, exploiting, reverse engineer, cryptography ...☆423Updated 3 years ago
- Fast and simple way to check any HTTP Headers☆45Updated last year
- JavaScript security CLI that allow you to deeply analyze the dependency tree of a given package or local Node.js project.☆367Updated this week
- Programmable interface to `clinic doctor`☆365Updated last year