Input Sanitization & Security Packages
Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).
Packages in Input Sanitization & Security
Kind
Sort:Used by Most Apps
DOMPurify
DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.
cors
Node.js CORS middleware for Express and Connect that sets standards-compliant headers to control cross-origin browser access.
sanitize-html
Allowlist-based HTML sanitizer that strips XSS vectors from untrusted markup while preserving the tags and attributes you choose to keep.
rehype-sanitize
A unified rehype plugin that sanitizes HTML to prevent XSS by dropping anything a schema does not explicitly allow.
helmet
Secure Node and Express apps by setting protective HTTP response headers with a single line of middleware.
validator.js
A dependency-free library of 100+ string validators and sanitizers for Node.js and the browser.
markupsafe
Escapes untrusted strings for safe use in HTML and XML markup, preventing injection attacks in templated output.
html-entities
Fast, zero-dependency HTML5/HTML4/XML entity encoding and decoding for JavaScript and TypeScript.
bluemonday
A fast, allowlist-based HTML sanitizer for Go that strips XSS vectors from untrusted content while preserving safe markup.
he
A robust, spec-compliant HTML entity encoder and decoder for JavaScript with full Unicode support.
express-validator
A chainable Express middleware that wraps validator.js to validate and sanitize incoming request data with minimal boilerplate.
RE2JS
Linear-time, ReDoS-safe regular expression engine for JavaScript
react-google-recaptcha
React component wrapper for Google reCAPTCHA v2, handling script loading, widget rendering, and the execute/reset API out of the box.
Purify
A Laravel wrapper around HTMLPurifier that sanitizes untrusted HTML through a fluent facade, Eloquent casts, and configurable purification profiles.
remark-html
A remark plugin that compiles markdown syntax trees directly into sanitized HTML strings.
proxy-addr
Determine the real client IP address behind trusted proxies, with full IPv4, IPv6, and CIDR support.
HTML Purifier
A standards-compliant PHP library that filters untrusted HTML through robust whitelists to block XSS while keeping rich formatting intact.
common-tags
A well-tested library of tagged template literal functions for cleaning up multiline strings, HTML, and lists in ES2015+ JavaScript.
string-strip-html
Strip HTML tags from strings without a full parser, safely handling mixed and templated markup.
csurf
CSRF token middleware for Express — archived by the Express team in 2025 and no longer maintained.
vue-dompurify-html
A DOMPurify-backed replacement for Vue's v-html directive that sanitizes bound HTML to prevent XSS.
near-membrane
A DOM membrane library for creating fast, secure sandboxed JavaScript environments in the browser.
html-escaper
A tiny, zero-dependency utility that safely escapes and unescapes HTML entities in JavaScript strings.
serialize-javascript
Serializes JavaScript values-including functions, RegExps, Dates, Maps, Sets, and BigInts-into a superset of JSON that's safe to embed directly in an HTML script tag.