express-slow-down

The premium Open Source alternative to Cloudflare Rate Limiting

🎯 Best for:Express.js applications needing user-friendly brute-force protection.

What is express-slow-down?

Replaces hard-limit request blocking with a progressive delay mechanism for repeated requests. Integrates as middleware to mitigate brute-force attacks without terminating user sessions.

Tech Stack
TypeScriptBackend & Auth

Why express-slow-down?

  • Prevents service denial
  • Lightweight footprint
  • Highly configurable delays

Limitations

  • In-memory state by default
  • Node.js specific
  • Requires manual tuning
3/4/2026
Last Update
19
Forks
4
Issues
MIT
License
Financial Leak Detected

Stop the "SaaS Tax"

Your team could be burning cash. Switching to express-slow-down instantly boosts your runway.

Competitor Cost
-$1,440
/ year (est. based on Cloudflare Rate Limiting)
Self-Hosted
$0
/ year
Team Size10 Users
150+
SAVE 100%

Community Discussion

Comments