New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@defen.so/sdk-node

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@defen.so/sdk-node

Defenso Node.js SDK — fail-open WAF, bot detection, and attack-log middleware for Express, Fastify, and Next.js. One line, always on. If Defenso is unreachable, your app keeps serving.

Source
npmnpm
Version
0.1.0
Version published
Weekly downloads
4
-55.56%
Maintainers
1
Weekly downloads
 
Created
Source

@defenso/sdk-node

Defenso security in your Node app. WAF + attack logging in one line.

Fails open. If Defenso is unreachable, your app keeps serving.

Install

npm install @defenso/sdk-node

Then get a token at https://app.defen.so/developer.

Express

import express from 'express';
import { defenso } from '@defenso/sdk-node/express';

const app = express();
app.use(defenso({ token: process.env.DEFENSO_TOKEN! }));

app.get('/', (req, res) => res.send('hi'));
app.listen(3000);

Fastify

import Fastify from 'fastify';
import { defensoFastify } from '@defenso/sdk-node/fastify';

const app = Fastify();
await app.register(defensoFastify, { token: process.env.DEFENSO_TOKEN! });

app.get('/', async () => ({ hello: 'world' }));
app.listen({ port: 3000 });

Next.js

// middleware.ts
import { NextResponse } from 'next/server';
import { defensoNext } from '@defenso/sdk-node/next';

const inspect = defensoNext({ token: process.env.DEFENSO_TOKEN! });

export function middleware(req: Request) {
    const verdict = inspect(req);
    if (verdict.blocked) {
        return new NextResponse(JSON.stringify({ error: verdict.reason }), { status: 403 });
    }
    return NextResponse.next();
}

How it works

  • Policy (WAF rules) is pulled from Defenso every 5 min and cached locally.
  • Requests are inspected in-process against the cached policy. Latency: ~0.1 ms.
  • Attack events are queued and flushed to Defenso every 10 s in the background.
  • If Defenso is down, requests are allowed. Your app never blocks on the network.

Options

defenso({
    token: '...',                // required
    api: 'https://app.defen.so/api', // override for self-hosted
    policyRefreshMs: 5 * 60_000,     // how often to pull rules
    logFlushMs: 10_000,              // background log flush cadence
    logBatchSize: 50,                // immediate flush at this batch size
    policyTimeoutMs: 250,            // fail-open threshold on policy fetch
});

License

MIT

Keywords

defenso

FAQs

Package last updated on 13 Jul 2026

Related posts