npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

eslint-plugin-knex

v0.3.0

Published

[![npm version](https://badge.fury.io/js/eslint-plugin-knex.svg)](https://badge.fury.io/js/eslint-plugin-knex)

Readme

eslint-plugin-knex

npm version

Installation

npm install -D eslint-plugin-knex
pnpm add -D eslint-plugin-knex

Usage

In your eslint config file:

{
  "plugins": ["knex"],
  "rules": {
    "knex/avoid-injections": "error"
  },
  "settings": {
    "knex": {
      "builderName": "^(knex|trx|transaction)$"
    }
  }
}

For ESLint 9 and 10, use eslint.config.js (CommonJS):

const knex = require("eslint-plugin-knex");

module.exports = [
  {
    plugins: { knex },
    rules: { "knex/avoid-injections": "error" },
    settings: { knex: { builderName: "^(knex|trx|transaction)$" } },
  },
];

Or use the flat recommended preset (ESLint 9+):

// eslint.config.js
const knex = require("eslint-plugin-knex");
module.exports = [knex.configs["flat/recommended"]];

The preset enables only knex/avoid-injections with its current defaults; plugins: ["knex"] in eslintrc remains supported.

The eslintrc example above works with ESLint 7 and 8. The rule tests run against ESLint 7, 8, 9 and 10 in CI. ESLint 8 also supports flat config via ESLINT_USE_FLAT_CONFIG=true; ESLint 9+ defaults to flat config.

Settings

builderName is optional. Without it, the rule checks every call using one of the raw-query methods listed below, including non-Knex calls. Set it to a regex string (or a RegExp in a JS config) to filter builder names. Invalid values are ignored, leaving all names checked.

Rules

knex/avoid-injections

Checks the first SQL argument of raw, whereRaw, joinRaw, orWhereRaw, havingRaw, orHavingRaw, groupByRaw, and orderByRaw by default.

0.3.0 changes default findings: the last five methods were not checked in 0.2.x, so upgrading may introduce new lint errors.

knex.raw("select * from users where id = ?", [id]); // OK: binding
knex.raw(`select * from users where id = ${id}`); // reported

Static strings/templates are accepted; interpolation and concatenation are reported. Bindings remain the safer choice. For a query variable, only its initializer is checked:

let query = "select * from users";
query += userInput;
knex.raw(query); // not reported: subsequent writes aren't tracked

Limits: parameters, imports and uninitialized variables are skipped; aliases, control flow and computed methods (knex["raw"]) aren't tracked. A non-Knex .raw() may be reported (false positive), while a dynamic query passed as a parameter may be missed (false negative). This is not complete SQL-injection analysis; use bindings, validation and security review too.