Matchboxmatchbox
← Back to match

JS-X-Ray

SAST scanner that detects malicious patterns and supply-chain risks in JavaScript and Node.js code.

Pluginfreeglobal

JS-X-Ray is a JavaScript and TypeScript SAST scanner that parses code into an AST to detect malicious patterns, obfuscation, and supply-chain risks that RegEx- or Semgrep-based tools miss — tracing variables and imports to catch data exfiltration, unsafe shell commands, and dangerous eval() usage. Originally built for NodeSecure CLI, it's now an independent tool for JS/Node.js developers and security teams protecting against supply-chain attacks.

Categories
security toolsstatic analysissupply-chain security

Full match profile

Behind the summary, Matchbox keeps a richer profile of JS-X-Ray - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether JS-X-Ray (or something else) actually fits.