← Back to match
JS-X-Ray
SAST scanner that detects malicious patterns and supply-chain risks in JavaScript and Node.js code.
Pluginfreeglobal
JS-X-Ray is a JavaScript and TypeScript SAST scanner that parses code into an AST to detect malicious patterns, obfuscation, and supply-chain risks that RegEx- or Semgrep-based tools miss — tracing variables and imports to catch data exfiltration, unsafe shell commands, and dangerous eval() usage. Originally built for NodeSecure CLI, it's now an independent tool for JS/Node.js developers and security teams protecting against supply-chain attacks.
Categories
security toolsstatic analysissupply-chain security

