A lightweight reusable Express.js middleware for protecting applications against Cross-Site Request Forgery (CSRF) attacks using cookie and header token validation.
A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules
Compile and play code (ditties) from [Dittytoy.net](https://dittytoy.net), an online platform that allows you to create generative music using a minimalistic javascript API. Zero dependencies.
Mitigate security concerns of Dependency Confusion supply chain security risks
join-customs-web3-attack
Review dependencies changes to prevent supply chain attack
Unified Solidity security scanner — static analysis, dependency audit, live threat intel, exploit simulation, and watch-mode monitoring
UI framework for Lodash UI
Vue.js slide to unlock component. Protect users from accidental clicks or protect your web app from bot attack.
Local-first CLI that blocks risky npm, pnpm, and bun installs before they run. Open source.
Client-side library to load the Paystack checkout form
`@bananapus/buyback-hook-v6` is a data hook that compares Juicebox's native mint or cash-out path with a Uniswap V4 pool and routes through whichever produces the better result for the project at that moment.
CLI tool for stress-testing web targets using k6
ReDoS analyzer: check if a regex is vulnerable to regular expression denial of service
AI-powered penetration testing CLI tool with terminal UI
Render React Component Using Jquery
A TypeScript library for parsing, rolling, and analyzing dice expressions, plus a small program language for tabletop-RPG-flavoured automation. Supports standard dice notation, custom dice, dice pools, exploding/rerolling/compound mechanics, structured-fa
A library that provides import of data from MITRE Matrices
null
Detect and fix the mini-shai-hulud TanStack supply-chain attack (socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack)
Sandbox runtime for secure JavaScript code execution
R-U-DEAD-YET ?
Prints a warning to the console if postnistall scripts are executed
hint for best practices related to the usage of the Strict-Transport-Security response header