Input Sanitization & Security Packages
Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).
Packages in Input Sanitization & Security
Kind
Sort:Used by Most Apps
DOMPurify
DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.
cors
Node.js CORS middleware for Express and Connect that sets standards-compliant headers to control cross-origin browser access.
helmet
Secure Node and Express apps by setting protective HTTP response headers with a single line of middleware.
express-rate-limit
Basic IP rate-limiting middleware for Express to throttle repeated requests and protect public APIs and sensitive endpoints.
validator.js
A dependency-free library of 100+ string validators and sanitizers for Node.js and the browser.
he
A robust, spec-compliant HTML entity encoder and decoder for JavaScript with full Unicode support.
django-cors-headers
Configurable CORS headers middleware for Django applications
express-validator
A chainable Express middleware that wraps validator.js to validate and sanitize incoming request data with minimal boilerplate.
secure
Standard net/http middleware that adds HSTS, CSP, X-Frame-Options, and other security headers to any Go web app in a few lines.
RE2JS
Linear-time, ReDoS-safe regular expression engine for JavaScript
react-google-recaptcha
React component wrapper for Google reCAPTCHA v2, handling script loading, widget rendering, and the execute/reset API out of the box.
hono-rate-limiter
Rate limiting middleware for Hono with pluggable memory, Redis, Cloudflare, and Unstorage backends, plus WebSocket support.
proxy-addr
Determine the real client IP address behind trusted proxies, with full IPv4, IPv6, and CIDR support.
csrf-sync
Stateful CSRF protection for Express using the Synchronizer Token Pattern, built to replace the deprecated csurf package.
common-tags
A well-tested library of tagged template literal functions for cleaning up multiline strings, HTML, and lists in ES2015+ JavaScript.
csurf
CSRF token middleware for Express — archived by the Express team in 2025 and no longer maintained.
near-membrane
A DOM membrane library for creating fast, secure sandboxed JavaScript environments in the browser.
Laravel CORS
CORS middleware that adds cross-origin headers to Laravel applications.
serialize-javascript
Serializes JavaScript values-including functions, RegExps, Dates, Maps, Sets, and BigInts-into a superset of JSON that's safe to embed directly in an HTML script tag.
express-mongo-sanitize
Express middleware that strips MongoDB operator injection payloads from req.body, req.query, req.params, and req.headers before they reach your database queries.
js-string-escape
Escapes strings into safe JavaScript string literals, correctly handling quotes, backslashes, and all four ECMAScript line-terminator characters.
quickjs-rs
Sandboxed JavaScript and TypeScript execution for Python, running QuickJS inside a WebAssembly sandbox.