Preparing for system design interviews?  Try bugzed.com →

mongo-escape

JSON →
library 2.0.6 ·javascript maintenance
verified Jun 5, 2026

Lightweight npm package (v2.0.6, last updated 2016) for escaping $ and . characters in MongoDB query keys to prevent NoSQL injection attacks. Replaces $ with Unicode fullwidth dollar sign ($) and . with Unicode fullwidth full stop (.). Only protects against keyword injection, not full JavaScript injection – mapReduce and $where are not safe. Works on strings and objects (keys escaped in-place, no clone). Supports escape and unescape functions, with optional recursion flag. Minimal dependencies, simple API. Suitable for legacy systems needing basic injection prevention; not actively maintained.

total hits 16
actors 3 distinct systems
last hit 19d ago ByteDance
GPTBot
3
Amazonbot
3
ByteDance
3
Humans
7

top countries 🇸🇬 Singapore · 🇺🇸 United States · 🇵🇱 Poland · 🇹🇷 Turkey · VN