Skip to main content
interlace
Plugin: mysql-security

Overview

MySQL security — SQL injection in raw queries

Live from GitHub

This content is fetched directly from README.md on GitHub and cached for 1 hour.

AI-Optimized Security

Every rule includes CWE, OWASP, and CVSS metadata for AI assistants to provide precise, context-aware fixes.


Live README from GitHubfrom eslint-plugin-mysql-security/README.md, cached for 1 hour.Edit on GitHub
Interlace

  

MySQL

  

oxlint

  

ESLint

Security rules for mysql2 / mysql (SQL injection prevention in raw queries).

NPM VersionNPM DownloadsPackage LicenseCodecovSince Dec 2025

⭐ If this plugin caught a real bug for you, star the repo — it's the signal that keeps these rules maintained.

Description

This plugin provides Security rules for mysql2 / mysql (SQL injection prevention in raw queries).

Why MySQL-specific?

Being MySQL-specific is what makes the rule precise. It knows which calls are raw-SQL sinks (.query(), .execute()) and which idioms are already safe, so it reports the patterns that actually lead to injection and stays quiet on parameterized queries. It also tracks variable taint across statements, so a query built on one line and executed on another is still reported.

The detection itself is shared with the other Interlace driver plugins through createSqlInjectionRule — install the one matching your stack and you get exactly one finding per line.

Philosophy

Interlace fosters strength through integration. Instead of stacking isolated rules, we interlace security directly into your workflow to create a resilient fabric of code. We believe tools should guide rather than gatekeep, providing educational feedback that strengthens the developer with every interaction.

Getting Started

npm install eslint-plugin-mysql-security --save-dev

⚙️ Configuration Presets

PresetDescription
recommendedRecommended preset - balanced security for most projects
strictStrict preset - all rules as errors
flagshipHighest-signal rules only, for CI gates

📚 Supported Libraries

LibrarynpmDownloadsDetection
mysql2npmdownloadsSQL Injection

Custom Configuration

import mysql from 'eslint-plugin-mysql-security';

export default [
  {
    plugins: { 'sequelize-security': sequelizeSecurity },
    rules: {
      'mysql-security/no-unsafe-query': 'error',
    },
  },
];

💡 What You Get

  • Covers the escapes your ORM leaves open: .query(), .execute()
  • MySQL's own remediation: every finding names MySQL's own safe API, not a generic "use parameterized queries"
  • Cross-statement taint tracking: catches queries assembled over several lines, including with +=
  • Quiet on safe code: parameterized queries, static SQL and builder calls do not report
  • LLM-optimized messages: structured 2-line errors with CWE + fixes that AI assistants can apply

Every rule produces a structured error message:

src/db.ts
  42:15  error  🔒 CWE-89 OWASP:A03-Injection CVSS:9.8 | Unsafe SQL query construction detected (template literal) | CRITICAL
                    Fix: Pass values as a second-argument array with `?` placeholders instead of interpolating them into the SQL string.

📦 Compatibility

PackageVersion
ESLint^8.0.0 || ^9.0.0 || ^10.0.0
Node.js>=18.0.0

See the ESLint Version Support Policy — current ecosystem share data, the 20% gate, and the forward-looking exception that covers v10.

Rules

Legend

IconDescription
💼Recommended: Included in the recommended preset.
⚠️Warns: Set to warn in recommended preset.
🔧Auto-fixable: Automatically fixable by the --fix CLI option.
💡Suggestions: Providing code suggestions in IDE.
🚫Deprecated: This rule is deprecated.
🟢Type-unaware: AST-only, runs in oxlint JS-plugin tier.
🟡Type-aware (refining): pure-AST primary path; types refine precision.
🟠Type-aware (graceful): requires TS program; silent without it.
RuleCWEOWASPCVSSDescription🧠💼⚠️🔧💡🚫
no-unsafe-queryCWE-89A03:2021Prevent SQL injection by disallowing string concatenation or interpolated template literals in mysql/mysql2…🟢💼
require-tlsCWE-319A02:2021Require TLS on mysql2 / mysql connections, so queries and credentials are not sent in cleartext and the ser…🟢

Part of the Interlace ESLint Ecosystem — AI-native security plugins with LLM-optimized error messages:

PluginDownloadsDescription
eslint-plugin-secure-codingdownloadsGeneral security rules & OWASP guidelines.
eslint-plugin-pgdownloadsPostgreSQL security & best practices.
eslint-plugin-node-securitydownloadsNode.js core-module security (fs, child_process, vm, crypto, Buffer).
eslint-plugin-jwtdownloadsJWT security & best practices.
eslint-plugin-browser-securitydownloadsBrowser-specific security & XSS prevention.
eslint-plugin-express-securitydownloadsExpress.js security hardening rules.
eslint-plugin-lambda-securitydownloadsAWS Lambda security best practices.
eslint-plugin-nestjs-securitydownloadsNestJS security rules & patterns.
eslint-plugin-mongodb-securitydownloadsMongoDB security best practices.
eslint-plugin-vercel-ai-securitydownloadsVercel AI SDK security hardening.
eslint-plugin-import-nextdownloadsNext-gen import sorting & architecture.

⭐ Support & follow

If this plugin caught a real bug for you, star the repo — stars are the signal that keeps the Interlace ESLint ecosystem maintained — and follow the writeups on Dev.to for the benchmarks and security research behind these rules.

GitHub stars

📄 License

MIT © Ofri Peretz

ESLint Interlace Plugin

Interlace

View README.md on GitHub →

Building secure JavaScript with Interlace? Star the repo to get new rules and CWE coverage as we ship them — or follow the AI-code-security benchmarks behind them.

On this page

No Headings