npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@oreefy/hash

v1.0.0

Published

Zero-dependency, secure password hashing for JavaScript/TypeScript using Web Crypto API (PBKDF2-SHA512) with constant-time comparison, Base64Url encoding, and 100k iterations.

Downloads

95

Readme

@oreefy/hash

Zero-dependency, secure plaintext hashing for JavaScript/TypeScript using Web Crypto API (PBKDF2-SHA512) with constant-time comparison, Base64Url encoding, and 100k iterations.

@oreefy/hash is a library built for the Oreefy ecosystem. The package is officially developed, maintained, and fully controlled by Oreefy, ensuring long-term stability, consistency, and compatibility across the ecosystem.

Required Capabilities

  • JavaScript / TypeScript
  • Web Crypto API (crypto)

API Reference

| Constant | Value | | ------------------- | ------------- | | VERSION | v1 | | ALGORITHM | PBKDF2-SHA512 | | ITERATIONS | 100_000 | | SALT_LENGTH | 16 | | KEY_LENGTH | 64 | | MAX_PLAINTEXT_BYTES | 1024 |

import { hash } from "@oreefy/hash";

await hash.make();
await hash.compare();

hash.make()

Creates a secure, salted hash from plaintext.

Before hashing, the input is normalized using NFC, checked against the maximum byte length, and combined with a cryptographically secure 16-byte salt. The final key is derived using PBKDF2-SHA512 with 100,000 iterations.

Example

import { hash } from "@oreefy/hash";

const hashed = await hash.make("my-super-secret-plaintext");
console.log(hashed);

Parameters

  • plaintext: string — The plaintext to hash. It must be non-empty and no larger than 1024 bytes after UTF-8 encoding.

Returns

Promise<string> — A formatted hash string:

<VERSION>$<ALGORITHM>$<i=ITERATIONS>$<BASE64_SALT>$<BASE64_HASH>

Errors

Throws an error when the input is invalid or cannot be processed.

hash.compare()

Verifies plaintext against a previously generated hash.

The comparison is performed in constant time to help mitigate timing attacks.

hash.compare() is designed to be safe to use with untrusted input: it never throws. Invalid input, malformed hashes, and non-matching plaintext simply return false.

Example

import { hash } from "@oreefy/hash";

const isMatch = await hash.compare("plaintext", "hashed-string");
console.log(isMatch);

Parameters

  • plaintext: string — The plaintext to verify.
  • hash: string — A hash generated by hash.make().

Returns

Promise<boolean> — Returns true when the plaintext matches the hash; otherwise false.

Technical Highlights

  • Zero Dependencies — Uses only the native Web Crypto API.
  • Cross-Runtime — Works anywhere Web Crypto is available, including Node.js, Bun, Deno, Cloudflare Workers, browsers, and edge runtimes.
  • Secure by Default — PBKDF2-SHA512 with 100,000 iterations, a 16-byte salt, and a 64-byte derived key.
  • Timing-Safe Comparison — Uses constant-time comparison to reduce timing-attack risk.
  • Strict Parsing — Validates the version, algorithm, iteration count, salt, hash length, and Base64Url encoding.

Hash Format

The generated hash follows a modular, future-proof format:

v1$PBKDF2-SHA512$i=100000$<Base64Url-Salt>$<Base64Url-Hash>

| Part | Description | | --------------- | -------------------------------------------------------- | | v1 | Hash format version | | PBKDF2-SHA512 | Key derivation algorithm | | i=100000 | PBKDF2 iteration count | | Salt | 16-byte cryptographically secure salt, Base64Url encoded | | Hash | 64-byte derived key, Base64Url encoded |

Security

@oreefy/hash applies several safeguards by default:

  1. Unicode normalization — Plaintext is normalized using NFC for consistent hashing across platforms.
  2. Input size limit — Plaintext larger than 1024 bytes is rejected to help reduce denial-of-service risk.
  3. Strict Base64Url validation — Encoded values are validated before decoding to reject malformed hash data.
  4. Constant-time comparison — Hash verification avoids regular string comparison for the derived key.

About Oreefy

Oreefy is an affordable business ecosystem designed for small to enterprise businesses. Oreefy provides essential software you need for your modern business within a single ecosystem. It will save you significant time, effort, and money.

License

MIT © Oreefy