npm

express

2 versionsdiscovered · its AI-security audit & verification record by name.

5.1.0unauditedresolved-commitverifiedqueued for audit · priority 158
coverage →

expressjs/express @ 51a0e7c9d3f28b6a…

AI security assessmentcleanqwen2.5-7b-instruct

Router and response paths sanitize reflected input; 4.x error-path echo is gone.

2026-08-15confidence 82%not a signed attestation — automated pre-screen
Methodology
Sources @ 51a0e7c9d3
README.md, lib/application.js, lib/response.js, lib/request.js, lib/router/index.js, index.js
Parts 6 files, 11200 bytes
Techniques llm-static-source-review, prompt-injection-detection, insecure-tool-and-function-calling, unsafe-eval-exec-of-model-output, ssrf-detection, secret-exposure-detection, classic-software-vulnerability-review
Parameters qwen2.5-7b-instruct · temp 0 · max 900 tok · local

No signed audits for this version yet. It is in the audit queue awaiting a claim.

4.21.2audit disputedresolved-commitverified
coverage →

expressjs/express @ f60718293a4b5c6d…

AI security assessmentfindingsrisk: mediumqwen2.5-7b-instruct

Reflected user input in an error path.

2026-08-15confidence 71%not a signed attestation — automated pre-screen
  • mediumError message echoes unsanitized pathCWE-79lib/response.js:1044
Methodology
Sources @ f60718293a
README.md, lib/application.js, lib/response.js, lib/request.js, lib/router/index.js, lib/router/route.js, index.js
Parts 7 files, 13520 bytes (truncated)
Techniques llm-static-source-review, prompt-injection-detection, insecure-tool-and-function-calling, unsafe-eval-exec-of-model-output, ssrf-detection, secret-exposure-detection, classic-software-vulnerability-review
Parameters qwen2.5-7b-instruct · temp 0 · max 900 tok · local
  • audited byAlice Ramirezflag upheld · falsified722f8c48d561

    A flag against this audit was upheld — its clean claim was overturned and the auditor's reputation slashed. Do not rely on it.

    classes examined: CWE-79, CWE-89

    Independently verified by
    reproducedBob Chen

Gate this package in CI

Fail the build on an attested vulnerability or registry tampering, and emit skip-scan excludes for audited files — one command against the registry.

signet gate --purl pkg:npm/express@5.1.0 --registry https://signet.seekerslab.com

README badge

Show this package's Signet status in its README — audited, AI pre-screened, or unaudited. Updates within an hour of a new attestation.

![signet](https://signet.seekerslab.com/v1/badge/npm/express.svg)

← Back to the package dictionary