ajinabraham/nodejsscan

Repository files navigation

Static security code scanner (SAST) for Node.js applications powered by libsast and semgrep.

Made with Lovein India Tweet

platformLicensepythonTests

  • Donate via Paypal: Donate via Paypal
  • Sponsor the Project: Github Sponsors

OpSecX Video CourseOpSecX Node.js Security: Pentesting and Exploitation - NJS

docker pull opensecurity/nodejsscan:latest
docker run -it -p 9090:9090 opensecurity/nodejsscan:latest

Install Postgres and configure SQLALCHEMY_DATABASE_URI in nodejsscan/settings.py or as environment variable.

From version 4 onwards, windows support is dropped.

git clone https://.com/ajinabraham/nodejsscan.git
cd nodejsscan
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
python3 manage.py recreate-db # Run once to create database schema

To run nodejsscan

./run.sh

This will run nodejsscan web user interface at http://127.0.0.1:9090

njsscan_cli

Watch the video

Create your slack app Slack App and set SLACK_WEBHOOK_URL in nodejsscan/settings.py or as environment variable.

nodejsscan slack alert

Configure SMTP settings in nodejsscan/settings.py or as environment variable.

docker build -t nodejsscan .
docker run -it -p 9090:9090 nodejsscan

nodejsscan web uinodejsscan dashboardnodejsscan chartsnodejsscan overviewnodejsscan findings

Sponsor this project

  •  

Packages

No packages published

Contributors 13