JSPM

Found 71 results for vulnerabilities

snyk

snyk library and cli utility

  • v1.1299.0
  • 87.45
  • Published

better-npm-audit

Reshape into a better npm audit for the community and encourage more people to include security audit into their process.

  • v3.11.0
  • 85.93
  • Published

@snyk/protect

Snyk protect library and utility

  • v1.1299.0
  • 70.66
  • Published

@snyk/fix

Snyk fix library and utility

  • v1.1299.0
  • 60.26
  • Published

@soos-io/api-client

This is the SOOS API Client for registered clients leveraging the various integrations to the SOOS platform. Register for a free trial today at https://app.soos.io/register

  • v1.9.4
  • 58.76
  • Published

@soos-io/soos-sca

SOOS Core SCA Security Analysis - Check for vulnerabilities, licenses, policy violations and more! Register for your free trial at https://app.soos.io/register

  • v4.2.4
  • 57.88
  • Published

audit-export

Pretty export your npm audit output as an offline accessible html page

  • v5.1.0
  • 53.67
  • Published

npm-audit-plus

A wrapper around NPM's built-in audit that adds extra features

  • v0.2.0
  • 50.20
  • Published

better-npm-audit-json

Reshape into a better npm audit for the community and encourage more people to include security audit into their process.

  • v3.7.9
  • 50.19
  • Published

@soos-io/soos-sast

SOOS Static Application Security Testing (SAST) scanning support. Register for a free SOOS trial at https://app.soos.io/register

  • v1.2.4
  • 49.35
  • Published

npmplus-mcp-server

Production-ready MCP server for intelligent JavaScript package management. Works with Claude, Windsurf, Cursor, VS Code, and any MCP-compatible AI editor.

  • v12.0.19
  • 48.50
  • Published

@chax-at/better-npm-audit

Reshape into a better npm audit for the community and encourage more people to include security audit into their process.

  • v3.6.11
  • 47.57
  • Published

@soos-io/soos-sbom

Upload your Software Bill of Materials (SBOM) to SOOS for vulnerability analysis, license matching and more. Register for a free trial today at https://app.soos.io/register

  • v1.2.4
  • 43.60
  • Published

npm-audit-plus-plus

A tool to capture the output of npm audit and convert it to xml

  • v1.1.1
  • 42.68
  • Published

is-website-vulnerable

finds publicly known security vulnerabilities in a website's frontend JavaScript libraries

  • v1.14.11
  • 40.25
  • Published

ssvc

TypeScript implementation of SSVC (Stakeholder-Specific Vulnerability Categorization). A prioritization framework to triage CVE vulnerabilities as an alternative or compliment to CVSS

  • v0.4.1
  • 37.57
  • Published

ubon

Security scanner for AI-generated React/Next.js and Python apps. Catches hardcoded secrets, accessibility issues, and vulnerabilities that traditional linters miss.

  • v1.1.3
  • 36.58
  • Published

qualscan

Scan your project to find quality issues

  • v3.1.9
  • 27.81
  • Published

npm-audit-excel

Generate Excel reports from npm audit with prioritization and multi-language support

  • v2.0.0
  • 27.39
  • Published

dr-dep-audit

Audit npm dependencies for outdated packages and vulnerabilities with a fast, colorized CLI. Supports config files, GitHub Actions annotations, and CI/CD integration with automatic failure on high/critical issues.

  • v0.0.3
  • 26.96
  • Published

@jitesoft/audit-for-gitlab

Minimal application to convert npm audit report into gitlab-ci vulnerability report format.

  • v4.0.1
  • 26.93
  • Published

npm-audit-reporter

This project builds on top of the existing `npm audit` functionality by providing additional features and presenting audit reports in various formats such as HTML, JSON, and tables.

  • v2.0.1
  • 24.52
  • Published

npm-audit-plus-uis

A wrapper around NPM's built-in audit that adds extra features

  • v0.2.93
  • 24.39
  • Published

npm-epss-audit

Use EPSS scores to prioritize NPM Audit findings

  • v0.0.13
  • 23.30
  • Published

npm-dependency-analyzer

Plugin to validate dependencies, concerning their license and vulnerabities

  • v0.7.0
  • 21.47
  • Published

security-report

a CLI to quickly report a security vulnerability

  • v1.1.4
  • 20.89
  • Published

pie-my-vulns

Visualize your project security vulnerabilities as a pie chart in the terminal

  • v1.6.11
  • 20.89
  • Published

supertest-security

It's a library that allows us to test api endpoints by fuzzing them with malicious payloads that you can choose. It bases on `supertest` package.

    • v1.0.1
    • 20.30
    • Published

    certfr-loader

    Module to load certfr from the CERT FR

    • v2.0.6
    • 19.64
    • Published

    depdrift

    A tool to analyze dependency drift in JavaScript projects

    • v0.1.0
    • 18.32
    • Published

    eslint-plugin-codesink

    Detect common javascript sinks that lead to web application vulnerabilities.

    • v1.0.12
    • 17.29
    • Published

    @soos-io/sample-project

    SOOS ( https://soos.io ) is an independent software security company, located in Winooski, VT USA, building security software for your team. Used for testing purposes, this package is an example of a vulnerable package on a public registry.

    • v1.1.4
    • 16.42
    • Published

    secure-dep-scanner

    A comprehensive security scanner for detecting suspicious dependencies, malicious packages, and vulnerabilities in Node.js projects.

    • v1.1.2
    • 15.75
    • Published

    snyker

    An opinionated, heavy-handed wrapper around Snyk.

    • v5.0.3
    • 14.59
    • Published

    js-vulns-detector

    Inject JS to the DOM to find vulnerable JavaScript libraries

    • v1.0.6
    • 14.27
    • Published

    @asos/snyker

    An opinionated, heavy-handed wrapper around Snyk.

    • v5.1.0
    • 13.70
    • Published

    @luciddr34m3r/nvd

    A JavaScript library for dealing with NVD, CVEs, and CPE strings.

    • v0.0.1
    • 13.21
    • Published

    gh-sec

    Github security alerts CLI

    • v1.0.0-beta.1
    • 11.17
    • Published

    snyk-recursive

    Run Snyk recursively in valid subdirectories.

    • v0.0.12
    • 10.83
    • Published

    olynpm

    Fitness App for your npm projects.

    • v0.1.8
    • 10.63
    • Published

    tfv-nvd-types

    National Vulnerability Database typescript definitions for data feeds.

    • v1.3.0
    • 9.40
    • Published

    @jitesoft/gitlab-dep-convert

    Tiny converter to convert npm audit report into gitlab-ci dependency report format.

      • v0.0.1
      • 9.38
      • Published

      audit-plus

      Bring back the missing features of NSP to NPM Audit

      • v0.1.3
      • 9.38
      • Published

      @soos-io/sample-project-node-license-fetch

      SOOS ( https://soos.io ) is an independent software security company, located in Winooski, VT USA, building security software for your team. Used for testing purposes, this tool is an example of fetching software license information from SOOS.

      • v1.0.1
      • 8.46
      • Published

      audit-ignore

      NPM Audit Ignore - Keep CI Scanning!

      • v0.0.2
      • 7.94
      • Published

      npmaudit2slack

      Post results from npm audit to a Slack channel

      • v1.0.0-beta.5
      • 7.90
      • Published

      npm-check-plus

      Project audit utility with CLI and API interfaces that checks vulnerabilities, dependencies, and updates.

      • v1.0.0-alpha.5
      • 6.96
      • Published

      @soos-io/sample-project-node-package-fetch

      SOOS ( https://soos.io ) is an independent software security company, located in Winooski, VT USA, building security software for your team. Used for testing purposes, this tool is an example of fetching package information from SOOS.

      • v1.0.2
      • 6.93
      • Published

      defendjs

      Middleware to detect and alert security vulnerabilities in real-time development mode

        • v1.0.0
        • 5.78
        • Published

        osv-npm-scan

        Scan package.json vulnerabilities in OSV Databases

        • v1.0.0
        • 5.71
        • Published

        @soos-io/sample-project-node-vulnerability-fetch

        SOOS ( https://soos.io ) is an independent software security company, located in Winooski, VT USA, building security software for your team. Used for testing purposes, this tool is an example of fetching vulnerability information from SOOS.

        • v1.0.1
        • 4.40
        • Published

        scansafe

        Scans source code packages for potential javascript vulnerabilities listed as strings or regular expressions.

        • v1.0.1
        • 4.32
        • Published

        @vapurrmaid/smorgasbord

        Smorgasbord checks for a variety of served files that should not be exposed.

        • v0.5.1
        • 2.75
        • Published

        auditly

        Visualization tool for npm audit.

        • v1.1.1
        • 2.74
        • Published

        windows-vulnerabilities

        Get the number of known security vulnerabilities for your current windows 10 version

        • v0.0.22
        • 0.00
        • Published

        nucleaus

        CLI which can be used to interface with Nucleaus. Initiate scans, retrieve scan results, etc.

          • v2.0.1
          • 0.00
          • Published

          package-ignore

          The missing tool to clean up the package.json file before publishing.

          • v1.0.0
          • 0.00
          • Published