New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@defen.so/sdk-node

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@defen.so/sdk-node

Defenso Node.js SDK — fail-open WAF, bot detection, and attack-log middleware for Express, Fastify, and Next.js. One line, always on. If Defenso is unreachable, your app keeps serving.

Source
npmnpm
Version
0.1.1
Version published
Weekly downloads
4
-55.56%
Maintainers
1
Weekly downloads
 
Created
Source

@defen.so/sdk-node

One-line WAF, bot detection, and attack logging for Node, Express, Fastify, Next.js, Bun, and Deno. Part of Defenso — the security layer for indie devs, vibe coders, and shipping teams.

  • Managed WAF with OWASP Top 10 + Core Rule Set + your custom rules
  • Bot detection with UA classification + rate limits
  • Attack logging with full context (IP, ASN, country, payload, route, verdict)
  • Fails open — if Defenso is unreachable, your app keeps serving
  • ~0.1 ms in-process latency (rules cached, evaluation is local)
  • Attack events queued and flushed in the background
  • Free tier forever · Pro $29/mo per site

Install

npm install @defen.so/sdk-node

Get a token at https://app.defen.so/developer.

Frameworks

Express

import express from 'express';
import { defenso } from '@defen.so/sdk-node/express';

const app = express();
app.use(defenso({ token: process.env.DEFENSO_TOKEN! }));

app.get('/', (req, res) => res.send('hi'));
app.listen(3000);

Fastify

import Fastify from 'fastify';
import { defensoFastify } from '@defen.so/sdk-node/fastify';

const app = Fastify();
await app.register(defensoFastify, { token: process.env.DEFENSO_TOKEN! });

app.get('/', async () => ({ hello: 'world' }));
app.listen({ port: 3000 });

Next.js (App or Pages router)

// middleware.ts
import { NextResponse } from 'next/server';
import { defensoNext } from '@defen.so/sdk-node/next';

const inspect = defensoNext({ token: process.env.DEFENSO_TOKEN! });

export function middleware(req: Request) {
    const verdict = inspect(req);
    if (verdict.blocked) {
        return new NextResponse(JSON.stringify({ error: verdict.reason }), { status: 403 });
    }
    return NextResponse.next();
}

Bun

import { defenso } from '@defen.so/sdk-node';
const guard = defenso({ token: Bun.env.DEFENSO_TOKEN });
Bun.serve({ fetch: guard.fetch });

Deno

import { defenso } from 'npm:@defen.so/sdk-node';
const guard = defenso({ token: Deno.env.get('DEFENSO_TOKEN')! });
Deno.serve(guard.handler);

How it works

  • Policy (WAF rules) is pulled from Defenso every 5 min and cached in-memory.
  • Requests are inspected in-process against the cached policy. Latency ~0.1 ms.
  • Attack events are queued and flushed to Defenso every 10 s in the background.
  • If Defenso is down, requests are allowed. Your app never blocks on the network.

Options

defenso({
    token: '...',                        // required
    api: 'https://app.defen.so/api',     // override for self-hosted
    policyRefreshMs: 5 * 60_000,         // how often to pull rules
    logFlushMs: 10_000,                  // background log flush cadence
    logBatchSize: 50,                    // immediate flush at this batch size
    policyTimeoutMs: 250,                // fail-open threshold on policy fetch
});

What Defenso stops

SQL injection, XSS (reflected / stored / DOM), CSRF, SSRF, path traversal, XXE, NoSQL / LDAP / command injection, brute force, credential stuffing, malicious file uploads (polyglots, PHP-in-PNG), bot scrapers, headless browser abuse, TOR exit nodes, exposed secrets, wide-open cloud config. Full list at defen.so/threats.

Companion tools

License

MIT

Keywords

defenso

FAQs

Package last updated on 21 Jul 2026

Related posts