JavaScript Apache-2.0

eslint-plugin-security

ESLint rules for Node Security

E

eslint-community

Dernière activité 29 sept. 2026
eslint-community/eslint-plugin-security

2,4 k

étoiles

113

forks

20

issues ouvertes

eslinteslint-plugin

Ce README est souvent en anglais.

eslint-plugin-security

NPM version

ESLint rules for Node Security

This project will help identify potential security hotspots, but finds a lot of false positives which need triage by a human.

Installation

npm install --save-dev eslint-plugin-security

or

yarn add --dev eslint-plugin-security

Usage

Flat config (requires eslint >= v8.23.0)

Add the following to your eslint.config.js file:

const pluginSecurity = require('eslint-plugin-security');

module.exports = [pluginSecurity.configs.recommended];

eslintrc config (deprecated)

Add the following to your .eslintrc file:

module.exports = {
  extends: ['plugin:security/recommended-legacy'],
};

Developer guide

  • Use GitHub pull requests.
  • Please implement a test for each new rule and use this command to be sure the new code respects the style guide and the tests keep passing:
npm run-script cont-int

Tests

npm test

Rules

⚠️ Configurations set to warn in.
✅ Set in the recommended configuration.

Name                                  Description ⚠️
detect-bidi-characters Detects trojan source attacks that employ unicode bidi attacks to inject malicious code. ✅
detect-buffer-noassert Detects calls to "buffer" with "noAssert" flag set. ✅
detect-child-process Detects instances of "child_process" & non-literal "exec()" calls. ✅
detect-disable-mustache-escape Detects "object.escapeMarkup = false", which can be used with some template engines to disable escaping of HTML entities. ✅
detect-eval-with-expression Detects "eval(variable)" which can allow an attacker to run arbitrary code inside your process. ✅
detect-invisible-characters Detects invisible characters that have no visible glyph and can be used to hide malicious code. ✅
detect-new-buffer Detects instances of new Buffer(argument) where argument is any non-literal value. ✅
detect-no-csrf-before-method-override Detects Express "csrf" middleware setup before "method-override" middleware. ✅
detect-non-literal-fs-filename Detects variable in filename argument of "fs" calls, which might allow an attacker to access anything on your system. ✅
detect-non-literal-regexp Detects "RegExp(variable)", which might allow an attacker to DOS your server with a long-running regular expression. ✅
detect-non-literal-require Detects "require(variable)", which might allow an attacker to load and run arbitrary code, or access arbitrary files on disk. ✅
detect-object-injection Detects "variable[key]" as a left- or right-hand assignment operand. ✅
detect-possible-timing-attacks Detects insecure comparisons (==, !=, !== and ===), which check input sequentially. ✅
detect-pseudoRandomBytes Detects if "pseudoRandomBytes()" is in use, which might not give you the randomness you need and expect. ✅
detect-unsafe-regex Detects potentially unsafe regular expressions, which may take a very long time to run, blocking the event loop. ✅

TypeScript support

Type definitions for this package are bundled with it, so nothing else needs to be installed.

They are written against the ESLint v9 type definitions, so they require either eslint >= v9.10.0, which is the first release that ships its own type definitions, or @types/eslint v9 alongside an older ESLint.

If you previously installed @types/eslint-plugin-security from DefinitelyTyped, it is no longer needed and can be removed:

npm uninstall @types/eslint-plugin-security

# OR

yarn remove @types/eslint-plugin-security

Projets similaires

Find and fix problems in your JavaScript code.

JavaScriptecmascripteslintjavascript
Eeslint
27,5 k étoiles5,2 k

More than 300 powerful ESLint rules

JavaScripteslinteslint-configeslint-plugin
Ssindresorhus
5,3 k étoiles496

ESLint plugin with rules that help validate proper imports.

JavaScriptcode-qualityeslinteslint-plugin
Iimport-js
5,9 k étoiles1,5 k