Input Sanitization & Security Packages
Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).
Packages in Input Sanitization & Security
Kind
Sort:Used by Most Apps
DOMPurify
DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.
sanitize-html
Allowlist-based HTML sanitizer that strips XSS vectors from untrusted markup while preserving the tags and attributes you choose to keep.
rehype-sanitize
A unified rehype plugin that sanitizes HTML to prevent XSS by dropping anything a schema does not explicitly allow.
markupsafe
Escapes untrusted strings for safe use in HTML and XML markup, preventing injection attacks in templated output.
html-entities
Fast, zero-dependency HTML5/HTML4/XML entity encoding and decoding for JavaScript and TypeScript.
bluemonday
A fast, allowlist-based HTML sanitizer for Go that strips XSS vectors from untrusted content while preserving safe markup.
he
A robust, spec-compliant HTML entity encoder and decoder for JavaScript with full Unicode support.
react-turnstile
React bindings for Cloudflare Turnstile — a privacy-first CAPTCHA alternative with a declarative component and a full imperative ref API.
react-google-recaptcha
React component wrapper for Google reCAPTCHA v2, handling script loading, widget rendering, and the execute/reset API out of the box.
altcha
Privacy-first, self-hosted CAPTCHA replacement that proves a visitor is human with invisible proof-of-work instead of puzzles, tracking, or third-party APIs.
Purify
A Laravel wrapper around HTMLPurifier that sanitizes untrusted HTML through a fluent facade, Eloquent casts, and configurable purification profiles.
remark-html
A remark plugin that compiles markdown syntax trees directly into sanitized HTML strings.
HTML Purifier
A standards-compliant PHP library that filters untrusted HTML through robust whitelists to block XSS while keeping rich formatting intact.
common-tags
A well-tested library of tagged template literal functions for cleaning up multiline strings, HTML, and lists in ES2015+ JavaScript.
react-hcaptcha
Drop-in React and Preact components for adding hCaptcha bot-protection challenges to any form.
string-strip-html
Strip HTML tags from strings without a full parser, safely handling mixed and templated markup.
base64Captcha
A flexible Go library for generating digit, string, math, Chinese-character, and audio CAPTCHAs encoded as base64 strings.
vue-dompurify-html
A DOMPurify-backed replacement for Vue's v-html directive that sanitizes bound HTML to prevent XSS.
html-escaper
A tiny, zero-dependency utility that safely escapes and unescapes HTML entities in JavaScript strings.
Gregwar Captcha
Generate distorted CAPTCHA images in PHP to stop bots.
ammonia
A fast, allowlist-based HTML sanitization library for Rust built on the html5ever browser-grade parser.
laravel-recaptcha
Drop-in Laravel package for embedding and validating Google reCAPTCHA v2 and v3 in your forms.
ExerciseHTMLPurifierBundle
Symfony integration for HTMLPurifier to sanitize untrusted HTML and prevent XSS
html-escape
Context-aware HTML encoding and entity decoding for Rust, with no-std support.