Stack Insight Logo

Home Docs Blog
  • 89% of 2,720 Prisma Schemas Leave a Foreign Key Unindexed

    89% of 2,720 Prisma Schemas Leave a Foreign Key Unindexed

    Prisma doesn't index foreign keys. Across 2,720 public schemas, the typical one leaves 41% of its foreign keys unindexed, and 89% miss at least one.

    View on GitHub

    Sep 23, 2026

  • N+1 Queries: 34x Slower on Localhost, 98x in Production

    N+1 Queries: 34x Slower on Localhost, 98x in Production

    I scanned 28 open-source repos for N+1 queries and verified all 213 findings against source. 212 hold up. Then measured one: 5.1 seconds where the batched fix takes 52ms.

    View on GitHub

    Sep 20, 2026

  • Redundant Work in Node.js: A 311-Repository Study on Memoization and Request-Scoped Caching

    Redundant Work in Node.js: A 311-Repository Study on Memoization and Request-Scoped Caching

    We scanned 311 Node.js repositories with AST-based static analysis to identify repeated function calls, HTTP requests, GraphQL queries, and database operations within single request flows. We found 1,247 cache opportunities across 412 files, with the strongest signal coming from repeated pure compute (489 findings), followed by repeated HTTP fetches (386 findings) and repeated DB/GraphQL queries (372 findings). This study reveals that the most effective caching optimization is not adding infrastructure—it's recognizing duplicate work that's already happening.

    View on GitHub

    Jun 8, 2026

  • ReDoS in the Wild: What 329 JavaScript Repositories Taught Us About Regex Denial of Service

    ReDoS in the Wild: What 329 JavaScript Repositories Taught Us About Regex Denial of Service

    We scanned 329 JavaScript/TypeScript repositories for ReDoS patterns, benchmarked the core attack mechanisms, and found 9,528 potential vulnerabilities. This study explains what those findings mean, why synthetic benchmarks are still useful, and how junior developers can spot the real danger in regex code.

    View on GitHub

    May 20, 2026

  • A 10MB API Response Costs 66ms Before Your Code Even Runs.

    A 10MB API Response Costs 66ms Before Your Code Even Runs.

    I benchmarked five large-payload patterns (1KB–10MB) and scanned 277 public API repositories (300 in corpus, 23 failed) with a Babel AST detector. JSON.parse on a 10MB response takes 66.0ms median on Node.js 22. Pagination cuts parse cost by ~10x. In the wild, 179/277 repos (64.6%) had at least one large-payload anti-pattern: 52,010 total findings. Unbounded ORM fetches dominate (32,829). Deep nested includes account for another 17,069. Here’s the data and the fixes.

    View on GitHub

    May 12, 2026

  • DOM Manipulation That Kills Your 60fps: A Benchmarked Study of Layout Thrashing and Anti-Patterns Across 275 Repositories

    DOM Manipulation That Kills Your 60fps: A Benchmarked Study of Layout Thrashing and Anti-Patterns Across 275 Repositories

    I ran 5 Playwright browser benchmarks across 5 DOM node counts (100–10,000) to measure the real cost of layout thrashing, innerHTML-in-loop, and style-mutation-in-loop. Then I scanned 275 repositories. The innerHTML anti-pattern at n=10,000 hit 24.8 seconds — 8,000× slower than batching. 54.9% of repos had at least one anti-pattern. Here's the full data.

    View on GitHub

    May 3, 2026

  • I Benchmarked Five Bundle Bloat Patterns and Scanned 500 Repos. Only Two Actually Matter.

    I Benchmarked Five Bundle Bloat Patterns and Scanned 500 Repos. Only Two Actually Matter.

    I ran esbuild bundle-size benchmarks on five common import anti-patterns and scanned 500 frontend repositories with a Babel AST detector. lodash full import inflates bundles by 17.6×. moment.js costs 5.9× vs dayjs. But the most commonly warned-about pattern — barrel imports from MUI and antd — showed zero measurable difference with a modern bundler. 21.2% of repos had at least one anti-pattern. 17,594 total findings. Here's the full data.

    View on GitHub

    Apr 10, 2026

  • Suspected Resource Leak Patterns in 87.8% of 368 Production Node.js Repositories: A Static Analysis Study

    Suspected Resource Leak Patterns in 87.8% of 368 Production Node.js Repositories: A Static Analysis Study

    I scanned 368 Node.js production repositories using a Babel AST detector for six resource leak patterns. 323 of them — 87.8% — matched at least one suspicious pattern (false positive rate unvalidated). 33,625 total findings. The dominant pattern was unclosed event listeners at 57.7%, followed by streams at 20.7% and timers at 14.4%. The fastest-killing leak types in controlled experiments (connection pools: 132 ms median exhaustion, HTTP sockets: 245 ms) appeared in only 7.2% of findings. The leak types that degrade slowly and evade standard heap monitoring dominate real code.

    View on GitHub

    Mar 24, 2026

  • How Fast Do Node.js Resource Leaks Fail? A Six-Subsystem Scaling Study

    How Fast Do Node.js Resource Leaks Fail? A Six-Subsystem Scaling Study

    We redesigned and re-ran six Node.js resource leak simulation experiments to answer the operator's question that matters most: when does a leak stop being survivable? The scaling results show three distinct failure classes. Connection pool leaks collapse in 132 ms to 880 ms. HTTP socket leaks follow at 245 ms to 3.1 s. File descriptor and stream leaks usually fail over 10-26 s. Redesigned timer and event-listener experiments, which previously had no finite time-to-failure, now produce operational exhaustion signals from 600 ms to 25.6 s. This article presents the final medians, explains the redesign, and shows why leak detection must be tied to the subsystem being leaked.

    View on GitHub

    Mar 21, 2026

  • File Descriptor Exhaustion: A Four-Case Simulation Study of How fs.open() Leaks Trigger EMFILE in Node.js

    File Descriptor Exhaustion: A Four-Case Simulation Study of How fs.open() Leaks Trigger EMFILE in Node.js

    We built a discrete-event file descriptor simulator and ran four two-dimensional parameter grid experiments to measure how leak probability, concurrency, file size, FD limits, error handling, and open rate interact to cause EMFILE errors. At FD limit 64, a 5% leak rate at concurrency 50 exhausts file descriptors in under 3 seconds. File size has zero effect on time-to-exhaustion but scales heap growth linearly — 64 leaked FDs on 10MB files = 640MB heap. This is Part 2 of our resource leak study, focusing on BM-02: file descriptor exhaustion.

    View on GitHub

    Mar 19, 2026

Page 1 of 4
Previous 1234 Next
 Stack Insight
About Contact Privacy Policy
© 2026 StackInsight.dev. All rights reserved.