{"id":13447914,"url":"https://github.com/jpillora/xhook","last_synced_at":"2025-10-08T17:10:23.720Z","repository":{"id":10248992,"uuid":"12355674","full_name":"jpillora/xhook","owner":"jpillora","description":"Easily intercept and modify XHR request and response","archived":false,"fork":false,"pushed_at":"2024-07-06T03:33:26.000Z","size":1285,"stargazers_count":1025,"open_issues_count":55,"forks_count":157,"subscribers_count":29,"default_branch":"main","last_synced_at":"2025-09-30T03:25:59.658Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"http://jpillora.com/xhook","language":"HTML","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jpillora.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2013-08-25T07:27:32.000Z","updated_at":"2025-09-28T00:29:54.000Z","dependencies_parsed_at":"2024-06-18T12:42:58.519Z","dependency_job_id":"48abe35c-3526-4727-b9fa-da38295e9144","html_url":"https://github.com/jpillora/xhook","commit_stats":{"total_commits":221,"total_committers":27,"mean_commits":8.185185185185185,"dds":0.751131221719457,"last_synced_commit":"950c7f42cb371fcbc65e003e13c4141db790a55f"},"previous_names":[],"tags_count":44,"template":false,"template_full_name":null,"purl":"pkg:github/jpillora/xhook","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jpillora%2Fxhook","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jpillora%2Fxhook/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jpillora%2Fxhook/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jpillora%2Fxhook/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jpillora","download_url":"https://codeload.github.com/jpillora/xhook/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jpillora%2Fxhook/sbom","scorecard":{"id":535745,"data":{"date":"2025-08-11","repo":{"name":"github.com/jpillora/xhook","commit":"950c7f42cb371fcbc65e003e13c4141db790a55f"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.7,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":7,"reason":"Found 19/26 approved changesets -- score normalized to 7","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Warn: no topLevel permission defined: .github/workflows/release.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":3,"reason":"dependency not pinned by hash detected -- score normalized to 3","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/jpillora/xhook/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/jpillora/xhook/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/jpillora/xhook/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/jpillora/xhook/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/jpillora/xhook/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/jpillora/xhook/release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/jpillora/xhook/release.yml/main?enable=pin","Info:   0 out of   7 GitHub-owned GitHubAction dependencies pinned","Info:   3 out of   3 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":0,"reason":"10 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-fwr7-v2mv-hh25","Warn: Project is vulnerable to: GHSA-gxpj-cx7g-858c","Warn: Project is vulnerable to: GHSA-74fj-2j2h-c42q","Warn: Project is vulnerable to: GHSA-pw2r-vq6v-hr8c","Warn: Project is vulnerable to: GHSA-jchw-25xp-jwwc","Warn: Project is vulnerable to: GHSA-cxjh-pqwp-8mfp","Warn: Project is vulnerable to: GHSA-p6mc-m468-83gw","Warn: Project is vulnerable to: GHSA-29mw-wpgm-hmr9","Warn: Project is vulnerable to: GHSA-35jh-r3h4-6jhm","Warn: Project is vulnerable to: GHSA-gcx4-mw62-g8wm"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-20T06:54:54.060Z","repository_id":10248992,"created_at":"2025-08-20T06:54:54.060Z","updated_at":"2025-08-20T06:54:54.060Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":278981518,"owners_count":26079640,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-08T02:00:06.501Z","response_time":56,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-31T05:01:30.222Z","updated_at":"2025-10-08T17:10:23.703Z","avatar_url":"https://github.com/jpillora.png","language":"HTML","readme":"# XHook\n\n#### Easily intercept and modify XHR (\"AJAX\") request and response\n\n\u003ca href=\"https://twitter.com/intent/tweet?hashtags=xhook%2Cjavascript%2Cxhr\u0026original_referer=http%3A%2F%2Fgithub.com%2F\u0026text=XHook%3A+Easily+intercept+and+modify+XHR+request+and+response\u0026tw_p=tweetbutton\u0026url=https%3A%2F%2Fgithub.com%2Fjpillora%2Fxhook\" target=\"_blank\"\u003e\n  \u003cimg src=\"http://jpillora.com/github-twitter-button/img/tweet.png\"\u003e\u003c/img\u003e\n\u003c/a\u003e\n\nWith XHook, you could easily implement functionality to:\n\n- Cache requests in memory, localStorage, etc.\n- Insert authentication headers\n  - S3 Request Signing, see [S3 Hook](https://github.com/jpillora/s3hook)\n- Simulate responses\n  - Create fake transparent backends for testing purposes\n- Sending Error statistics to Google Analytics\n- Create a client-side alternative to CORS by offloading requests to an iframe then splicing the response back in, see [XDomain](http://jpillora.com/xdomain)\n- Devious practical jokes\n- Supports RequiresJS and Browserify\n- Preflight GZip compression, see [XZip](http://github.com/jpillora/xzip) (Incomplete)\n\n## Features\n\n- Intercept and modify XMLHttpRequest (\"AJAX\") **request** and **response**\n- Simulate **responses** transparently\n- Backwards compatible `addEventListener` `removeEventListener`\n- Backwards compatible user controlled progress (download/upload) events\n\n## Browser Support\n\nSupport Modern Browser.\n\n## Demos\n\n### *http://jpillora.com/xhook*\n\n## Usage\n\n:warning: _It's_ **important** _to include XHook first as other libraries may store a reference to `XMLHttpRequest` before XHook can patch it_\n\nUsing `script` link to load xhook and use it, like so:\n\n```html\n\u003cscript src=\"//unpkg.com/xhook@latest/dist/xhook.min.js\"\u003e\u003c/script\u003e\n\u003cscript\u003e\n  xhook.after(function (request, response) {\n    if (request.url.match(/example\\.txt$/))\n      response.text = response.text.replace(/[aeiou]/g, \"z\");\n  });\n\u003c/script\u003e\n```\n\n- Development [xhook.js](https://jpillora.com/xhook/dist/xhook.js)\n- Production [xhook.min.js](https://jpillora.com/xhook/dist/xhook.min.js)\n- CDN (Use `latest` or lock to one of the [available versions](https://github.com/jpillora/xhook/releases))\n\nWe can also install xhook via npm.\n\n```bash\nnpm install xhook\n```\n\nThen use ESM syntax to load xhook.\n\n```js\nimport xhook from \"xhook\";\n//modify 'responseText' of 'example2.txt'\nxhook.after(function (request, response) {\n  if (request.url.match(/example\\.txt$/))\n    response.text = response.text.replace(/[aeiou]/g, \"z\");\n});\n```\n\n## API\n\n### `xhook.before(handler(request[, callback])[, index])`\n\nModifying **any** property of the `request` object will modify the underlying XHR before it is sent.\n\nTo make the `handler` is asynchronous, just include the optional `callback` function, which accepts an optional `response` object.\n\nTo provide a **fake** response, `return` **or** `callback()` a `response` object.\n\n### `xhook.after(handler(request, response[, callback]) [, index])`\n\nModifying **any** property of the `response` object will modify the underlying XHR before it is received.\n\nTo make the `handler` is asynchronous, just include the optional `callback` function.\n\n### `xhook.enable()`\n\nEnables XHook (swaps out the native `XMLHttpRequest` class). XHook is enabled be default.\n\n### `xhook.disable()`\n\nDisables XHook (swaps the native `XMLHttpRequest` class back in)\n\n---\n\n### `request` Object\n\n- `method` (String) (_\u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#open()\"\u003e`open(method,url)`\u003c/a\u003e_)\n- `url` (String) (_\u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#open()\"\u003e`open(method,url)`\u003c/a\u003e_)\n- `body` (String) (_\u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#send()\"\u003e`send(body)`\u003c/a\u003e_)\n- `headers` (Object) (_Contains Name-Value pairs set with \u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#setRequestHeader()\"\u003e`setRequestHeader(name,value)`\u003c/a\u003e_)\n- `timeout` (Number) _([`timeout`](https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#timeout))_\n- `type` (String) _([`responseType`](https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#responseType))_\n- `withCredentials` (String) _([`withCredentials`](https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#withCredentials))_\n\n### `response` Object\n\n- `status` (Number) **Required when for fake `response`s** _([`status`](https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#status))_\n- `statusText` (String) _([`statusText`](https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#statusText))_\n- `text` (String) _([`responseText`](https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#responseText))_\n- `headers` (Object) (_Contains Name-Value pairs retrieved with \u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#getAllResponseHeaders()\"\u003e`getAllResponseHeaders()`\u003c/a\u003e_)\n- `xml` (XML) _([`responseXML`](https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#responseXML))_\n- `data` (Varies) _([`response`](https://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest#response))_\n\n## Overview\n\n\u003cimg src=\"https://docs.google.com/drawings/d/1PTxHDqdW9iNqagDwtaO0ggXZkJp7ILiRDVWAMHInFGQ/pub?w=498\u0026amp;h=235\"\u003e\n\n_The dark red `before` hook is returning a `response` object, which will trigger the `after`\nhooks, then trigger the appropriate events, so it_ **appears** _as if `response` came from\nthe server._\n\n## Reference\n\nhttps://developer.mozilla.org/en-US/docs/Web/API/XMLHttpRequest\n\nhttp://www.w3.org/TR/XMLHttpRequest/\n\nhttp://www.w3.org/TR/XMLHttpRequest2/\n\n## Issues\n\n- XHook does **not** attempt to resolve any browser compatibility issues. Libraries like jQuery\n  and https://github.com/ilinsky/xmlhttprequest will attempt to do this. XHook simply proxies to and from `XMLHttpRequest`, so you may use any library\n  conjunction with XHook, just make sure to load XHook **first**.\n\n- You may use synchronous XHR, though this will cause asynchronous hooks to be **skipped**.\n\n## Contributing\n\nSee [CONTRIBUTING](CONTRIBUTING.md) for instructions on how to build and run XHook locally.\n\n## License\n\n[MIT](LICENSE) License Copyright © 2022 Jaime Pillora dev@jpillora.com\n","funding_links":[],"categories":["JavaScript"],"sub_categories":[],"project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjpillora%2Fxhook","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjpillora%2Fxhook","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjpillora%2Fxhook/lists"}