Hub rules-alpinejs

rules-alpinejs

v2 public Verified

Alpine.js

Alpine.js is a rugged, minimal tool for composing behavior directly in your markup. These rules govern reactive patterns, directive usage, and security best practices for AI-assisted Alpine.js development.

@sigmashakeinc 2 pulls 6 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-alpinejs →
Severity
4 error 2 warn 0 info
demo.cast
Alpine.js is a rugged, minimal tool for composing behavior directly in your markup. These rules govern reactive patterns, directive usage, and security best practices for AI-assisted Alpine.js development.

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

alpinejs

alpinejs-attribute-injection-x-bind-url error block

Potential Attribute Injection vulnerability detected. Binding 'href' or 'src' attributes with untrusted input can lead to XSS (e.g., 'javascript:...' URLs) or resource loading from malicious domains. Always validate and sanitize URLs bound to 'x-bind:href' or 'x-bind:src' to ensure they conform to expected protocols and domains.

Rule source requires an active Pro or Enterprise subscription.
alpinejs-avoid-var-keyword warning log

Usage of the 'var' keyword detected in Alpine.js expressions. While not a direct security vulnerability, 'var' has function-level scope and can lead to unexpected behavior or shadowing issues. Prefer 'let' or 'const' for block-scoped variable declarations to promote modern JavaScript practices and avoid potential scope-related issues.

Rule source requires an active Pro or Enterprise subscription.
alpinejs-direct-eval-or-new-function error block

Direct use of 'eval()' or 'new Function()' within Alpine.js expressions is a severe security risk, enabling arbitrary code execution. This bypasses Alpine.js's secure expression evaluation. Refactor your code to use Alpine.js's built-in reactivity and event handling mechanisms, or define functions securely outside of inline expressions.

Rule source requires an active Pro or Enterprise subscription.
alpinejs-sensitive-data-in-x-data error block

Sensitive data (e.g., API keys, secrets, tokens, passwords) detected directly within 'x-data' attributes. This exposes sensitive information to the client-side DOM and can be easily accessed by attackers. Store sensitive data securely on the backend and retrieve it via authenticated API calls, or use secure client-side storage mechanisms with appropriate encryption if absolutely necessary.

Rule source requires an active Pro or Enterprise subscription.
alpinejs-unsanitized-server-template-variable-in-x-data warning log

Potentially unsanitized server-side template variable detected within 'x-data'. Directly embedding server-side variables without proper escaping or sanitization can introduce XSS vulnerabilities if the variable contains untrusted user input. Ensure all server-side variables rendered into 'x-data' are properly escaped for HTML attributes or JSON context (e.g., using '{{ variable | json_encode }}' or equivalent).

Rule source requires an active Pro or Enterprise subscription.
alpinejs-xss-x-html-unsanitized error block

Potential Cross-Site Scripting (XSS) vulnerability detected. Using 'x-html' with unsanitized user input can lead to arbitrary code execution. Always prefer 'x-text' for displaying user-generated content. If 'x-html' is absolutely necessary, ensure the content is rigorously sanitized using a trusted library like DOMPurify before binding.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v2
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
d1cb0e6dd603dc8044e036832bc6c7f96cd3a6622ba68fbdf3a441039ec3744e
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-alpinejs/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-alpinejs. The published version only bumps when a maintainer resyncs.

No commit history available.