3,937 packages matching “hardcoded”
lightning-flow-scanner
v6.19.5 · 29 days ago
A Salesforce CLI plugin for analysis and optimization of Salesforce Flow. Scans metadata for 20+ issues such as hardcoded IDs, unsafe contexts, inefficient SOQL/DML operations, recursion risks, and missing fault handling. Supports auto-fixes, rule configu
No known vulnerabilities
@i2analyze/example-connector
v1.0.3 · 4 months ago
The `example-connector` provides eleven services that return data from a hardcoded data set:
No known vulnerabilities
hardcoded-hint
v0.0.1 · 7 years ago
Hardcoded prompt tool
No known vulnerabilities
git-cli-scanner
v1.5.6 · 20 days ago
A powerful interactive CLI tool that scans your codebase for hardcoded secrets, API keys, passwords, and private keys before they reach your Git history.
No known vulnerabilities
ai-localize-vscode
v4.0.1 · 1 month ago
Highlight hardcoded text, extract locale keys, and validate translations
No known vulnerabilities
eslint-plugin-jwt-security
v3.3.0 · 17 days ago
ESLint plugin for JWT security — detects algorithm confusion (CVE-2022-23540), alg:none, weak or hardcoded secrets, and decode-without-verify.
No known vulnerabilities
ubon
v3.2.3 · 4 months ago
Security scanner for AI-generated apps (Cursor, Lovable, Windsurf, v0). Catches hardcoded secrets, prompt injection, hallucinated imports, Server Actions / Edge runtime mistakes, and the vibe-coded vulnerabilities traditional linters miss.
No known vulnerabilities
eslint-plugin-mongodb-security
v9.1.3 · 23 days ago
ESLint plugin for MongoDB and Mongoose security — detects NoSQL operator injection, unsafe queries and regex, hardcoded connection strings, and missing TLS.
No known vulnerabilities
eslint-plugin-vercel-ai-security
v2.1.3 · 23 days ago
ESLint plugin for Vercel AI SDK security — detects prompt injection, system-prompt leaks, hardcoded API keys, and unvalidated model output in generateText and streamText.
No known vulnerabilities
@localize-infra/cli
v0.4.0 · 9 days ago
Extract hardcoded UI strings from a React codebase, translate them, and open a pull request with the locale files.
No known vulnerabilities
@bernierllc/validators-secret-patterns
v1.6.0 · 4 months ago
Primitive validator for detecting hardcoded secrets and sensitive patterns in code
No known vulnerabilities
@discordstyles/classes
v1.0.6 · 8 months ago
A SCSS helper function to select classes without any hardcoded values
No known vulnerabilities
eslint-plugin-design-tokens
v1.5.0 · 9 days ago
ESLint rules that catch hardcoded colors, spacing, typography, shadows, radii, borders, transitions and z-index in sx/style/css props and styled-components, so design tokens stay the only source of truth.
No known vulnerabilities
@thkimsw98/slopscan
v0.1.2 · 29 days ago
Free offline CLI that scans your local repo for hardcoded secrets and risky AI-generated code before you ship.
No known vulnerabilities
sic-security
v7.0.0 · 3 months ago
SIC free code scanner — read-only static analysis for hardcoded secrets, dangerous patterns, and dependency CVEs. Zero runtime dependencies.
No known vulnerabilities
gulp-i18n-lint
v0.1.1 · 9 years ago
> A [gulp](http://gulpjs.com/) plugin that lints your templates for hardcoded texts
No known vulnerabilities
@sam-ael/medusa-plugin-mailer
v0.2.0 · 2 months ago
Medusa v2 email notifications: hardcoded events, DB mappings (no seed), SMTP delivery.
No known vulnerabilities
i18n-smell-detector
v0.9.1 · 2 months ago
Find copied locale values, placeholder mismatches, and hardcoded user-visible strings.
No known vulnerabilities
eslint-plugin-openai-security
v0.3.4 · 23 days ago
ESLint plugin for OpenAI SDK security — catches dangerouslyAllowBrowser, hardcoded API keys, and system prompts assembled from untrusted input.
No known vulnerabilities
correctover-scan
v3.2.2 · 2 hours ago
Correctover Security Scanner — CCS audit for MCP configurations AND published JS bundles/npm packages. Detects hardcoded secrets, RCE, SSRF, credential hijacking against OWASP AISVS 1.0.
No known vulnerabilities