{"repo":"metakraft/payload-doctor","free":true,"listed":false,"github":"https://github.com/metakraft/payload-doctor","clone":"git clone https://github.com/metakraft/payload-doctor.git","description":"Static security & correctness linter for Payload CMS. Zero-config, deterministic, ts-morph-based. Catches access-control gaps, unsafe Local API usage & richtext render risks. npx-runnable.","language":"TypeScript","stars":14,"topics":["cli","code-quality","devtools","linter","nextjs","payload","payload-cms","payloadcms","security","static-analysis"],"license":"MIT","category":"dev-tools","readme_excerpt":"payload-doctor Static security & correctness linter for Payload CMS — the TypeScript headless CMS. It scans your collections, access control, hooks, routes and config for known anti-patterns — the kind that AI coding agents and humans alike get wrong — and prints a 0–100 health score with actionable findings. Note: this is for Payload CMS (the framework). It does not inspect or validate API request/response payloads (JSON/XML). If you came looking for that, this isn't it. Think of it as a react-doctor for Payload. One command, no install: Why Payload's Local API bypasses access control by default ( overrideAccess is true unless you set it to false ). It's the single most expensive footgun in a Payload app: a route can authenticate a user and still hand them someone else's records, because the collection's access functions never run. payload-doctor catches that and a dozen related issues before they reach production. Usage Recommended workflow: run it → fix the errors first → re-run and watch the score climb. Keep a clean git state before applying fixes. Score bands: 75–100 great · 50–74 needs work · 0–49 critical. The score is max(0, 100 − 10·errors − 3·warnings) ; info findings don't affect it. Ten or more errors floor it at 0 by design — once you're in the red, track the dropping error/warning counts (and the per-rule summary) to gauge progress rather than the score alone. Exit code is 1 when any error -severity finding is present (or the score is below --min-score ), 0 oth","default_branch":null,"files":null,"tree":[],"storefront":"/r/metakraft","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/metakraft/payload-doctor/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}