npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

moonito

v2.3.0

Published

Moonito is the official Node.js SDK for real-time website analytics and advanced bot protection. Instantly detect and block AI crawlers, scrapers, and malicious bots — while tracking genuine visitors in real-time. Perfect for Express, TypeScript, and mode

Readme

Moonito

Real-time analytics and AI bot protection SDK for Node.js and TypeScript.

NPM version npm bundle size

Moonito is a powerful Node.js and TypeScript module for website security, traffic filtering, and real-time analytics.
It helps developers block AI bots, web scrapers, malicious traffic, competitors, and unwanted visitors while gaining accurate insights into genuine visitors.
Perfect for modern web apps, SaaS platforms, and backend applications that need intelligent protection and analytics in one solution.

Features

  • Traffic Filtering: Block harmful traffic based on IP addresses, user agents, and visitor behavior
  • Bot Protection: Shield your website from malicious bots and automated scrapers
  • Visitor Analytics: Track and analyze your website traffic in real-time
  • Flexible Configuration: Choose how to handle unwanted visitors (redirect, iframe, or custom content)
  • Easy Integration: Works seamlessly with Express and other Node.js frameworks

Install the Package

Install Moonito via npm:

npm install moonito

Initialize the Client

Sign up for Moonito, create a project, and copy your API keys from your account dashboard. Then, create a new instance of VisitorTrafficFiltering.

import { VisitorTrafficFiltering } from 'moonito';

const filter = new VisitorTrafficFiltering({
    apiPublicKey: 'YOUR_API_PUBLIC_KEY',
    apiSecretKey: 'YOUR_API_SECRET_KEY',
    isProtected: true,
    unwantedVisitorTo: 'https://example.com/blocked', // URL or HTTP status code
    unwantedVisitorAction: 1 // 1 = Redirect, 2 = Iframe, 3 = Load content
});

Usage

Method 1: Using Express Middleware (Recommended)

If you can, use middleware to track and filter incoming requests to all pages from a single place. Here's an example with Express:

import express from 'express';
import { VisitorTrafficFiltering } from 'moonito';

const app = express();
const port = 3000;

// Configure Moonito
const filter = new VisitorTrafficFiltering({
    apiPublicKey: 'YOUR_API_PUBLIC_KEY',
    apiSecretKey: 'YOUR_API_SECRET_KEY',
    isProtected: true,
    unwantedVisitorTo: 'https://example.com/blocked', // Redirect to this URL
    unwantedVisitorAction: 1
});

// Alternative configuration with HTTP status code
// const filter = new VisitorTrafficFiltering({
//     apiPublicKey: 'YOUR_API_PUBLIC_KEY',
//     apiSecretKey: 'YOUR_API_SECRET_KEY',
//     isProtected: true,
//     unwantedVisitorTo: '403', // Return HTTP 403 Forbidden
//     unwantedVisitorAction: 1
// });

// Apply Moonito middleware
app.use(async (req, res, next) => {
    // Never throws: if the check cannot run, the visitor is let through.
    await filter.evaluateVisitor(req, res);

    // A blocked visitor has already been answered.
    if (!res.headersSent) {
        next();
    }
});

// Your routes
app.get('/', (req, res) => {
    res.send('Hello World!');
});

// Start server
app.listen(port, () => {
    console.log(`Server running at http://localhost:${port}`);
});

Method 2: Manual Evaluation

For more control or custom implementations, you can manually evaluate visitors by providing IP, user agent, event, and domain information:

import { VisitorTrafficFiltering } from 'moonito';

// Configure Moonito
const filter = new VisitorTrafficFiltering({
    apiPublicKey: 'YOUR_API_PUBLIC_KEY',
    apiSecretKey: 'YOUR_API_SECRET_KEY',
    isProtected: true,
    unwantedVisitorTo: '403', // Return HTTP 403 Forbidden
    unwantedVisitorAction: 1
});

// Visitor data
const userIP = '1.1.1.1';
const userAgent = 'Mozilla/5.0...';
const event = 'page-view';
const domain = 'example.com';

// Evaluate visitor
filter.evaluateVisitorManually(userIP, userAgent, event, domain)
    .then(result => {
        if (result.need_to_block) {
            console.log('Visitor blocked. Detect activity:', result.detect_activity);
            console.log('Block content type:', typeof result.content);

            // Handle blocked visitor based on the returned content
            if (typeof result.content === 'number') {
                // HTTP status code - return status directly
                console.log('HTTP Status Code:', result.content);
                // In your application, you might do: res.status(result.content).send()
            } else {
                // HTML content - use as response body
                console.log('HTML Content:', result.content);
                // In your application, you might do: res.send(result.content)
            }

            return;
        }
        console.log('Visitor allowed. Detect activity:', result.detect_activity);
    })
    .catch(error => {
        console.error('Error evaluating visitor:', error);
    });

Configuration Options

| Option | Type | Description | |--------|------|-------------| | apiPublicKey | string | Your Moonito API public key (required) | | apiSecretKey | string | Your Moonito API secret key (required) | | isProtected | boolean | Enable (true) or disable (false) protection | | unwantedVisitorTo | string | URL to redirect unwanted visitors or HTTP error code | | unwantedVisitorAction | number | Action for unwanted visitors: 1 = Redirect, 2 = Iframe, 3 = Load content |

Requirements

  • Node.js 14 or later
  • TypeScript >= 4.7 (if using TypeScript)

Documentation

For detailed documentation, guides, and API reference, visit:

Contributing

We welcome contributions! For significant changes, please open an issue first to discuss what you would like to change. Make sure to update tests as appropriate.

License

This project is licensed under the MIT License.

Support

Need help? Have questions or suggestions?