express-slow-down
The premium Open Source alternative to Cloudflare Rate Limiting
🎯 Best for:Express.js applications needing user-friendly brute-force protection.
What is express-slow-down?
Replaces hard-limit request blocking with a progressive delay mechanism for repeated requests. Integrates as middleware to mitigate brute-force attacks without terminating user sessions.
Tech Stack
TypeScriptBackend & Auth
Why express-slow-down?
- • Prevents service denial
- • Lightweight footprint
- • Highly configurable delays
Limitations
- • In-memory state by default
- • Node.js specific
- • Requires manual tuning
3/4/2026
Last Update
19
Forks
4
Issues
MIT
License
Financial Leak Detected
Stop the "SaaS Tax"
Your team could be burning cash. Switching to express-slow-down instantly boosts your runway.
Competitor Cost
-$1,440
/ year (est. based on Cloudflare Rate Limiting)
Self-Hosted
$0
/ year
Team Size10 Users
150+
SAVE 100%