JavaScript and TypeScript
Vulkro does full source analysis for JavaScript and TypeScript. It covers the Node.js server frameworks and the client-side XSS / DOM-sink surface.
Both languages are in the Free tier, with no upgrade needed for the deep analysis. You still need an account and sign-in to scan. See Accounts.
Project detection
Vulkro spots the project from package.json and reads installed versions from
package-lock.json. TypeScript is analysed directly. There is no build step or
type-check to run first.
vulkro scan .
vulkro discover . # endpoint map only
Frameworks
Vulkro extracts endpoints from:
- Express
- Fastify
- NestJS
- Next.js (App Router and Pages Router)
- Koa
- Hono
- Hapi
- Elysia
- AdonisJS
- tRPC
It also covers:
- GraphQL (Apollo, graphql-yoga)
- gRPC
- WebSocket (
ws, Socket.IO) - React and Angular client surfaces (for XSS and DOM-sink analysis)
Router composition is followed so the recorded path matches what the server
serves (for example Express Router mounts and Next.js route segments).
Access model
Every endpoint is tagged with an AuthTier (Anonymous / User / Admin / Service
/ Machine / Unknown), its scopes, and its tenant-scoping. The BOLA / IDOR and
broken-authentication rules read this metadata, so a finding already handled by
a visible auth gate is suppressed. Java, Python, and Go share the same endpoint
model, and all of them feed the OWASP API Top 10 checks.
Taint analysis
Vulkro follows request data through function calls to dangerous sinks.
Sources include req.body, req.query, req.params, req.headers, the
equivalents in Next.js route handlers, and route-handler parameters.
Sinks include:
- SQL query builders (
knex.raw,sequelize.query,db.query,pool.query) child_process.execeval/Function(...)fetch(...)(SSRF)redirect(...)(open redirect)- template-as-string XSS
__proto__writes (prototype pollution)
Each finding shows the source-to-sink hop chain (SARIF codeFlows).
Loop-carried taint is off by default. Turn on the worklist engine with
VULKRO_TAINT_CFG=1 (JS/TS and Python only). See
Taint analysis for the full source / sink /
sanitiser model and its limits.
Dependencies
Vulkro reads npm dependencies from package.json (resolved via
package-lock.json) and matches them against the local CVE bundle.
For a curated set of high-traffic packages, CVE findings are tagged
[reachable] or [unreachable] based on whether the vulnerable code is
actually called. See
Dependencies and CVEs and
Reachability.
Related detectors
The AI-generated-code checks (slopsquatted package names, RAG-index safety, CI/CD pipeline injection) apply to JS/TS. See New detectors.
Useful commands
vulkro scan .
vulkro discover . --format json
vulkro dataflow .
vulkro explain JS-TAINT-SQL-001