Skip to main content
interlace
Plugin: mongodb-security

eslint-plugin-mongodb-security

NoSQL injection, operator attacks, and MongoDB/Mongoose security rules

AI-Optimized Security

Every rule includes CWE, OWASP, and CVSS metadata for AI assistants to provide precise, context-aware fixes.

Install

npm install -D eslint-plugin-mongodb-security

Live from GitHub

This content is fetched directly from README.md on GitHub and cached for 1 hour.

Live README from GitHubfrom eslint-plugin-mongodb-security/README.md, cached for 1 hour.Edit on GitHub

⭐ If this plugin caught a real bug for you, star the repo β€” it's the signal that keeps these rules maintained.

Description

This plugin provides Security rules for MongoDB queries and interactions (NoSQL injection).

  • Why β€” a linter nobody reads protects nothing. We would rather miss a finding than spend your attention on one that was never real.
  • How β€” evidence, not names. A rule fires on what the code does, resolved through the AST and ESLint's own scope analysis.
  • What β€” every finding carries its fix, in prose for a human and as structured JSON for an agent. Security rules add a CWE mapping and, where assigned, a CVSS score.

That trade costs recall, and we measure it: methodology Β· results Β· a false positive is a bug.

Getting Started

npm install eslint-plugin-mongodb-security --save-dev

βš™οΈ Configuration Presets

PresetDescription
recommendedCritical rules as errors, high as warnings
strictAll rules as errors
mongooseSpecialized rules for Mongoose ODM usage patterns

πŸ“š Supported Libraries

LibrarynpmDownloadsDetection
mongodbnpmdownloadsInjection, Unbounded Queries
mongoosenpmdownloadsSchema Safety, Leans

🏒 Usage Examples

Prevent NoSQL Injection (no-operator-injection)

// ❌ Incorrect (Vulnerable to { $ne: null })
User.findOne({ email: req.body.email, password: req.body.password });

// βœ… Correct (Safe execution)
User.findOne({ email: { $eq: email }, password: { $eq: password } });

Prevent JavaScript Injection (no-unsafe-where)

// ❌ Incorrect (Allows RCE)
User.find({ $where: `this.name === '${userInput}'` });

// βœ… Correct (Standard operators)
User.find({ name: { $eq: sanitize(userInput) } });

πŸ“¦ Compatibility

PackageVersion
ESLint^8.40.0 || ^9.0.0 || ^10.0.0
Node.js>=18.0.0

See the ESLint Version Support Policy β€” current ecosystem share data, the 20% gate, and the forward-looking exception that covers v10.

Rules

Legend

IconDescription
πŸ’ΌRecommended: Included in the recommended preset.
⚠️Warns: Set to warn in recommended preset.
πŸ”§Auto-fixable: Automatically fixable by the --fix CLI option.
πŸ’‘Suggestions: Providing code suggestions in IDE.
🚫Deprecated: This rule is deprecated.
🟒Type-unaware: AST-only, runs in oxlint JS-plugin tier.
🟑Type-aware (refining): pure-AST primary path; types refine precision.
🟠Type-aware (graceful): requires TS program; silent without it.
RuleCWEOWASPCVSSDescriptionπŸ§ πŸ’Όβš οΈπŸ”§πŸ’‘πŸš«
no-bypass-middlewareCWE-284A01:2021Detects Mongoose operations that bypass middleware hooks (pre/post hooks).🟒⚠️
no-debug-mode-productionCWE-489A05:2021Detects Mongoose debug mode that could expose sensitive query information in production.πŸŸ’πŸ’ΌπŸ’‘
no-hardcoded-connection-stringCWE-798A07:2021Detects hardcoded MongoDB connection strings containing credentials in source code.πŸŸ’πŸ’Ό
no-hardcoded-credentialsCWE-798A07:2021Detects hardcoded MongoDB authentication credentials in connection options.πŸŸ’πŸ’Ό
no-operator-injectionCWE-943A03:2021Detects MongoDB operator injection attacks where user input is passed directly as query values, allowing atβ€¦πŸŸ’πŸ’Ό
no-select-sensitive-fieldsCWE-200A01:2021Detects queries that may return sensitive fields like passwords, tokens, or API keys.🟒⚠️
no-unbounded-findCWE-400A04:2021Requires limit() on find queries to prevent resource exhaustion from unbounded result sets.πŸŸ’βš οΈπŸ’‘
no-unsafe-populateCWE-943A03:2021Detects user-controlled populate() paths that could lead to data exposure or injection.πŸŸ’πŸ’Ό
no-unsafe-queryCWE-943A03:2021Prevents NoSQL injection by detecting direct use of user input in MongoDB query objects.πŸŸ’πŸ’ΌπŸ’‘
no-unsafe-regex-queryCWE-400A03:2021Detects user input in MongoDB $regex operators that could cause ReDoS (Regular Expression Denial of Serviceβ€¦πŸŸ’πŸ’Ό
no-unsafe-whereCWE-943A01:2021Prevents use of the dangerous $where operator which executes JavaScript on the MongoDB server, enabling Remβ€¦πŸŸ’πŸ’Ό
require-auth-mechanismCWE-287A07:2021Requires explicit authentication mechanism specification for MongoDB connections.🟒⚠️
require-lean-queriesCWE-400A04:2021Suggests using .lean() for read-only Mongoose queries to reduce memory usage.πŸŸ’πŸ’‘
require-projectionCWE-200A01:2021Requires field projection on queries to minimize data exposure.🟒
require-schema-validationCWE-20A04:2021Requires validation options on Mongoose schema fields to prevent invalid or malicious data.🟒⚠️
require-tls-connectionCWE-295A02:2021Requires TLS/SSL encryption for MongoDB connections in production environments.πŸŸ’βš οΈπŸ’‘

Part of the Interlace ESLint ecosystem β€” AI-native rules with LLM-optimized error messages:

Security

PluginDownloadsDescription
eslint-plugin-anthropic-securitydownloadsAnthropic SDK security.
eslint-plugin-browser-securitydownloadsXSS, DOM security.
eslint-plugin-drizzle-securitydownloadsDrizzle security.
eslint-plugin-express-securitydownloadsExpress middleware hardening.
eslint-plugin-gemini-securitydownloadsGoogle Gemini SDK security.
eslint-plugin-jwt-securitydownloadsToken security.
eslint-plugin-knex-securitydownloadsKnex security.
eslint-plugin-lambda-securitydownloadsAWS Lambda hardening.
eslint-plugin-mcp-sdk-securitydownloadsMCP SDK security.
eslint-plugin-mysql-securitydownloadsMySQL security.
eslint-plugin-nestjs-securitydownloadsNestJS framework hardening.
eslint-plugin-node-securitydownloadsServer-side patterns.
eslint-plugin-openai-securitydownloadsOpenAI SDK security.
eslint-plugin-postgresql-securitydownloadsPostgreSQL security.
eslint-plugin-prisma-securitydownloadsPrisma security.
eslint-plugin-secure-codingdownloadsInjection prevention.
eslint-plugin-sequelize-securitydownloadsSequelize ORM security.
eslint-plugin-sqlite-securitydownloadsSQLite security.
eslint-plugin-supabase-securitydownloadsSupabase security.
eslint-plugin-typeorm-securitydownloadsTypeORM security.
eslint-plugin-vercel-ai-securitydownloadsAI SDK security.

Code quality

PluginDownloadsDescription
eslint-plugin-conventionsdownloadsTeam-specific habits and styles.
eslint-plugin-import-nextdownloadsFast cycle + import-graph analysis.
eslint-plugin-maintainabilitydownloadsCognitive load and clean-code patterns.
eslint-plugin-modernizationdownloadsESNext migration + syntax evolution.
eslint-plugin-modularitydownloadsStructural integrity and DDD patterns.
eslint-plugin-operabilitydownloadsProduction readiness and resource health.
eslint-plugin-react-a11ydownloadsReact accessibility / WCAG.
eslint-plugin-react-featuresdownloadsReact best practices and optimization.
eslint-plugin-reliabilitydownloadsRuntime stability and error safety.

⭐ Support & follow

If this plugin caught a real bug for you, star the repo β€” stars are the signal that keeps the Interlace ESLint ecosystem maintained β€” and follow the writeups on Dev.to for the benchmarks and security research behind these rules.

GitHub stars

πŸ“„ License

MIT Β© Ofri Peretz

View README.md on GitHub β†’

Building secure JavaScript with Interlace? Star the repo to get new rules and CWE coverage as we ship them β€” or follow the AI-code-security benchmarks behind them.