AuditJS Logo

AuditJS

AuditJS is a command-line tool that scans JavaScript projects for known vulnerabilities and outdated packages in npm dependencies using the OSS Index API or Nexus IQ Server.

229
Application Security
Free
Visit website
0

AuditJS Description

AuditJS is a command-line tool that audits JavaScript projects for known vulnerabilities and outdated package versions. The tool integrates with the OSS Index v3 REST API to scan npm dependencies installed in node_modules folders. The tool supports multiple JavaScript package managers including npm, Angular, yarn, and bower. It can identify security vulnerabilities in project dependencies by cross-referencing them against known vulnerability databases. For enterprise users, AuditJS can connect to Nexus IQ Server (version 77 or above) as an alternative data source for vulnerability scanning. Users must have the 'Can Evaluate Applications' permission to perform scans with Nexus IQ Server. AuditJS can be installed and used in two ways: via npx for temporary usage or through global installation for permanent access. The tool supports Node.js LTS versions 8.x and forward, making it compatible with most modern JavaScript development environments. The tool provides vulnerability assessment capabilities specifically focused on JavaScript package dependencies, helping developers identify and address security issues in their project's third-party components.

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.

10
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

5
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

5
Fabric Platform by BlackStork Logo

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

5
Mandos Brief Newsletter Logo

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

5
View Popular Tools →