njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.