
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
plpgsql-parser
Advanced tools
Combined SQL + PL/pgSQL parser with hydrated ASTs and transform API.
⚠️ Experimental: This package is currently experimental. If you're looking for just SQL parsing, see
pgsql-parser. For body-only PL/pgSQL deparsing, seeplpgsql-deparser.
This package provides a unified API for heterogeneous parsing and deparsing of SQL scripts containing PL/pgSQL functions. It handles the full pipeline: parsing SQL + PL/pgSQL together, transforming ASTs, and deparsing back to complete SQL.
Use this package when you need to:
CREATE FUNCTION statements with PL/pgSQL bodiesKey features:
CREATE FUNCTION statements with LANGUAGE plpgsqlRETURN statement handling based on function return typenpm install plpgsql-parser
import { parse, transform, deparseSync, loadModule } from 'plpgsql-parser';
// Initialize the WASM module
await loadModule();
// Parse SQL with PL/pgSQL functions - auto-detects and hydrates
const result = parse(`
CREATE FUNCTION my_func(p_id int)
RETURNS void
LANGUAGE plpgsql
AS $$
BEGIN
RAISE NOTICE 'Hello %', p_id;
END;
$$;
`);
console.log(result.functions.length); // 1
console.log(result.functions[0].plpgsql.hydrated); // Hydrated AST
// Transform API for parse -> modify -> deparse pipeline
const output = transformSync(sql, (ctx) => {
// Modify the function name
ctx.functions[0].stmt.funcname[0].String.sval = 'renamed_func';
});
// Deparse back to SQL
const sql = deparseSync(result, { pretty: true });
parse(sql, options?)Parses SQL and auto-detects PL/pgSQL functions, hydrating their bodies.
Options:
hydrate (default: true) - Whether to hydrate PL/pgSQL function bodiesReturns a ParsedScript with:
sql - The raw SQL parse resultitems - Array of parsed items (statements and functions)functions - Array of detected PL/pgSQL functions with hydrated ASTstransform(sql, callback, options?)Async transform pipeline: parse -> modify -> deparse.
transformSync(sql, callback, options?)Sync version of transform.
deparseSync(parsed, options?)Converts a parsed script back to SQL.
Options:
pretty (default: true) - Whether to pretty-print the outputThe package provides a visitor pattern for traversing PL/pgSQL ASTs, similar to @pgsql/traverse but designed for PL/pgSQL node types.
walk(root, callback, options?)Walks the tree of PL/pgSQL AST nodes using a visitor pattern.
import { parse, walk, loadModule } from 'plpgsql-parser';
import type { PLpgSQLVisitor } from 'plpgsql-parser';
await loadModule();
const parsed = parse(`
CREATE FUNCTION get_user(p_id int)
RETURNS text
LANGUAGE plpgsql
AS $$
BEGIN
RETURN (SELECT name FROM users WHERE id = p_id);
END;
$$;
`);
// Visit PL/pgSQL nodes
const visitor: PLpgSQLVisitor = {
PLpgSQL_stmt_block: (path) => {
console.log('Found block at path:', path.path);
},
PLpgSQL_stmt_return: (path) => {
console.log('Found return statement');
},
};
walk(parsed.functions[0].plpgsql.hydrated, visitor);
Options:
walkSqlExpressions (default: true) - Whether to recurse into hydrated SQL expressionssqlVisitor - SQL visitor to use when walking hydrated SQL expressions (from @pgsql/traverse)walkParsedScript(parsed, plpgsqlVisitor, sqlVisitor?)Convenience function that walks both SQL statements and PL/pgSQL function bodies.
import { parse, walkParsedScript, loadModule } from 'plpgsql-parser';
await loadModule();
const parsed = parse(`
CREATE TABLE users (id int);
CREATE FUNCTION get_user(p_id int) RETURNS text LANGUAGE plpgsql AS $$
BEGIN
RETURN (SELECT name FROM users WHERE id = p_id);
END;
$$;
`);
walkParsedScript(
parsed,
// PL/pgSQL visitor
{
PLpgSQL_stmt_return: (path) => {
console.log('PL/pgSQL return statement');
},
},
// SQL visitor (optional) - visits both top-level SQL and embedded SQL in functions
{
CreateStmt: (path) => {
console.log('CREATE TABLE statement');
},
RangeVar: (path) => {
console.log('Table reference:', path.node.relname);
},
}
);
PLpgSQLNodePathThe path object passed to visitor functions:
class PLpgSQLNodePath<TTag extends string = string> {
tag: TTag; // Node type (e.g., 'PLpgSQL_stmt_block')
node: any; // The actual node data
parent: PLpgSQLNodePath | null; // Parent path
keyPath: readonly (string | number)[]; // Full path array
get path(): (string | number)[]; // Copy of keyPath
get key(): string | number; // Last element of path
}
For power users, the package re-exports underlying primitives:
parseSql - SQL parser from @libpg-query/parserparsePlpgsqlBody - PL/pgSQL parser from @libpg-query/parserdeparseSql - SQL deparser from pgsql-deparserdeparsePlpgsqlBody - PL/pgSQL deparser from plpgsql-deparserhydratePlpgsqlAst - Hydration utility from plpgsql-deparserdehydratePlpgsqlAst - Dehydration utility from plpgsql-deparserMIT
🛠 Built by the Constructive team — creators of modular Postgres tooling for secure, composable backends. If you like our work, contribute on GitHub.
pgsql-parser.pgsql-parser for parsing and deparsing SQL queries.AS DESCRIBED IN THE LICENSES, THE SOFTWARE IS PROVIDED "AS IS", AT YOUR OWN RISK, AND WITHOUT WARRANTIES OF ANY KIND.
No developer or entity involved in creating Software will be liable for any claims or damages whatsoever associated with your use, inability to use, or your interaction with other users of the Software code or Software CLI, including any direct, indirect, incidental, special, exemplary, punitive or consequential damages, or loss of profits, cryptocurrencies, tokens, or anything else of value.
FAQs
Combined SQL + PL/pgSQL parser with hydrated ASTs and transform API
The npm package plpgsql-parser receives a total of 206,431 weekly downloads. As such, plpgsql-parser popularity was classified as popular.
We found that plpgsql-parser demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.