$npx skillfedfor your agent

njsscan

njsscan is a SAST tool that can find insecure code patterns in your Node.js applications.

With conditionsPyPI Quality AssuranceReleased Aug 2026163.0K downloads / mocopyleft licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — njsscan-1.0.0-py3-none-any.whl
v1.0.0 · released 2026-08-11 · Python >=3.10 · 6 runtime deps: colorama, libsast, semgrep, sarif-om, jschema-to-python, tabulate

Yes, if you develop Node.js applications on Mac or Linux and want to integrate security scanning into your workflow. The tool is actively maintained, has no known vulnerabilities, and offers both CLI and Python API access. The LGPLv3+ license is a consideration for proprietary software; review your distribution model before use. Windows is not supported.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10+ and runs only on Mac and Linux (not Windows).
  • Low install friction with a pure Python wheel.
  • Actively maintained as of 2026-08-11 with recent releases.

License · maintenance · safety

copyleft license (copyleft) — Licensed under LGPLv3+, a copyleft license. Derivative works and modifications must be released under the same license; using this in proprietary software requires careful review of your distribution model.

last release 2026-08-11 (3 days) · last repo commit 2026-08-11 · 446 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 163,023 downloads/mo, #10,580 on PyPI

Verify before relying

pip install njsscan

from njsscan.njsscan import NJSScan
scanner = NJSScan(['/path/to/node/code'], json=True)
scanner.scan()
  • Whether semgrep and libsast dependencies are pre-installed or downloaded on first run, and any network/system requirements they impose.
  • Performance characteristics and typical scan time for large Node.js codebases.
  • Whether the tool can be integrated into CI/CD pipelines beyond the GitHub Actions example shown.
Same gist for agents: .md · .json

What it is and what it does

njsscan combines two scanning approaches to find security issues in Node.js code: simple pattern matching via libsast and syntax-aware semantic analysis via semgrep. It detects common vulnerabilities like SQL injection, cross-site scripting (XSS), open redirects, and other OWASP-class issues. The tool runs from the command line or as a Python library, accepts configuration files to customize rules and ignore paths, and outputs results in multiple formats including JSON, SARIF, SonarQube, DefectDojo, GitLab SAST, and HTML.

The package is designed for developers and security teams integrating code scanning into development workflows. It supports suppressing individual findings via inline comments, filtering by severity level, and overriding rule severity. Runtime dependencies include colorama for terminal output, tabulate for formatted tables, and the two core scanning engines (libsast and semgrep), plus utilities for schema validation and SARIF report generation.

Use it for

  • Scan Node.js source code in CI/CD pipelines to catch security issues before deployment.
  • Integrate into local development workflows to find insecure patterns during code review.
  • Generate compliance-ready security reports in SonarQube, DefectDojo, or GitLab SAST formats.
  • Suppress known false positives or acceptable patterns using inline comments and configuration files.
  • Audit existing Node.js codebases for common vulnerabilities like SQL injection and XSS.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you develop Node.js applications on Mac or Linux and want to integrate security scanning into your workflow.

The tool is actively maintained, has no known vulnerabilities, and offers both CLI and Python API access. The LGPLv3+ license is a consideration for proprietary software; review your distribution model before use. Windows is not supported.

Install

njsscan on PyPI

Before you install

Low install friction with a pure Python wheel. Actively maintained as of 2026-08-11 with recent releases. Requires Python 3.10 or later and runs on Mac and Linux only.

Requires Python 3.10+ and runs only on Mac and Linux (not Windows).

License in practice

Licensed under LGPLv3+, a copyleft license. Derivative works and modifications must be released under the same license; using this in proprietary software requires careful review of your distribution model.

Quickstart

pip install njsscan

from njsscan.njsscan import NJSScan
scanner = NJSScan(['/path/to/node/code'], json=True)
scanner.scan()

Verify before relying

  • Whether semgrep and libsast dependencies are pre-installed or downloaded on first run, and any network/system requirements they impose.
  • Performance characteristics and typical scan time for large Node.js codebases.
  • Whether the tool can be integrated into CI/CD pipelines beyond the GitHub Actions example shown.

Package facts

Licensecopyleft license copyleft
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
6 packages
coloramalibsastsemgrepsarif-omjschema-to-pythontabulate
MaintenanceActively maintained 3 days since the last release
Last repo commit
First released
Downloads163,023 / month, #10,580 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: GNU Lesser General Public License v3 or later (LGPLv3+)Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14

Evidence: njsscan-1.0.0-py3-none-any.whl

Tags

Capabilities
node.js security scanningsast tool javascriptstatic code analysis nodejsvulnerability detection javascriptcode pattern matching securitysemgrep nodejsinsecure code patterns
Topics
security-scanningnodejssast

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “node.js security scanning”

  • njsscannjsscan is a static application security testing (SAST) tool that…
  • socketsecuritySocket Security CLI scans Python projects for supply-chain security…
  • vt-pyOfficial Python client for the VirusTotal REST API v3, enabling file…

Give your agent the search over MCP, or paste the wish link into any chat.

More Quality Assurance packages

coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
ruff Worth it
PyPI · Python Modules · released Aug 2026

Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.

MITcompiled wheel · 3.7+
316.1Mdownloads / mo
pexpect With conditions
PyPI · Software Development · released Nov 2023

Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.

ISCpure Pythonaging
200.8Mdownloads / mo
black Worth it
PyPI · Python Modules · released May 2026

Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.

MITpure Python · 3.10+
179.9Mdownloads / mo
pytest-xdist Worth it
PyPI · Utilities · released Jul 2025

pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.

Install it if your test suite takes long enough that parallelization would save meaningful time.

MITpure Python · 3.9+
177.1Mdownloads / mo
cfn-lint Worth it
PyPI · Quality Assurance · released Aug 2026

Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.

Install it if you work with CloudFormation templates.

MIT-0pure Python
114.9Mdownloads / mo

See also libsast · mobsfscan · secscanner2junit · semgrep · kingfisher-bin · cycode · cisco-ai-skill-scanner · trailmark · xbsl · MarkupSafe

Further reading