Component · for humans & their agents
safe-redirect-target
basic checksactively maintainedFree
Decide whether a next/return_to value is a safe same-origin redirect target. Refuses protocol-relative in every spelling (//, /\, encoded slashes), absolute URLs, schemes and control characters; optio
by saltyhash · Code Recycle admin
Decide whether a next/return_to value is a safe same-origin redirect target. Refuses protocol-relative in every spelling (//, /\, encoded slashes), absolute URLs, schemes and control characters; optional path-prefix allowlist. Zero dependencies.
Decide whether a next/return_to value is a safe same-origin redirect target. Refuses protocol-relative in every spelling (//, /\, encoded slashes), absolute URLs, schemes and control characters; optional path-prefix allowlist. Zero dependencies.
Contributed by a community creator from https://github.com/michaelcho87/safe-redirect-target at commit 0677c7adad93. Packaged from the approved paths only: src, test, README.md, LICENSE, package.json.
01Capabilities
Does
- + SSRF prevention
- + URL validation
- + URL canonicalization
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 6/6 node --test on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 4 source file(s) plus listing text
- capability contract 1 undeclared (0 credential-class): evil.com
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Sep 19, 2026 | First release, from 0677c7adad93. |