
Research
/Security News
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.
xpress-generator
Advanced tools
Professional Express.js project generator — scaffold a complete backend with TypeScript, Auth, Testing and more in one command
Professional Express.js project generator. Scaffold a complete, production-ready backend in one command — clean architecture, validated env config, structured logging, optional auth, OpenAPI docs, Docker, CI, testing, and linting all wired up automatically.
npx xpress-generator create MyApp
src/modules/{name}/, src/shared/, src/middleware/ instead of scattered flat folders.ts templates, tsconfig.json, ts-jestsrc/shared/config/env.js validates process.env with Zod at boot and fails fast with a clear error instead of crashing laterpino (+ pino-pretty in dev), request logging via pino-httpGET /health out of the boxSIGTERM/SIGINT close the HTTP server and the DB connection cleanlyregister + login flow backed by a User model (bcrypt-hashed passwords). Skip it entirely if you're using OAuth/an external providerverifyToken + requireRole('admin') middlewareALLOWED_ORIGINS, closed by default instead of wide openAppError, errorHandler, catchAsyncvalidate middleware, wired into every generated CRUD routegenerate:model list endpoints support ?page & ?limit out of the boxhttpResponse.success / created / paginated / noContentGET /docs, auto-generated from route annotationsdb/init.sql auto-bootstraps the database on first docker compose up (MySQL/PostgreSQL)Dockerfile (non-root in production) + docker-compose.yml per database, DB ports bound to localhost onlynpm run audit script in every generated projecttests/setup.js, realistic coverage threshold@typescript-eslint for TS projects), .eslintignore includedgenerate:model (full CRUD module, paginated, validated) and generate:middleware# Interactive — prompts all questions
npx xpress-generator create
# Or pass the project name directly
npx xpress-generator create MyApp
The CLI will ask:
MyApp/
├── src/
│ ├── app.js / app.ts ← Express app (exported, no listen)
│ ├── server.js / server.ts ← Entry point — listens + graceful shutdown
│ ├── config/
│ │ └── config-{db}.js ← Database connection
│ ├── shared/ ← Reusable code shared across modules
│ │ ├── config/
│ │ │ ├── env.js ← Zod-validated environment config
│ │ │ └── swagger.js ← OpenAPI spec setup
│ │ ├── errors/
│ │ │ └── AppError.js
│ │ ├── utils/
│ │ │ ├── catchAsync.js
│ │ │ ├── httpResponse.js
│ │ │ └── logger.js ← pino logger
│ │ ├── constants/
│ │ │ ├── httpStatus.js
│ │ │ └── messages.js
│ │ └── validators/
│ │ ├── validate.js
│ │ └── exampleSchema.js
│ ├── middleware/
│ │ ├── auth.js ← verifyToken, requireRole, authRateLimiter, apiLimiter
│ │ └── errorHandler.js
│ └── modules/
│ ├── {name}/ ← Index module (your project name)
│ │ ├── controller.js
│ │ ├── routes.js
│ │ ├── {name}Model.js
│ │ └── service.js
│ └── auth/ ← Auth module (only if auth is enabled)
│ ├── authController.js ← register, login, refresh, logout
│ ├── authRoutes.js
│ ├── User.js ← bcrypt-hashed password model
│ └── RefreshToken.js ← stores a SHA-256 hash, never the raw token
├── db/ ← Relational DBs only
│ ├── migrations/
│ │ └── {timestamp}-create-{name}.js ← + users / refresh_tokens if auth is enabled
│ └── init.sql ← Auto-bootstrap on first `docker compose up` (MySQL/Postgres)
├── tests/
│ ├── setup.js ← NODE_ENV=test, JWT secrets + dummy DB env for testing
│ └── indexController.test.js
├── .env
├── .eslintrc.json
├── .eslintignore
├── .gitignore
├── .github/workflows/ci.yml ← lint + build + test on push/PR
├── .husky/
│ └── pre-commit ← npx lint-staged
├── .lintstagedrc.json
├── .sequelizerc ← (MySQL / PostgreSQL only)
├── .xpress.json ← project metadata for generate commands
├── .dockerignore
├── Dockerfile ← Multi-stage build, non-root in production
├── docker-compose.yml ← DB service (localhost-only) + app
├── jest.config.js
└── package.json
TypeScript projects use
.tsextensions, includetsconfig.json, and scripts usets-node.
| Script | Description |
|---|---|
npm run dev | Start with nodemon (JS) or ts-node (TS) |
npm start | Start production server |
npm test | Run Jest with coverage |
npm run test:watch | Run Jest in watch mode |
npm run lint | Run ESLint |
npm run build | Compile TypeScript to dist/ (TS only) |
npm run audit | Check dependencies for known vulnerabilities |
npm run db:migrate | Run pending migrations (relational DBs only) |
npm run db:migrate:undo | Roll back last migration (MySQL / PostgreSQL) |
# Create a new project
npx xpress-generator create [name]
# Generate a full CRUD module (model + service + controller + routes + schema, paginated & validated)
npx xpress-generator generate:model <ModelName>
npx xpress-generator g:model <ModelName> # alias
# Generate a custom middleware
npx xpress-generator generate:middleware <name>
npx xpress-generator g:middleware <name> # alias
generate:model outputRunning xpress generate:model Product inside a project creates:
src/modules/product/
├── productModel.js ← DB model (Mongoose / Sequelize / mssql)
├── service.js ← getAll (paginated), getById, create, update, remove
├── schema.js ← Zod validation schema matching the model fields
├── controller.js ← CRUD handlers via catchAsync
└── routes.js ← Express router, validated + auth-protected, OpenAPI-annotated
db/migrations/{ts}-create-product.js ← (MySQL / PostgreSQL)
db/migrations/{ts}-create-product.sql ← (SQL Server)
GET /products?page=1&limit=20 returns a paginated response with meta: { page, limit, total, totalPages }.
If you answer "yes" to the auth prompt, the generated project includes a ready-to-use, real auth layer backed by a User model:
| Method | Route | Description |
|---|---|---|
| POST | /api/auth/register | Creates a user (bcrypt-hashed password) and returns accessToken + sets refreshToken cookie |
| POST | /api/auth/login | Verifies credentials against the User model |
| POST | /api/auth/refresh | Issues a new accessToken from the refresh cookie |
| POST | /api/auth/logout | Revokes the refresh token and clears the cookie |
Refresh tokens are stored as a SHA-256 hash, never in plain text. /auth/* routes are protected by a strict rate limiter (10 requests / 15 min); the rest of the API is protected by a general one (300 requests / 15 min).
Configure in .env:
JWT_SECRET=your-access-secret
JWT_EXPIRES_IN=15m
REFRESH_TOKEN_SECRET=your-refresh-secret
ALLOWED_ORIGINS=http://localhost:5173
If you skip auth, none of src/modules/auth/, the auth routes, or the users/refresh_tokens migrations are generated.
Every generated project exposes interactive OpenAPI docs at:
GET /docs
generate:model annotates the CRUD routes it creates automatically, so new modules show up in the docs without extra work.
# Run all pending migrations
npm run db:migrate
# Roll back the last migration
npm run db:migrate:undo
Migration files are stored in db/migrations/ and tracked automatically by Sequelize CLI. If auth is enabled, users and refresh_tokens migrations are included from the start.
For local development, db/init.sql is mounted into the database container and runs automatically the first time docker compose up creates the volume — no need to run migrations just to get a working local DB.
# Run all pending .sql files (tracked in _migrations table)
npm run db:migrate
# Start the full stack (app + database)
docker compose up
# Production build
docker compose up --build
# Detached mode
docker compose up -d
Dockerfile uses multi-stage builds: the production image contains only production dependencies and compiled source, and runs as a non-root user.127.0.0.1 only — never exposed to the network by default.MYSQL_ROOT_PASSWORD, MYSQL_PASSWORD, POSTGRES_PASSWORD and DB_PASSWORD have no insecure defaults — docker compose up fails with a clear message if you haven't set them in .env.Production:
express dotenv cors helmet pino pino-http
bcryptjs jsonwebtoken zod express-rate-limit cookie-parser
swagger-jsdoc swagger-ui-express
+ DB driver (mongoose / mysql2+sequelize / pg+sequelize / mssql)
Dev — runtime:
nodemon pino-pretty
+ TypeScript: ts-node typescript @types/*
Dev — testing:
jest supertest eslint lint-staged
+ TypeScript: ts-jest @types/jest @types/supertest @typescript-eslint/parser @typescript-eslint/eslint-plugin
Dev — git hooks:
husky
Dev — migrations:
sequelize-cli (MySQL / PostgreSQL only)
All dependencies are installed with pinned version ranges (not floating latest) to avoid an unexpected major version breaking a freshly generated project.
MIT © Felipe Vargas
FAQs
Professional Express.js project generator — scaffold a complete backend with TypeScript, Auth, Testing and more in one command
The npm package xpress-generator receives a total of 2 weekly downloads. As such, xpress-generator popularity was classified as not popular.
We found that xpress-generator demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.