132 packages matching “idor”
idor
v2.0.1 · 3 years ago
A type-based ID obfuscation library to prevent insecure direct object references (IDOR)
No known vulnerabilities
mcp-tenant-isolation
v2.0.0 · 1 month ago
Static analysis scanner for MCP server code and multi-tenant SaaS applications. 57 deterministic rules covering tenant isolation, tool visibility, cache key scoping, RLS, IDOR, and credential vault isolation. MCP server for AI agent integration.
No known vulnerabilities
avantgate
v2.0.0 · 2 hours ago
Zero-infrastructure, in-process AI Application Firewall (AI-WAF) & privacy control plane for TypeScript: real-time prompt guardrails, zero-egress PII redaction, agent tool isolation, anti-IDOR defense, pre-flight token budgets, and multi-model failover.
No known vulnerabilities
authzscan
v0.2.0 · 1 month ago
Autonomous IDOR/BOLA (broken access control) review for Next.js App Router repos, driven by Claude agents.
No known vulnerabilities
atsuomi
v0.0.0 · 29 days ago
Deterministic code quality and security analysis for TypeScript — SAST, secret detection, IDOR, code smells, real test coverage. No AI layer; also usable as a guardrail for AI-generated code. Placeholder release; implementation in progress.
No known vulnerabilities
flarehq-mcp
v0.2.1 · 1 month ago
Flare MCP server: let Claude Code, Cursor or Windsurf scan your running app and repo for leaked secrets, exposed routes, open RLS, missing rate limits and injection risks, test for IDOR / broken object-level authorization across two accounts, and verify w
No known vulnerabilities
@atsuomi/cli
v0.0.0 · 29 days ago
CLI for atsuomi — deterministic code quality and security analysis for TypeScript (SAST, secret detection, IDOR, code smells, real test coverage). No AI layer; also usable as a guardrail for AI-generated code. Placeholder release; implementation in progre
No known vulnerabilities
@boldsec/next
v0.12.0 · 2 months ago
BoLD live authorization monitoring for Next.js App Router: wrap a route, watch it for cross-user access (BOLA/IDOR), function-level (BFLA), mass-assignment (BOPLA), and tenant-isolation risks. Metadata only, fail-safe.
No known vulnerabilities
@boldsec/mcp
v0.14.0 · 2 months ago
BoLD MCP server: connect, wire, and verify BoLD authorization monitoring (BOLA/IDOR, BFLA, BOPLA mass-assignment, tenant isolation, missing-auth) from your AI editor (Claude, Cursor, Codex). Metadata only; never reaches a verdict.
No known vulnerabilities
codedrift
v1.2.12 · 6 months ago
Guardrails for AI-assisted development - Detects IDOR, missing input validation, hardcoded secrets, and other critical bugs in AI-generated code
No known vulnerabilities
ironward
v3.2.0 · 5 months ago
Security scanning for the vibe coding era. MCP server + CLI that finds secrets, auth bugs, SQL injection, XSS, IDOR, and vulnerable deps — and opens fix PRs. Works in Cursor, Claude Code, and VS Code. Bring your own model (Anthropic, OpenAI, Gemini, Groq,
No known vulnerabilities
@aikidosec/firewall
v1.8.44 · 1 day ago
Zen by Aikido is an embedded Application Firewall that autonomously protects Node.js apps against common and critical attacks, provides rate limiting, detects malicious traffic (including bots), and more.
No known vulnerabilities
keysnag
v0.2.0 · 5 days ago
Cybersecurity for AI founders and vibe coders. A pre-push security gate for apps built with Claude Code, Cursor, Codex, Lovable and Bolt: 12 offline checks for leaked keys, Supabase RLS, cross-account (IDOR) access, injection, Stripe webhooks, known CVEs
No known vulnerabilities
apollo-idor
v1.0.3 · 3 years ago
Apollo Server schema directive to create opaque ID values
No known vulnerabilities
@felix-neuro/eslint-plugin-routeguard
v0.1.1 · 4 months ago
ESLint plugin for Node.js API security — detects BOLA/IDOR, mass-assignment, SSRF, SQL injection, command injection, path traversal, open redirect, and hardcoded secrets across Express, Fastify, and NestJS.
No known vulnerabilities
@boldsec/supabase
v0.1.0 · 2 months ago
BoLD live authorization monitoring for Supabase: a fetch-level wrapper for supabase-js watches your PostgREST/RPC traffic for cross-user access (BOLA/IDOR) and mass-assignment (BOPLA) risks. Metadata only, fail-safe, zero query-builder patching.
No known vulnerabilities
api-security-probe
v0.2.1 · 4 months ago
Lightweight API security probe: rate limiting, JWT attacks, BOLA, IDOR, security headers. No ZAP required.
No known vulnerabilities
@kevyn-castelo/vibeaudit
v0.1.0 · 1 month ago
Agent skills (SKILL.md) that find and fix the five security failures AI-generated code leaves behind most often: missing RLS, frontend-only authorization, IDOR, exposed secrets, unvalidated input. Works in Claude Code, Codex, OpenCode, Antigravity, Devin,
No known vulnerabilities
@boldsec/hono
v0.1.0 · 2 months ago
BoLD live authorization monitoring for Hono (4.x): one middleware watches your routes for cross-user access (BOLA/IDOR), function-level (BFLA), mass-assignment (BOPLA), and tenant-isolation risks. Metadata only, fail-safe, zero extraction logic in the ada
No known vulnerabilities
@boldsec/nestjs
v0.1.0 · 2 months ago
BoLD live authorization monitoring for NestJS (9/10/11): one global interceptor watches your routes for cross-user access (BOLA/IDOR), function-level (BFLA), mass-assignment (BOPLA), and tenant-isolation risks. Metadata only, fail-safe, zero extraction lo
No known vulnerabilities