89 AI-parseable security rules with OWASP Top 10 2021 + Mobile 2024 coverage. The flagship security plugin with LLM-optimized error messages for both human developers and AI coding assistants.
XSS prevention, postMessage abuse detection, storage token exposure, and CSP enforcement. Essential for frontend security.
24 rules for cryptographic best practices and CVE detection. Catches weak algorithms, insecure random generation, and deprecated crypto APIs.
JWT security rules covering algorithm confusion attacks, weak secrets, and library-specific CVEs for jsonwebtoken, jose, and jwt-decode.
Drop-in replacement for eslint-plugin-import with 100x faster no-cycle detection. Optimized for modern Nx monorepos and large-scale codebases.
Security rules for NestJS applications covering guards, validation pipes, throttling, and sensitive field exposure.
Since Dec 1, 2025