npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

eslint-plugin-rn-security

v0.1.0

Published

ESLint rules for React Native security defects that generic JavaScript security plugins do not catch

Readme

eslint-plugin-rn-security

ESLint rules for React Native security defects that generic JavaScript security plugins do not catch.

CI npm downloads license

Why this exists

There are good general purpose security linters for JavaScript. eslint-plugin-security covers dangerous sinks like eval and unsafe regular expressions. eslint-plugin-no-secrets finds hardcoded credentials. Use both.

Neither knows anything about React Native. They will not tell you that a WebView with originWhitelist={['*']} will load any origin including file://, that a token in AsyncStorage sits unencrypted on disk, or that a deep link handler is passing an attacker supplied URL straight into navigation.

This plugin covers only that gap. Six rules, all React Native specific, all statically detectable.

Install

npm install --save-dev eslint-plugin-rn-security

Requires ESLint 8.40 or later and Node 18 or later.

Usage

Flat config (ESLint 9)

// eslint.config.js
import rnSecurity from 'eslint-plugin-rn-security'

export default [
  rnSecurity.configs.recommended,
]

Or wire the rules yourself:

import rnSecurity from 'eslint-plugin-rn-security'

export default [
  {
    plugins: { 'rn-security': rnSecurity },
    rules: {
      'rn-security/no-unsafe-webview': 'error',
      'rn-security/no-insecure-storage': 'error',
    },
  },
]

Legacy config (.eslintrc)

{
  "plugins": ["rn-security"],
  "extends": ["plugin:rn-security/legacy-recommended"]
}

Rules

| Rule | What it catches | | --- | --- | | no-unsafe-webview | WebView configured to allow any origin, filesystem access, or mixed content | | no-insecure-storage | Credentials written to AsyncStorage or web storage rather than Keychain or Keystore | | no-cleartext-http | http:// endpoints in network calls | | no-dynamic-link-open | Linking.openURL with an unvalidated value, or a dangerous scheme | | no-unvalidated-deep-link | Deep link URLs reaching navigation or fetch without a check | | no-sensitive-console | Credentials written to the device log |

What this plugin does not do

It does not find secrets in native or config files. ESLint only sees the files it lints, which is JavaScript and TypeScript. React Native secrets often live in .env, app.json, google-services.json, Info.plist and gradle.properties, and no ESLint plugin can reach those. Use a dedicated scanner such as gitleaks or trufflehog for that.

It is not a substitute for a real assessment. These are lint rules. They catch a specific set of mistakes cheaply and early. They do not analyse data flow across modules, they do not inspect your native code, and a clean run does not mean an app is secure.

It will not catch everything, and it will occasionally be wrong. Rules that reason about names, such as no-insecure-storage and no-sensitive-console, use heuristics. Both accept an additionalPatterns option so you can extend them, and both are ordinary ESLint rules you can disable per line where they are wrong.

Contributing

Issues and pull requests are welcome, particularly reports of false positives with a reproduction. Run the tests with:

npm test

Each rule lives in lib/rules/ with its cases in tests/rules.test.js.

License

MIT