Do Not Use bodyParser with Express.js Note: this post has been edited to take into account TJ's diligent work in response to this. I came across this Google+ post mentioning this StackOverflow post in which someone is quite wisely asking whether the express.js framework is secure enough to use for production applications. This reminds me of one "gotcha" in particular that you could be bitten by if