Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
@evansolomon/open-graph-scraper
Advanced tools
A simple node module for scraping Open Graph info off a site.
npm install open-graph-scraper
var ogs = require('open-graph-scraper');
var options = {'url':'http://ogp.me/'};
ogs(options, function(err, results) {
console.log("err:",err);
console.log("results:",results);
});
You can also set a timeout flag like...
var ogs = require('open-graph-scraper');
var options = {'url':'http://ogp.me/','timeout':'2000'};
ogs(options, function(err, results) {
console.log("err:",err);
console.log("results:",results);
});
Check the return for a success
flag. If success is set to true, then the url input was valid. Otherwise it will be set to false. The above eample will return something like...
{
data: {
ogTitle: "Open Graph protocol"
ogType: "website"
ogUrl: "http://ogp.me/"
ogImage: {
url: "http://ogp.me/logo.png"
width: 100
height: 100
type: 'image/jpeg'
}
ogDescription: "The Open Graph protocol enables any web page to become a rich object in a social graph."
}
success: true
}
You have to have mocha running. To install it run...
npm install mocha -g
Then you can run the tests by turning on the server and run...
mocha tests/
This will install the all of the dependencies, then run the tests
make test
-Get more info from url(s) like title tags and more images
FAQs
Node.js scraper service for Open Graph info
We found that @evansolomon/open-graph-scraper demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.