Input Sanitization & Security Packages
Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).
Packages in Input Sanitization & Security
Kind
Sort:Used by Most Apps
DOMPurify
DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.
cors
Node.js CORS middleware for Express and Connect that sets standards-compliant headers to control cross-origin browser access.
helmet
Secure Node and Express apps by setting protective HTTP response headers with a single line of middleware.
validator.js
A dependency-free library of 100+ string validators and sanitizers for Node.js and the browser.
he
A robust, spec-compliant HTML entity encoder and decoder for JavaScript with full Unicode support.
express-validator
A chainable Express middleware that wraps validator.js to validate and sanitize incoming request data with minimal boilerplate.
RE2JS
Linear-time, ReDoS-safe regular expression engine for JavaScript
react-google-recaptcha
React component wrapper for Google reCAPTCHA v2, handling script loading, widget rendering, and the execute/reset API out of the box.
proxy-addr
Determine the real client IP address behind trusted proxies, with full IPv4, IPv6, and CIDR support.
common-tags
A well-tested library of tagged template literal functions for cleaning up multiline strings, HTML, and lists in ES2015+ JavaScript.
csurf
CSRF token middleware for Express — archived by the Express team in 2025 and no longer maintained.
near-membrane
A DOM membrane library for creating fast, secure sandboxed JavaScript environments in the browser.
serialize-javascript
Serializes JavaScript values-including functions, RegExps, Dates, Maps, Sets, and BigInts-into a superset of JSON that's safe to embed directly in an HTML script tag.
js-string-escape
Escapes strings into safe JavaScript string literals, correctly handling quotes, backslashes, and all four ECMAScript line-terminator characters.
quickjs-rs
Sandboxed JavaScript and TypeScript execution for Python, running QuickJS inside a WebAssembly sandbox.