npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@sharkvoid/rasp

v2.2.13

Published

Production-grade Runtime Application Self-Protection for Express, Next.js, Firebase, and Supabase. Defends against SQL injection, XSS, path traversal, command injection, bots, brute force, and AI-powered attackers. Powered by SharkVoid.

Readme

@sharkvoid/rasp

npm license node downloads

Runtime Application Self-Protection for Node.js, powered by SharkVoid. Every request passes through nine detection layers before reaching your route handlers. Attacks are blocked, tarpitted, or flagged in milliseconds. Your dashboard updates in real time.


Install

npm install @sharkvoid/rasp

Requires Node 18+.


Quick Start

const express = require('express');
const { sharkvoidRasp } = require('@sharkvoid/rasp');

const app = express();
app.use(express.json());

app.use(sharkvoidRasp({
  agentId: 'rasp_xxxxxxxx_xxxxxx',
  secret:  'your-webhook-secret',
}));

app.get('/', (req, res) => res.send('Hello world'));
app.listen(3000);

Get your agentId and secret by creating an agent at sharkvoid.com.


What It Detects

SQL injection, XSS, path traversal, LFI, command injection, SSTI, XXE, prototype pollution, brute force, bots and scanners, AI agents, credential harvesting, and encoding bypass attacks. Requests are decoded through URL encoding, base64, HTML entities, hex escapes, Unicode normalization, and null bytes before scanning, so encoding tricks do not evade detection.


How Risk Scoring Works

Every request gets a score from 0 to 100 combining IP reputation, pattern matches, behavioral signals, header analysis, and async LLM review. The score maps to an action automatically.

| Score | Action | |---|---| | 0-29 | Allow | | 30-49 | Watch and log | | 50-69 | Challenge (CAPTCHA) | | 70-84 | Tarpit with convincing fake data | | 85-94 | Block, 24-hour IP ban | | 95-100 | Block, permanent ban |

Tarpitted requests receive realistic fake responses: fake JWT tokens, fake .env files, fake passwd files, fake user lists. The attacker thinks they succeeded.


Modes

Switch modes from your dashboard with no redeploy. Changes take effect within 60 seconds.

Block — enforces everything. Recommended for production.
Challenge — shows CAPTCHA to suspicious requests. Humans pass, bots fail.
Monitor — logs everything, blocks nothing. Start here to baseline your traffic.
Paused — all analysis skipped, every request passes through immediately.


Platform Adapters

| Platform | Import | |---|---| | Express / Node.js | @sharkvoid/rasp | | Next.js (Edge Middleware) | @sharkvoid/rasp/nextjs | | Firebase Functions | @sharkvoid/rasp/firebase | | AWS Lambda | @sharkvoid/rasp/lambda | | Azure Functions | @sharkvoid/rasp/azure | | Supabase Edge Functions | @sharkvoid/rasp/supabase |

Tarpit and CAPTCHA are not available on serverless platforms due to timeout and billing constraints. Behavioral analysis resets on cold starts in Deno-based environments (Supabase). All other detection layers work fully across every platform.


Optional: Geo-IP

npm install geoip-lite

Adds country detection to your event logs. Without it, country shows as null.


Links