
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
plpgsql-parser
Advanced tools
Combined SQL + PL/pgSQL parser with hydrated ASTs and transform API.
⚠️ Experimental: This package is currently experimental. If you're looking for just SQL parsing, see
pgsql-parser. For body-only PL/pgSQL deparsing, seeplpgsql-deparser.
This package provides a unified API for heterogeneous parsing and deparsing of SQL scripts containing PL/pgSQL functions. It handles the full pipeline: parsing SQL + PL/pgSQL together, transforming ASTs, and deparsing back to complete SQL.
Use this package when you need to:
CREATE FUNCTION statements with PL/pgSQL bodiesKey features:
CREATE FUNCTION statements with LANGUAGE plpgsqlRETURN statement handling based on function return typenpm install plpgsql-parser
import { parse, transform, deparseSync, loadModule } from 'plpgsql-parser';
// Initialize the WASM module
await loadModule();
// Parse SQL with PL/pgSQL functions - auto-detects and hydrates
const result = parse(`
CREATE FUNCTION my_func(p_id int)
RETURNS void
LANGUAGE plpgsql
AS $$
BEGIN
RAISE NOTICE 'Hello %', p_id;
END;
$$;
`);
console.log(result.functions.length); // 1
console.log(result.functions[0].plpgsql.hydrated); // Hydrated AST
// Transform API for parse -> modify -> deparse pipeline
const output = transformSync(sql, (ctx) => {
// Modify the function name
ctx.functions[0].stmt.funcname[0].String.sval = 'renamed_func';
});
// Deparse back to SQL
const sql = deparseSync(result, { pretty: true });
parse(sql, options?)Parses SQL and auto-detects PL/pgSQL functions, hydrating their bodies.
Options:
hydrate (default: true) - Whether to hydrate PL/pgSQL function bodiesReturns a ParsedScript with:
sql - The raw SQL parse resultitems - Array of parsed items (statements and functions)functions - Array of detected PL/pgSQL functions with hydrated ASTstransform(sql, callback, options?)Async transform pipeline: parse -> modify -> deparse.
transformSync(sql, callback, options?)Sync version of transform.
deparseSync(parsed, options?)Converts a parsed script back to SQL.
Options:
pretty (default: true) - Whether to pretty-print the outputThe walkers themselves live in @pgsql/traverse and are
re-exported here, so one import covers parsing and traversal. This package owns
the one entry point that genuinely needs a parser: SQL text in.
walkSql(sql, visitors, options?)Parses a SQL string, hydrates its PL/pgSQL function bodies, and walks both with the given visitors — SQL statements and PL/pgSQL bodies in a single pass.
import { loadModule, walkSql } from 'plpgsql-parser';
await loadModule();
const result = walkSql(sql, {
// SQL nodes, at the top level and inside function bodies
RangeVar: (path, ctx) => {
if (ctx.isWrite && path.node.schemaname === 'audit') {
ctx.abort('the audit schema is read-only');
}
if (ctx.insideFunction) {
console.log(`${path.node.relname} referenced by ${ctx.functionName}`);
}
},
// PL/pgSQL-only nodes, in the same visitor
PLpgSQL_stmt_dynexecute: (_path, ctx) => ctx.abort('dynamic EXECUTE is not allowed')
});
result.aborted; // true when a visitor called ctx.abort()
result.reason; // 'the audit schema is read-only'
Pass an array of visitors to compose independent policies in one parse. Every
callback receives a WalkContext (stmtTag, stmtIndex, isWrite, isRead,
insideFunction, functionName, abort) — see the
@pgsql/traverse README for the full traversal reference.
Options:
walkFunctionBodies (default: true) - Hydrate and walk PL/pgSQL function bodies. false skips the PL/pgSQL parse entirelywalkSqlExpressions (default: true) - Recurse into hydrated SQL expressions inside bodiessqlVisitor - Override the visitor used for those SQL expressionsUnparseable input is reported as { aborted: true, reason } rather than
throwing, so a validator can treat "rejected" and "could not be understood"
uniformly.
walk(ast, visitors, options?)Re-exported from @pgsql/traverse. Same behavior as walkSql, but takes an AST
you already have — a ParsedScript from parse(), a ParseResult, a SQL node,
or a PL/pgSQL node:
import { loadModule, parse, walk } from 'plpgsql-parser';
await loadModule();
const parsed = parse(`
CREATE TABLE users (id int);
CREATE FUNCTION get_user(id int) RETURNS text LANGUAGE plpgsql AS $$
BEGIN
RETURN (SELECT name FROM users WHERE users.id = id);
END;
$$;
`);
walk(parsed, {
CreateStmt: () => console.log('CREATE TABLE statement'),
RangeVar: (path) => console.log('Table reference:', path.node.relname),
PLpgSQL_stmt_return: () => console.log('PL/pgSQL return statement')
});
Also re-exported: walkSqlAst (SQL-only primitive), walkPlpgsqlAst
(PL/pgSQL-only primitive), PlpgsqlNodePath, and the WalkContext /
UnifiedVisitor / WalkResult types.
For power users, the package re-exports underlying primitives:
parseSql - SQL parser from @libpg-query/parserparsePlpgsqlBody - PL/pgSQL parser from @libpg-query/parserdeparseSql - SQL deparser from pgsql-deparserdeparsePlpgsqlBody - PL/pgSQL deparser from plpgsql-deparserhydratePlpgsqlAst - Hydration utility from plpgsql-deparserdehydratePlpgsqlAst - Dehydration utility from plpgsql-deparserwalk, walkSqlAst, walkPlpgsqlAst - Walkers from @pgsql/traverseMIT
🛠 Built by the Constructive team — creators of modular Postgres tooling for secure, composable backends. If you like our work, contribute on GitHub.
pgsql-parser.pgsql-parser for parsing and deparsing SQL queries.AS DESCRIBED IN THE LICENSES, THE SOFTWARE IS PROVIDED "AS IS", AT YOUR OWN RISK, AND WITHOUT WARRANTIES OF ANY KIND.
No developer or entity involved in creating Software will be liable for any claims or damages whatsoever associated with your use, inability to use, or your interaction with other users of the Software code or Software CLI, including any direct, indirect, incidental, special, exemplary, punitive or consequential damages, or loss of profits, cryptocurrencies, tokens, or anything else of value.
FAQs
Combined SQL + PL/pgSQL parser with hydrated ASTs and transform API
The npm package plpgsql-parser receives a total of 201,461 weekly downloads. As such, plpgsql-parser popularity was classified as popular.
We found that plpgsql-parser demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.