Packages

Input Sanitization & Security Packages

Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).

123 packages

Packages in Input Sanitization & Security

89Health
Library npm

DOMPurify

DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.

17,413
Apache 2.0
Used by 135
50Health
Library npm

cors

Node.js CORS middleware for Express and Connect that sets standards-compliant headers to control cross-origin browser access.

6,195
MIT
Used by 79
84Health
Library npm

sanitize-html

Allowlist-based HTML sanitizer that strips XSS vectors from untrusted markup while preserving the tags and attributes you choose to keep.

4,630
MIT
Used by 42
37Health
Library npm

rehype-sanitize

A unified rehype plugin that sanitizes HTML to prevent XSS by dropping anything a schema does not explicitly allow.

222
MIT
Used by 33
71Health
Library npm

helmet

Secure Node and Express apps by setting protective HTTP response headers with a single line of middleware.

10,736
MIT
Used by 32
81Health
Library npm

express-rate-limit

Basic IP rate-limiting middleware for Express to throttle repeated requests and protect public APIs and sensitive endpoints.

3,305
MIT
Used by 30
75Health
Library npm

validator.js

A dependency-free library of 100+ string validators and sanitizers for Node.js and the browser.

23,736
MIT
Used by 26
56Health
Library npm

isbot

Detect bots, crawlers, and spiders from the user agent string with a single call.

1,160
Other
Used by 23
45Health
Library PyPI

markupsafe

Escapes untrusted strings for safe use in HTML and XML markup, preventing injection attacks in templated output.

697
BSD 3
Used by 20
44Health
Library Go

cors

A spec-compliant, configurable CORS middleware for Go's net/http, with drop-in compatibility for most Go web frameworks.

2,898
MIT
Used by 19
66Health
Library npm

rate-limiter-flexible

Atomic and non-atomic counters and rate-limiting tools that protect against DoS and brute-force attacks at any scale

3,589
Other
Used by 16
41Health
Library PyPI

defusedxml

Drop-in replacements for Python's XML modules that block XML-bomb and entity-expansion attacks

554
Other
Used by 15
41Health
Library npm

html-entities

Fast, zero-dependency HTML5/HTML4/XML entity encoding and decoding for JavaScript and TypeScript.

685
MIT
Used by 14
69Health
Library npm

@fastify/cors

Official Fastify plugin that adds configurable CORS headers and preflight handling to any Fastify API.

497
MIT
Used by 14
45Health
Library Go

bluemonday

A fast, allowlist-based HTML sanitizer for Go that strips XSS vectors from untrusted content while preserving safe markup.

3,726
BSD 3
Used by 13
69Health
Library npm

isolated-vm

Secure, isolated V8 JavaScript environments for Node.js

2,929
Other
Used by 13
81Health
Library npm

isomorphic-dompurify

Isomorphic wrapper for DOMPurify that sanitizes HTML identically on server and client.

598
MIT
Used by 12
55Health
Library npm

shell-quote

Parses and quotes POSIX shell command strings, guarding against shell injection when building commands programmatically.

63
MIT
Used by 12
40Health
Library npm

he

A robust, spec-compliant HTML entity encoder and decoder for JavaScript with full Unicode support.

3,595
MIT
Used by 11
84Health
SDK npm

react-turnstile

React bindings for Cloudflare Turnstile — a privacy-first CAPTCHA alternative with a declarative component and a full imperative ref API.

853
MIT
Used by 11
64Health
Library PyPI

django-cors-headers

Configurable CORS headers middleware for Django applications

5,584
MIT
Used by 10
45Health
Library PyPI

Bleach

Allowlist-based HTML sanitizing library for untrusted text

2,765
Apache 2.0
Used by 9
79Health
Library npm

express-validator

A chainable Express middleware that wraps validator.js to validate and sanitize incoming request data with minimal boilerplate.

6,233
MIT
Used by 8
59Health
Library Go

govalidator

A comprehensive Go package of string, numeric, and struct validators and sanitizers, modeled on validator.js.

6,203
MIT
Used by 7

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers