New:Microsoft Teams Notifications Are Now Available in Socket.Learn more
Get Started
r

renzom13

npm

884

total weekly downloads

Packages

Current Co-maintainers

Former Co-maintainers

39 packages

appwrite-security

Audit Appwrite projects for over-permissive collection/document permissions. Keyless --discover mode parses your repo + probes the public REST API anon (no API key needed). Active probe confirms leaks live.

convex-security

Audit any Convex backend for public functions reachable without auth — and PROVE each leak live by calling the public HTTP API anonymously and returning the real rows. No deploy key needed for the keyless scan.

deep-research-mcp-server

MCP server that gives Claude, Cursor, or any AI agent web search, clean page reading, and one-call research dossiers. No OpenAI/Perplexity/Tavily key required.

directus-security

Audit any Directus instance for public-role data exposure, user enumeration, unauthenticated version/schema leaks and GraphQL introspection — and PROVE each leak live with an anonymous probe. No admin token needed for the keyless scan.

dotclaude-security

Scan a repo's local .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE and API-key-exfiltration footguns (CVE-2025-59536, CVE-2026-21852) that fire the moment you clone and open an untrusted repository — and flag the exact

dotenv-exposure-check

Probe a live URL for accidentally-served secret artifacts — .env, .env.production, .git/config, source maps (.js.map), .DS_Store, backup files — and CONFIRM each hit by fetching the bytes and flagging the real credentials and endpoints found inside. Zero

firebase-security

Audit Firebase Firestore Rules for the infamous 'if true' / wildcard-match-all data leak patterns. Keyless --discover mode parses your repo + probes Firestore REST anon (no service account). Active probe confirms leaks live.

hasura-security

Audit any self-hosted Hasura GraphQL endpoint for the misconfigs that actually leak data — open introspection without the admin secret, the anonymous 'public' unauthorized role exposing tables/columns/rows, and an unauthenticated console — and PROVE each

incomeos-mcp

MCP server for IncomeOS — ask your AI agent how much you made across every income stream (Stripe, affiliates, apps, ads, manual).

leadfinder-api

Free Google Maps lead finder API client. Find business names, phones, websites, ratings for any niche in any city.

multi-scraper-mcp

MCP server exposing 14 web scrapers as tools for AI agents: Reddit, Amazon, eBay, Google Maps, Yelp, YouTube, TikTok, Indeed, Trustpilot, contact finder, and lead-gen.

mxverify

Fast email verifier with no API key — checks syntax, disposable domains, role addresses, and live MX records. Tags each email valid / risky / invalid. Zero dependencies.

n8n-nodes-amazon-product-scraper

n8n community node for the Apify Amazon Product Scraper - scrape Amazon products by search or URL with no API key. Get titles, live prices, ratings, review counts, ASIN, seller, brand, Prime status and stock.

n8n-nodes-facebook-ad-library

n8n community node for the Apify Facebook Ad Library Scraper - spy on competitor Facebook and Instagram ads with no login. Pull every active ad creative, copy, run dates and landing page from the Meta Ad Library.

n8n-nodes-google-maps-businesses

n8n community node for the Apify Google Maps Email Extractor - scrape Google Maps businesses with emails, phones and social links for lead generation. No API key required.

n8n-nodes-google-maps-leads

n8n community node for the Apify Google Maps Email Scraper - extract business leads from Google Maps complete with emails, phones and social profiles for lead generation. No API key required.

n8n-nodes-healthcare-provider-leads

n8n community node for the Apify Healthcare Provider Leads Actor - get verified US doctor, dentist and clinic leads from the official NPI registry with name, specialty, address, phone, plus enriched emails and socials.

n8n-nodes-postwire

Publish one idea natively to TikTok, Instagram, YouTube, LinkedIn, X, Bluesky, Mastodon, Telegram, Discord and Reddit from n8n — a different post written for each network, via PostWire.

n8n-nodes-reddit-scraper

n8n community node for the Apify Reddit Sentiment Scraper - scrape Reddit posts, comments and full threads with built-in sentiment scoring. No login, no API key, no rate limits.

n8n-nodes-telegram-channel-scraper

n8n community node for the Apify Telegram Channel Scraper - scrape any public Telegram channel with no login and no API key. Get every post, view count, media, link and timestamp in clean JSON.

n8n-nodes-website-contact-finder

n8n community node for the Apify Email Scraper & Contact Finder - extract emails and contact details from any list of websites in bulk for lead generation. No API key required.

n8n-security

Audit any self-hosted n8n instance for the misconfigurations that lead to takeover — the unauthenticated /rest/settings config+version leak, open owner-setup registration, exposed version vs known critical CVEs, and missing auth on the editor/REST API — a

nhost-security

Audit Nhost (Hasura+Postgres) projects for permissive role permissions, public GraphQL access, and unsafe auth config. Keyless --discover mode parses your repo + probes GraphQL anon (no admin secret needed).

ollama-security

Audit any Ollama server for the misconfiguration that leaks compute and models — a public API bound with no auth — and PROVE it live with an anonymous probe of /api/tags, /api/ps, /api/version and CORS reflection. Zero deps, no keys.

payload-security

Audit any Payload CMS instance for collections readable without auth, GraphQL introspection, user/login enumeration and field-level leaks (apiKey, email, hash) — and PROVE each leak live with an anonymous probe. No admin token needed for the keyless scan.