eslint-plugin-sequelize-security
v0.3.3
Published
ESLint plugin for the Sequelize ORM — detects SQL injection in raw sequelize.query() and Sequelize.literal() calls built with string concatenation or template literals, connection configuration that disables TLS or certificate validation, and hardcoded da
Maintainers
Readme
⭐ If this plugin caught a real bug for you, star the repo — it's the signal that keeps these rules maintained.
Description
This plugin provides Security rules for the Sequelize ORM (SQL injection prevention in raw queries).
Why Sequelize-specific?
An ORM is not a defence against SQL injection — it narrows the surface to the raw escapes, and those are still string-built. Sequelize has two: sequelize.query() and Sequelize.literal(). OWASP Juice Shop's two flagship injections are both the former, and neither was reported by any recommended preset in this ecosystem until this plugin existed — the only implementation of the detection shipped inside eslint-plugin-pg, which no Sequelize user installs.
Being Sequelize-specific is what makes the rule precise. It knows the safe conventions to stay quiet on (replacements, bind), and it knows literal() is a SQL sink rather than an ordinary helper — so it catches ORDER BY injection that a generic string-concatenation linter has no reason to flag. It also tracks variable taint across statements, so const sql = "SELECT..." + id; sequelize.query(sql) reports even with the concatenation on a separate line.
Philosophy
Interlace fosters strength through integration. Instead of stacking isolated rules, we interlace security directly into your workflow to create a resilient fabric of code. We believe tools should guide rather than gatekeep, providing educational feedback that strengthens the developer with every interaction.
Getting Started
- To check out the guide, visit eslint.interlace.tools. 📚
- 要查看中文 指南, 请访问 eslint.interlace.tools. 📚
- 가이드 문서는 eslint.interlace.tools에서 확인하실 수 있습니다. 📚
- ガイドは eslint.interlace.toolsでご確認ください。 📚
- Para ver la guía, visita eslint.interlace.tools. 📚
- للاطلاع على الدليل، قم بزيارة eslint.interlace.tools. 📚
npm install eslint-plugin-sequelize-security --save-dev⚙️ Configuration Presets
| Preset | Description |
| :------------ | :------------------------------------------------------- |
| recommended | Recommended preset - balanced security for most projects |
| strict | Strict preset - all rules as errors |
| flagship | Highest-signal rules only, for CI gates |
📚 Supported Libraries
| Library | npm | Downloads | Detection |
| ----------- | ---------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | ------------- |
| sequelize | |
| SQL Injection |
Sequelize runs on Postgres, MySQL, MariaDB, SQLite, MSSQL and Snowflake — this plugin fires on the raw-SQL escapes regardless of which dialect is configured.
Custom Configuration
import sequelize from 'eslint-plugin-sequelize-security';
export default [
{
plugins: { 'sequelize-security': sequelizeSecurity },
rules: {
'sequelize-security/no-unsafe-query': 'error',
},
},
];💡 What You Get
- Covers the escapes your ORM leaves open:
sequelize.query()andSequelize.literal(), the two places raw SQL still gets built by hand - Sequelize's own remediation: every finding names
replacements/bind, not a generic "use parameterized queries" - Cross-statement taint tracking: catches queries assembled over several lines, including with
+= - Quiet on safe code: parameterized queries, static SQL and builder calls do not report
- LLM-optimized messages: structured 2-line errors with CWE + fixes that AI assistants can apply
Every rule produces a structured error message:
routes/search.ts
23:24 error 🔒 CWE-89 OWASP:A03-Injection CVSS:9.8 | Unsafe SQL query construction detected (template literal) | CRITICAL
Fix: Pass values via `replacements` or `bind` instead of interpolating them into the SQL string.📦 Compatibility
| Package | Version |
| :--- | :--- |
| ESLint | ^8.40.0 \|\| ^9.0.0 \|\| ^10.0.0 |
| Node.js | >=18.0.0 |
See the ESLint Version Support Policy — current ecosystem share data, the 20% gate, and the forward-looking exception that covers v10.
Rules
Legend
| Icon | Description |
| :---: | :--- |
| 💼 | Recommended: Included in the recommended preset. |
| ⚠️ | Warns: Set to warn in recommended preset. |
| 🔧 | Auto-fixable: Automatically fixable by the --fix CLI option. |
| 💡 | Suggestions: Providing code suggestions in IDE. |
| 🚫 | Deprecated: This rule is deprecated. |
| 🟢 | Type-unaware: AST-only, runs in oxlint JS-plugin tier. |
| 🟡 | Type-aware (refining): pure-AST primary path; types refine precision. |
| 🟠 | Type-aware (graceful): requires TS program; silent without it. |
| Rule | CWE | OWASP | CVSS | Description | 🧠 | 💼 | ⚠️ | 🔧 | 💡 | 🚫 | | :--- | :---: | :---: | :---: | :--- | :---: | :---: | :---: | :---: | :---: | :---: | | no-hardcoded-credentials | CWE-798 | A07:2021 | | Disallow literal database passwords in Sequelize connection configuration, including credentials embedded i… | 🟢 | | | | | | | no-mass-assignment | CWE-915 | A04:2021 | | Disallow writing an inbound request object straight to the database through Sequelize, which lets the calle… | 🟢 | | | | | | | no-unsafe-query | CWE-89 | A03:2021 | | Detects SQL injection in raw Sequelize queries built with string concatenation or template literals | 🟢 | 💼 | | | | | | require-tls | CWE-319 | A02:2021 | | Require TLS on Sequelize connections, so queries and credentials are not sent in cleartext and the server i… | 🟢 | | | | | |
🔗 Related ESLint Plugins
Part of the Interlace ESLint Ecosystem — AI-native security plugins with LLM-optimized error messages:
| Plugin | Downloads | Description |
| :--- | :---: | :--- |
| eslint-plugin-secure-coding | | General security rules & OWASP guidelines. |
|
eslint-plugin-pg | | PostgreSQL security & best practices. |
|
eslint-plugin-node-security | | Node.js core-module security (fs, child_process, vm, crypto, Buffer). |
|
eslint-plugin-jwt | | JWT security & best practices. |
|
eslint-plugin-browser-security | | Browser-specific security & XSS prevention. |
|
eslint-plugin-express-security | | Express.js security hardening rules. |
|
eslint-plugin-lambda-security | | AWS Lambda security best practices. |
|
eslint-plugin-nestjs-security | | NestJS security rules & patterns. |
|
eslint-plugin-mongodb-security | | MongoDB security best practices. |
|
eslint-plugin-vercel-ai-security | | Vercel AI SDK security hardening. |
|
eslint-plugin-import-next | | Next-gen import sorting & architecture. |
⭐ Support & follow
If this plugin caught a real bug for you, star the repo — stars are the signal that keeps the Interlace ESLint ecosystem maintained — and follow the writeups on Dev.to for the benchmarks and security research behind these rules.
📄 License
MIT © Ofri Peretz
