Packages

Input Sanitization & Security Packages

Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).

123 packages

Packages in Input Sanitization & Security

Showing 15 of 123 packages
90Health
Librarynpm

DOMPurify

DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.

17,358
Apache 2.0
Used by 130
51Health
Librarynpm

cors

Node.js CORS middleware for Express and Connect that sets standards-compliant headers to control cross-origin browser access.

6,194
MIT
Used by 77
84Health
Librarynpm

sanitize-html

Allowlist-based HTML sanitizer that strips XSS vectors from untrusted markup while preserving the tags and attributes you choose to keep.

4,614
MIT
Used by 42
37Health
Librarynpm

rehype-sanitize

A unified rehype plugin that sanitizes HTML to prevent XSS by dropping anything a schema does not explicitly allow.

221
MIT
Used by 32
74Health
Librarynpm

helmet

Secure Node and Express apps by setting protective HTTP response headers with a single line of middleware.

10,731
MIT
Used by 31
85Health
Librarynpm

express-rate-limit

Basic IP rate-limiting middleware for Express to throttle repeated requests and protect public APIs and sensitive endpoints.

3,296
MIT
Used by 30
75Health
Librarynpm

validator.js

A dependency-free library of 100+ string validators and sanitizers for Node.js and the browser.

23,736
MIT
Used by 26
61Health
Librarynpm

isbot

Detect bots, crawlers, and spiders from the user agent string with a single call.

1,160
Other
Used by 22
45Health
LibraryPyPI

markupsafe

Escapes untrusted strings for safe use in HTML and XML markup, preventing injection attacks in templated output.

697
BSD 3
Used by 20
45Health
LibraryGo

cors

A spec-compliant, configurable CORS middleware for Go's net/http, with drop-in compatibility for most Go web frameworks.

2,898
MIT
Used by 19
55Health
Librarynpm

rate-limiter-flexible

Atomic and non-atomic counters and rate-limiting tools that protect against DoS and brute-force attacks at any scale

3,582
Other
Used by 16
41Health
LibraryPyPI

defusedxml

Drop-in replacements for Python's XML modules that block XML-bomb and entity-expansion attacks

550
Other
Used by 14
70Health
Librarynpm

isolated-vm

Secure, isolated V8 JavaScript environments for Node.js

2,916
Other
Used by 13
41Health
Librarynpm

html-entities

Fast, zero-dependency HTML5/HTML4/XML entity encoding and decoding for JavaScript and TypeScript.

686
MIT
Used by 13
73Health
Librarynpm

@fastify/cors

Official Fastify plugin that adds configurable CORS headers and preflight handling to any Fastify API.

496
MIT
Used by 13

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers

Search