Playground
Pick a flagship rule, edit the code, toggle the plugins, copy a real eslint.config.js. Live linting — edits trigger a real ESLint run in under 300 ms; plugin toggles drive the active rule set.
Pick an example
CWE-327 · Algorithm confusion
Live · linted by the published pluginsjwt/no-algorithm-none
JWT algorithm confusion — accepting tokens with `alg: "none"` lets attackers forge any payload.
Plugins enabled · 1/1
Code · editable
Lints as you type
Findings · 1
Algorithm 'none' allows unsigned JWTs to pass verification (CWE-327). Drop 'none' from the algorithms allow-list.
Read the rule
Inspired by OXC Playground.
About the examples
Each of the 6 examples corresponds to one of our flagship rules. The findings list shows what our rule emits when run against the snippet on the left — captured directly from the rule’s test corpus, not invented for marketing. The “Read the rule” link takes you to the canonical docs page where you can read the detection logic, CWE / OWASP mapping, and configuration options.