11,684 packages matching “prototype pollution”
@billdaddy/mergekit
v0.1.1 · 3 months ago
Tiny, type-safe deep merge — immutable, prototype-pollution safe, with configurable array strategy. Zero dependencies.
No known vulnerabilities
@nifrajs/edge
v3.3.0 · 26 days ago
Compact fetch-handler server for edge and serverless runtimes (Cloudflare Workers, Vercel Edge, Deno Deploy, Bun). Keeps the server().get().post() DX and the full request trust boundary - bounded body read, Content-Length pre-reject, prototype-pollution g
No known vulnerabilities
pinelight-detectors
v0.2.0 · 1 month ago
Pinelight Labs' open-source AST security scanner + CLI. Run `pinelight scan .` to find SQL injection, XSS, secrets, path traversal, command injection, weak crypto, race conditions, vulnerable dependencies, prototype pollution, and prompt injection in your
No known vulnerabilities
null-prototype-object
v1.2.7 · 5 months ago
Fastest way for creating null-prototype objects in JavaScript
No known vulnerabilities
@arcis/node
v1.7.1 · 3 months ago
Inside-the-app security middleware for Node.js. Express and NestJS run the full sanitizer pipeline (XSS, SQL, NoSQL, SSTI, XXE, path, command, prompt injection, prototype pollution, LDAP, XPath, header injection, plus 20+ more attack types). Fastify, Koa,
No known vulnerabilities
neotraverse
v1.0.1 · 3 months ago
traverse and transform objects by visiting every node on a recursive walk
No known vulnerabilities
jsonpath-rewritten
v1.0.1 · 7 months ago
Rewrite of the https://www.npmjs.com/package/jsonpath library fixing prototype pollution CVE
No known vulnerabilities
@ecorpin/utils-extend-patch
v1.0.10 · 1 year ago
Patched utils-extend with deny-list for prototype pollution in utils-extend
No known vulnerabilities
no-pollution
v1.0.2 · 7 years ago
Prevent prototype pollution by sanitizing all string inputs to the JSON parser
No known vulnerabilities
minimist
v1.2.8 · 3 years ago
parse argument options
No known vulnerabilities
exceljs-hardened
v5.0.0 · 29 days ago
Unofficial security-hardened fork of exceljs, patching known unpatched vulnerabilities in the upstream (unmaintained) project. Not affiliated with the original exceljs maintainers.
No known vulnerabilities
kotlified-ts
v0.1.0 · 1 month ago
Compile-time Kotlin extension functions (let/apply/run/also/takeIf/takeUnless) for Vite — zero prototype pollution.
No known vulnerabilities
npm-api-analyzer
v1.0.3 · 1 year ago
CLI tool to analyze npm packages for network API usage, prototype pollution, and security vulnerabilities
No known vulnerabilities
@ktuban/safe-json-loader
v1.1.3 · 7 months ago
A security‑hardened JSON loader with prototype‑pollution protection, depth limits, safe parsing, and optional validation layers.
No known vulnerabilities
@opsimathically/safejsonparse
v1.0.0 · 1 year ago
Parse untrusted JSON, avoiding potential prototype pollution/bad type issues.
No known vulnerabilities
secure-qs
v0.0.1 · 1 year ago
A secure and simple query string parser and stringifier for Node.js and TypeScript. Prevents prototype pollution.
No known vulnerabilities
xlsx-prototype-pollution-fixed
v0.19.3 · 3 years ago
SheetJS Spreadsheet data parser and writer
No known vulnerabilities
sealenv
v2.0.1 · 3 months ago
Validate, type-check, and secure your environment variables — with prototype pollution detection, secret masking, and a CI-ready CLI.
No known vulnerabilities
static-extend
v0.1.2 · 10 years ago
Adds a static `extend` method to a class, to simplify inheritance. Extends the static properties, prototype properties, and descriptors from a `Parent` constructor onto `Child` constructors.
No known vulnerabilities
dotpathkit
v0.1.1 · 3 months ago
Tiny, type-safe deep get/set by dot-path — immutable set/unset, prototype-pollution safe, array-index syntax. Zero dependencies.
No known vulnerabilities