qlscan

A zero-setup CodeQL pre-commit scanner for JavaScript/TypeScript.

npm-api-analyzer

CLI tool to analyze npm packages for network API usage, prototype pollution, and security vulnerabilities