Packages

Input Sanitization & Security Packages

Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).

123 packages

Packages in Input Sanitization & Security

89Health
Library npm

DOMPurify

DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.

17,413
Apache 2.0
Used by 135
84Health
Library npm

sanitize-html

Allowlist-based HTML sanitizer that strips XSS vectors from untrusted markup while preserving the tags and attributes you choose to keep.

4,630
MIT
Used by 42
37Health
Library npm

rehype-sanitize

A unified rehype plugin that sanitizes HTML to prevent XSS by dropping anything a schema does not explicitly allow.

222
MIT
Used by 33
45Health
Library PyPI

markupsafe

Escapes untrusted strings for safe use in HTML and XML markup, preventing injection attacks in templated output.

697
BSD 3
Used by 20
41Health
Library npm

html-entities

Fast, zero-dependency HTML5/HTML4/XML entity encoding and decoding for JavaScript and TypeScript.

685
MIT
Used by 14
45Health
Library Go

bluemonday

A fast, allowlist-based HTML sanitizer for Go that strips XSS vectors from untrusted content while preserving safe markup.

3,726
BSD 3
Used by 13
40Health
Library npm

he

A robust, spec-compliant HTML entity encoder and decoder for JavaScript with full Unicode support.

3,595
MIT
Used by 11
84Health
SDK npm

react-turnstile

React bindings for Cloudflare Turnstile — a privacy-first CAPTCHA alternative with a declarative component and a full imperative ref API.

853
MIT
Used by 11
40Health
SDK npm

react-google-recaptcha

React component wrapper for Google reCAPTCHA v2, handling script loading, widget rendering, and the execute/reset API out of the box.

1,082
MIT
Used by 5
71Health
Library npm

altcha

Privacy-first, self-hosted CAPTCHA replacement that proves a visitor is human with invisible proof-of-work instead of puzzles, tracking, or third-party APIs.

2,779
MIT
Used by 4
42Health
Library Composer

Purify

A Laravel wrapper around HTMLPurifier that sanitizes untrusted HTML through a fluent facade, Eloquent casts, and configurable purification profiles.

538
MIT
Used by 4
43Health
Library npm

remark-html

A remark plugin that compiles markdown syntax trees directly into sanitized HTML strings.

335
MIT
Used by 4
72Health
Library Composer

HTML Purifier

A standards-compliant PHP library that filters untrusted HTML through robust whitelists to block XSS while keeping rich formatting intact.

3,353
Other
Used by 3
42Health
Library npm

common-tags

A well-tested library of tagged template literal functions for cleaning up multiline strings, HTML, and lists in ES2015+ JavaScript.

2,025
MIT
Used by 3
72Health
SDK npm

react-hcaptcha

Drop-in React and Preact components for adding hCaptcha bot-protection challenges to any form.

641
MIT
Used by 3
68Health
Library npm

string-strip-html

Strip HTML tags from strings without a full parser, safely handling mixed and templated markup.

214
MIT
Used by 3
49Health
Library Go

base64Captcha

A flexible Go library for generating digit, string, math, Chinese-character, and audio CAPTCHAs encoded as base64 strings.

2,367
Apache 2.0
Used by 2
78Health
Library npm

vue-dompurify-html

A DOMPurify-backed replacement for Vue's v-html directive that sanitizes bound HTML to prevent XSS.

334
MIT
Used by 2
30Health
Library npm

html-escaper

A tiny, zero-dependency utility that safely escapes and unescapes HTML entities in JavaScript strings.

112
MIT
Used by 2
63Health
Library Composer

Gregwar Captcha

Generate distorted CAPTCHA images in PHP to stop bots.

1,818
MIT
Used by 1
73Health
Library Cargo

ammonia

A fast, allowlist-based HTML sanitization library for Rust built on the html5ever browser-grade parser.

678
Other
Used by 1
42Health
SDK Composer

laravel-recaptcha

Drop-in Laravel package for embedding and validating Google reCAPTCHA v2 and v3 in your forms.

516
MIT
Used by 1
44Health
Library Composer

ExerciseHTMLPurifierBundle

Symfony integration for HTMLPurifier to sanitize untrusted HTML and prevent XSS

278
MIT
Used by 1
45Health
Library Cargo

html-escape

Context-aware HTML encoding and entity decoding for Rust, with no-std support.

56
MIT
Used by 1

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers