npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

chimeraguard

v1.5.0

Published

ChimeraGuard - Multi-Vector DevSecOps Platform & Defense Arsenal (formerly ObsidianSec)

Readme

🛡️ ChimeraGuard // Multi-Vector DevSecOps Platform & Defense Arsenal

npm version License: MIT Tests: 181 Passed Security Tools: 16 Engines Quality Gate

The All-In-One DevSecOps, Edge Defense, SAST & Reconnaissance CLI.
Consolidating 16 specialized security engines into a single, zero-dependency npm install.

⚡ Evolution Notice: Formerly known as ObsidianSec. All existing commands (npx obsidiansec ...) continue to work seamlessly for backward compatibility!


⚡ Quick Start (No Install Needed)

Run any of the 14 tactical commands instantly using npx:

# 🔍 1. Complete Edge Audit (Headers, Cookies, CORS & MITRE Attack Chain)
npx chimeraguard audit https://your-website.com

# 🎯 2. Cloudflare & Origin Bypass Finder (Detects Real IP leaks via SPF, MX & Subdomains)
npx chimeraguard origin https://your-website.com

# 🔒 3. SSL/TLS Certificate & Protocol Security (SSL Labs Engine)
npx chimeraguard ssl https://your-website.com

# 🧬 4. Technology Stack Fingerprinting (Wappalyzer Engine: React, Next.js, Nginx, CDNs)
npx chimeraguard tech https://your-website.com

# 📡 5. HTTP Method Enumeration (Detects dangerous TRACE/XST, PUT, DELETE)
npx chimeraguard methods https://your-website.com

# 🔀 6. Open Redirect Detector (OWASP CWE-601 Parameter Fuzzing)
npx chimeraguard redirects https://your-website.com

# 🛡️ 7. Web Application Firewall Detector (22+ WAFs: Cloudflare, AWS WAF, Fastly, Fortinet)
npx chimeraguard waf https://your-website.com

# 🚪 8. TCP Port Scanner (37 Critical Ports: Redis, Mongo, MSSQL, Oracle, K8s, SMB, VNC)
npx chimeraguard ports your-server-ip-or-domain

# 🔐 9. Secret Hunter & SAST Local (45+ Patterns: AWS, Stripe, Supabase, Slack, Discord, PGP)
npx chimeraguard scan-dir ./

# 🎟️ 10. JWT Token Security Auditor (Detects alg: none, expiration & decodes claims)
npx chimeraguard jwt <your-jwt-token>

# 🌐 11. Passive Subdomain Reconnaissance (Certificate Transparency Logs)
npx chimeraguard subdomains your-domain.com

# 📧 12. DNS & Email Anti-Phishing Suite (SPF, DMARC, DNSSEC)
npx chimeraguard dns your-domain.com

# 🔑 13. Shannon Password Entropy & GPU Cluster Crack Time (Hashcat Model)
npx chimeraguard entropy "YourPasswordHere"

# ⚙️ 14. Generate Scope & AI Budget Config Template
npx chimeraguard init-config

📋 Command Arsenal Matrix

| Command | Category | Engine / Reference | Key Capabilities | |---|---|---|---| | audit <url> | Edge Security | Mozilla Observatory / Burp | CSP, HSTS, X-Frame-Options, Cookie flags, CORS, MITRE ATT&CK Graph | | origin <url> | Perimeter Defense | Shodan / DoH Recon | Uncovers real origin IP leaks bypassing Cloudflare/WAF; generates UFW patches | | ssl <url> | Cryptography | SSL Labs | TLS 1.3/1.2 validation, SAN inspection, weak cipher/hash detection, expiry days | | tech <url> | Reconnaissance | Wappalyzer / BuiltWith | Identifies React, Next.js, Vue, Angular, WordPress, Django, Nginx, Cloudflare | | methods <url> | Protocol Audit | OWASP Testing Guide | Enumerates verbs; detects TRACE (XST vector), unauthenticated PUT/DELETE | | redirects <url> | Web Vulnerability | OWASP CWE-601 | Probes 20+ redirect parameters against malicious external destinations | | waf <url> | Edge Defense | WAFW00F Engine | Identifies 22+ WAF vendors (Cloudflare, AWS, Fastly, Fortinet, Imperva, Akamai) | | ports <host> | Network SAST | Nmap / Shodan Model | Scans 37 critical ports (Databases, Remote Access, K8s, Legacy protocols) | | scan-dir [path] | Code SAST | TruffleHog / Gitleaks Model | 45+ regex patterns for API keys, private keys, database strings, .env files | | jwt <token> | Auth Audit | jwt_tool Model | Validates signature presence, alg: none bypass, expiration & claim decoding | | subdomains <dom> | OSINT Recon | Subfinder / crt.sh | Passive subdomain enumeration via public Certificate Transparency logs | | dns <dom> | Anti-Phishing | RFC 7208 / 7489 | Audits SPF hardfail mechanisms, DMARC reject policies, and DNSSEC | | entropy <pass> | Cryptanalysis | Shannon Entropy / Hashcat | Bits of entropy, character set diversity & GPU brute-force crack time | | init-config | Configuration | ChimeraGuard Core | Generates chimeraguard.config.json with authorized scope and AI budget limits |


🏛️ Architecture & Core Defenses

1. 🛡️ Authorized Scope Guard

Prevents accidental audits against forbidden domains (e.g. government, military, unowned infrastructure) with allowlist/blocklist glob patterns:

{
  "scope": {
    "strictMode": false,
    "allowlist": ["localhost", "127.0.0.1", "*.yourcompany.com"],
    "blocklist": ["*.gov.br", "*.mil.br", "*.jus.br"]
  }
}

2. 🧠 Token Budget Guard & Zero-Token Default

  • 100% Free & Local by Default: Operates without requiring external AI APIs or cloud tokens.
  • SHA-256 Deduplication Cache: Caches audit findings locally for 72 hours (0 tokens, 0 network cost on repeated runs).
  • Circuit Breaker: Enforces a strict maximum requests-per-hour limit when LLM features are enabled.

3. 🕸️ BloodHound MITRE ATT&CK Mapping

Translates missing headers into an actionable exploitation graph, demonstrating how an attacker chains missing CSP or CORS into session hijacking (T1539) and account takeover (T1078).


🤖 CI/CD Quality Gate Example (GitHub Actions)

Fail pull requests automatically if security standards or perimeter requirements are violated:

name: ChimeraGuard CI/CD Quality Gate

on: [push, pull_request]

jobs:
  security-gate:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout Code
        uses: actions/checkout@v4

      - name: Secret Hunter (SAST)
        run: npx chimeraguard scan-dir ./

      - name: Edge Security Audit (Quality Gate Grade >= A)
        run: npx chimeraguard audit https://staging.yourdomain.com --min-grade=A

🧪 Automated Testing

ChimeraGuard is thoroughly tested with 39 Vitest suites and 181 automated tests (100% GREEN):

# Run complete test suite
npm test

# Build production bundle
npm run build

📜 License & Compliance

MIT License © 2026 Matheus Oliveira & ChimeraGuard Contributors.
Designed in compliance with OWASP Top 10, NIST SP 800-207 (Zero Trust), and CWE Standards.