Skip to main content
interlace
Plugin: sequelize

Overview

Sequelize ORM security — SQL injection in raw queries

Live from GitHub

This content is fetched directly from README.md on GitHub and cached for 1 hour.

AI-Optimized Security

Every rule includes CWE, OWASP, and CVSS metadata for AI assistants to provide precise, context-aware fixes.


Live README from GitHubfrom eslint-plugin-sequelize-security/README.md, cached for 1 hour.Edit on GitHub
Interlace

  

Sequelize

  

oxlint

  

ESLint

Security rules for the Sequelize ORM (SQL injection prevention in raw queries).

NPM VersionNPM DownloadsPackage LicenseCodecovSince Dec 2025

⭐ If this plugin caught a real bug for you, star the repo — it's the signal that keeps these rules maintained.

Description

This plugin provides Security rules for the Sequelize ORM (SQL injection prevention in raw queries).

Why Sequelize-specific?

An ORM is not a defence against SQL injection — it narrows the surface to the raw escapes, and those are still string-built. Sequelize has two: sequelize.query() and Sequelize.literal(). OWASP Juice Shop's two flagship injections are both the former, and neither was reported by any recommended preset in this ecosystem until this plugin existed — the only implementation of the detection shipped inside eslint-plugin-pg, which no Sequelize user installs.

Being Sequelize-specific is what makes the rule precise. It knows the safe conventions to stay quiet on (replacements, bind), and it knows literal() is a SQL sink rather than an ordinary helper — so it catches ORDER BY injection that a generic string-concatenation linter has no reason to flag. It also tracks variable taint across statements, so const sql = "SELECT..." + id; sequelize.query(sql) reports even with the concatenation on a separate line.

Philosophy

Interlace fosters strength through integration. Instead of stacking isolated rules, we interlace security directly into your workflow to create a resilient fabric of code. We believe tools should guide rather than gatekeep, providing educational feedback that strengthens the developer with every interaction.

Getting Started

npm install eslint-plugin-sequelize-security --save-dev

⚙️ Configuration Presets

PresetDescription
recommendedRecommended preset - balanced security for most projects
strictStrict preset - all rules as errors
flagshipHighest-signal rules only, for CI gates

📚 Supported Libraries

LibrarynpmDownloadsDetection
sequelizenpmdownloadsSQL Injection

Sequelize runs on Postgres, MySQL, MariaDB, SQLite, MSSQL and Snowflake — this plugin fires on the raw-SQL escapes regardless of which dialect is configured.

Custom Configuration

import sequelize from 'eslint-plugin-sequelize-security';

export default [
  {
    plugins: { 'sequelize-security': sequelizeSecurity },
    rules: {
      'sequelize-security/no-unsafe-query': 'error',
    },
  },
];

💡 What You Get

  • Covers the escapes your ORM leaves open: sequelize.query() and Sequelize.literal(), the two places raw SQL still gets built by hand
  • Sequelize's own remediation: every finding names replacements / bind, not a generic "use parameterized queries"
  • Cross-statement taint tracking: catches queries assembled over several lines, including with +=
  • Quiet on safe code: parameterized queries, static SQL and builder calls do not report
  • LLM-optimized messages: structured 2-line errors with CWE + fixes that AI assistants can apply

Every rule produces a structured error message:

routes/search.ts
  23:24  error  🔒 CWE-89 OWASP:A03-Injection CVSS:9.8 | Unsafe SQL query construction detected (template literal) | CRITICAL
                    Fix: Pass values via `replacements` or `bind` instead of interpolating them into the SQL string.

📦 Compatibility

PackageVersion
ESLint^8.0.0 || ^9.0.0 || ^10.0.0
Node.js>=18.0.0

See the ESLint Version Support Policy — current ecosystem share data, the 20% gate, and the forward-looking exception that covers v10.

Rules

Legend

IconDescription
💼Recommended: Included in the recommended preset.
⚠️Warns: Set to warn in recommended preset.
🔧Auto-fixable: Automatically fixable by the --fix CLI option.
💡Suggestions: Providing code suggestions in IDE.
🚫Deprecated: This rule is deprecated.
🟢Type-unaware: AST-only, runs in oxlint JS-plugin tier.
🟡Type-aware (refining): pure-AST primary path; types refine precision.
🟠Type-aware (graceful): requires TS program; silent without it.
RuleCWEOWASPCVSSDescription🧠💼⚠️🔧💡🚫
no-unsafe-queryCWE-89A03:2021Detects SQL injection in raw Sequelize queries built with string concatenation or template literals🟢💼
require-tlsCWE-319A02:2021Require TLS on Sequelize connections, so queries and credentials are not sent in cleartext and the server i…🟢

Part of the Interlace ESLint Ecosystem — AI-native security plugins with LLM-optimized error messages:

PluginDownloadsDescription
eslint-plugin-secure-codingdownloadsGeneral security rules & OWASP guidelines.
eslint-plugin-pgdownloadsPostgreSQL security & best practices.
eslint-plugin-node-securitydownloadsNode.js core-module security (fs, child_process, vm, crypto, Buffer).
eslint-plugin-jwtdownloadsJWT security & best practices.
eslint-plugin-browser-securitydownloadsBrowser-specific security & XSS prevention.
eslint-plugin-express-securitydownloadsExpress.js security hardening rules.
eslint-plugin-lambda-securitydownloadsAWS Lambda security best practices.
eslint-plugin-nestjs-securitydownloadsNestJS security rules & patterns.
eslint-plugin-mongodb-securitydownloadsMongoDB security best practices.
eslint-plugin-vercel-ai-securitydownloadsVercel AI SDK security hardening.
eslint-plugin-import-nextdownloadsNext-gen import sorting & architecture.

⭐ Support & follow

If this plugin caught a real bug for you, star the repo — stars are the signal that keeps the Interlace ESLint ecosystem maintained — and follow the writeups on Dev.to for the benchmarks and security research behind these rules.

GitHub stars

📄 License

MIT © Ofri Peretz

ESLint Interlace Plugin

Interlace

View README.md on GitHub →

Building secure JavaScript with Interlace? Star the repo to get new rules and CWE coverage as we ship them — or follow the AI-code-security benchmarks behind them.

On this page

No Headings