Skip to main content
interlace
Plugin: jwt

eslint-plugin-jwt-security

JSON Web Token security patterns and validation rules

AI-Optimized Security

Every rule includes CWE, OWASP, and CVSS metadata for AI assistants to provide precise, context-aware fixes.

Install

npm install -D eslint-plugin-jwt-security

Live from GitHub

This content is fetched directly from README.md on GitHub and cached for 1 hour.

Live README from GitHubfrom eslint-plugin-jwt-security/README.md, cached for 1 hour.Edit on GitHub

⭐ If this plugin caught a real bug for you, star the repo β€” it's the signal that keeps these rules maintained.

Description

This plugin provides Security validation for JSON Web Tokens (JWT) implementation (signing, verification).

  • Why β€” a linter nobody reads protects nothing. We would rather miss a finding than spend your attention on one that was never real.
  • How β€” evidence, not names. A rule fires on what the code does, resolved through the AST and ESLint's own scope analysis.
  • What β€” every finding carries its fix, in prose for a human and as structured JSON for an agent. Security rules add a CWE mapping and, where assigned, a CVSS score.

That trade costs recall, and we measure it: methodology Β· results Β· a false positive is a bug.

Getting Started

npm install eslint-plugin-jwt-security --save-dev

βš™οΈ Configuration Presets

PresetDescription
recommendedRecommended preset - balanced security
strictStrict preset - maximum security (includes 2025 research)
legacyLegacy preset - migration mode
allAll rules preset

πŸ“š Supported Libraries

LibrarynpmDownloadsDetection
jsonwebtokennpmdownloadsSigning, Verification, Decoding
josenpmdownloadsVerification (Fix Suggestion)
jwt-decodenpmdownloadsUnsafe Decoding

πŸ€– AI-Optimized Messages

Every rule uses formatLLMMessage for structured output:

πŸ”’ CWE-347 OWASP:A02-Crypto CVSS:9.8 | Using alg:"none" bypasses signature verification
   Fix: Remove "none" and use RS256, ES256, or other secure algorithms
   https://nvd.nist.gov/vuln/detail/CVE-2022-23540

By providing this structured context (CWE, OWASP, Fix), we enable AI tools to reason about the security flaw rather than hallucinating. This allows Copilot/Cursor to suggest the exact correct fix immediately.

By structuring errors with specific CWE codes, OWASP categories, and direct fix suggestions, this format allows AI coding assistants to autonomously identify, explain, and resolve security vulnerabilities with high confidence.

πŸ’‘ What You Get

  • 13 Security Rules - Algorithm attacks, replay prevention, claim validation
  • 6 JWT Libraries - jsonwebtoken, jose, express-jwt, @nestjs/jwt, jwks-rsa, jwt-decode
  • 2025 Research - "Back to the Future" replay attack prevention (LightSEC 2025)
  • AI-Optimized - Structured messages for GitHub Copilot, Cursor, Claude assistance
  • CWE References - Every rule maps to Common Weakness Enumeration

πŸ“¦ Compatibility

PackageVersion
ESLint^8.40.0 || ^9.0.0 || ^10.0.0
Node.js>=18.0.0

See the ESLint Version Support Policy β€” current ecosystem share data, the 20% gate, and the forward-looking exception that covers v10.

Rules

Legend

IconDescription
πŸ’ΌRecommended: Included in the recommended preset.
⚠️Warns: Set to warn in recommended preset.
πŸ”§Auto-fixable: Automatically fixable by the --fix CLI option.
πŸ’‘Suggestions: Providing code suggestions in IDE.
🚫Deprecated: This rule is deprecated.
🟒Type-unaware: AST-only, runs in oxlint JS-plugin tier.
🟑Type-aware (refining): pure-AST primary path; types refine precision.
🟠Type-aware (graceful): requires TS program; silent without it.
RuleCWEOWASPCVSSDescriptionπŸ§ πŸ’Όβš οΈπŸ”§πŸ’‘πŸš«
no-algorithm-confusionCWE-347This rule detects algorithm confusion attacks where symmetric algorithms (HS256, HS384, HS512) are used witβ€¦πŸŸ’πŸ’Ό
no-algorithm-noneCWE-347This rule detects attempts to use the none algorithm which completely bypasses JWT signature verificationπŸŸ’πŸ’Ό
no-decode-without-verifyCWE-345The rule provides LLM-optimized error messages (Compact 2-line format) with actionable security guidance:πŸŸ’πŸ’Ό
no-hardcoded-secretCWE-798The rule provides LLM-optimized error messages (Compact 2-line format) with actionable security guidance:πŸŸ’πŸ’Ό
no-sensitive-payloadCWE-359JWT payloads are NOT encrypted, only base64-encoded🟒⚠️
no-timestamp-manipulationCWE-294This rule detects noTimestamp: true which disables automatic iat (issued at) claim generationπŸŸ’πŸ’Ό
no-weak-secretCWE-326The rule provides LLM-optimized error messages (Compact 2-line format) with actionable security guidance:πŸŸ’πŸ’Ό
require-algorithm-whitelistCWE-757This rule enforces explicit algorithm specification in verify() callsπŸŸ’πŸ’Ό
require-audience-validationCWE-287The rule provides LLM-optimized error messages (Compact 2-line format) with actionable security guidance:🟒
require-expirationCWE-613The rule provides LLM-optimized error messages (Compact 2-line format) with actionable security guidance:πŸŸ’πŸ’Ό
require-issued-atCWE-294This rule ensures tokens have the iat claim for freshness validation🟒
require-issuer-validationCWE-287The rule provides LLM-optimized error messages (Compact 2-line format) with actionable security guidance:🟒
require-max-ageCWE-294This rule mandates maxAge in verify operations🟒

Part of the Interlace ESLint ecosystem β€” AI-native rules with LLM-optimized error messages:

Security

PluginDownloadsDescription
eslint-plugin-anthropic-securitydownloadsAnthropic SDK security.
eslint-plugin-browser-securitydownloadsXSS, DOM security.
eslint-plugin-drizzle-securitydownloadsDrizzle security.
eslint-plugin-express-securitydownloadsExpress middleware hardening.
eslint-plugin-gemini-securitydownloadsGoogle Gemini SDK security.
eslint-plugin-knex-securitydownloadsKnex security.
eslint-plugin-lambda-securitydownloadsAWS Lambda hardening.
eslint-plugin-mcp-sdk-securitydownloadsMCP SDK security.
eslint-plugin-mongodb-securitydownloadsMongoDB injection.
eslint-plugin-mysql-securitydownloadsMySQL security.
eslint-plugin-nestjs-securitydownloadsNestJS framework hardening.
eslint-plugin-node-securitydownloadsServer-side patterns.
eslint-plugin-openai-securitydownloadsOpenAI SDK security.
eslint-plugin-postgresql-securitydownloadsPostgreSQL security.
eslint-plugin-prisma-securitydownloadsPrisma security.
eslint-plugin-secure-codingdownloadsInjection prevention.
eslint-plugin-sequelize-securitydownloadsSequelize ORM security.
eslint-plugin-sqlite-securitydownloadsSQLite security.
eslint-plugin-typeorm-securitydownloadsTypeORM security.
eslint-plugin-vercel-ai-securitydownloadsAI SDK security.

Code quality

PluginDownloadsDescription
eslint-plugin-conventionsdownloadsTeam-specific habits and styles.
eslint-plugin-import-nextdownloadsFast cycle + import-graph analysis.
eslint-plugin-maintainabilitydownloadsCognitive load and clean-code patterns.
eslint-plugin-modernizationdownloadsESNext migration + syntax evolution.
eslint-plugin-modularitydownloadsStructural integrity and DDD patterns.
eslint-plugin-operabilitydownloadsProduction readiness and resource health.
eslint-plugin-react-a11ydownloadsReact accessibility / WCAG.
eslint-plugin-react-featuresdownloadsReact best practices and optimization.
eslint-plugin-reliabilitydownloadsRuntime stability and error safety.

⭐ Support & follow

If this plugin caught a real bug for you, star the repo β€” stars are the signal that keeps the Interlace ESLint ecosystem maintained β€” and follow the writeups on Dev.to for the benchmarks and security research behind these rules.

GitHub stars

πŸ“„ License

MIT Β© Ofri Peretz

View README.md on GitHub β†’

Building secure JavaScript with Interlace? Star the repo to get new rules and CWE coverage as we ship them β€” or follow the AI-code-security benchmarks behind them.