Input Sanitization & Security Packages
Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).
Packages in Input Sanitization & Security
Kind
Sort:Used by Most Apps
DOMPurify
DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.
cors
Node.js CORS middleware for Express and Connect that sets standards-compliant headers to control cross-origin browser access.
sanitize-html
Allowlist-based HTML sanitizer that strips XSS vectors from untrusted markup while preserving the tags and attributes you choose to keep.
helmet
Secure Node and Express apps by setting protective HTTP response headers with a single line of middleware.
validator.js
A dependency-free library of 100+ string validators and sanitizers for Node.js and the browser.
isomorphic-dompurify
Isomorphic wrapper for DOMPurify that sanitizes HTML identically on server and client.
he
A robust, spec-compliant HTML entity encoder and decoder for JavaScript with full Unicode support.
express-validator
A chainable Express middleware that wraps validator.js to validate and sanitize incoming request data with minimal boilerplate.
RE2JS
Linear-time, ReDoS-safe regular expression engine for JavaScript
react-google-recaptcha
React component wrapper for Google reCAPTCHA v2, handling script loading, widget rendering, and the execute/reset API out of the box.
proxy-addr
Determine the real client IP address behind trusted proxies, with full IPv4, IPv6, and CIDR support.
sanitize-filename
A basic filename sanitizer for Rust, ported from Node's sanitize-filename
common-tags
A well-tested library of tagged template literal functions for cleaning up multiline strings, HTML, and lists in ES2015+ JavaScript.
csurf
CSRF token middleware for Express — archived by the Express team in 2025 and no longer maintained.
near-membrane
A DOM membrane library for creating fast, secure sandboxed JavaScript environments in the browser.
serialize-javascript
Serializes JavaScript values-including functions, RegExps, Dates, Maps, Sets, and BigInts-into a superset of JSON that's safe to embed directly in an HTML script tag.
svg-hush
A Rust library and CLI that strips scripting, cross-origin links, and other XSS vectors from untrusted SVG files.
pathvalidate
A zero-dependency Python library that sanitizes and validates filenames, file paths, and LTSV labels across Windows, Linux, macOS, and POSIX platforms.
decancer
Rust library that strips unicode confusables, homoglyphs, and leetspeak from text for moderation and search normalization.
js-string-escape
Escapes strings into safe JavaScript string literals, correctly handling quotes, backslashes, and all four ECMAScript line-terminator characters.
HTMLawed
A single-file PHP library that sanitizes HTML input to block XSS attacks and enforce standards-compliant markup.
quickjs-rs
Sandboxed JavaScript and TypeScript execution for Python, running QuickJS inside a WebAssembly sandbox.