Input Sanitization & Security Packages
Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).
Packages in Input Sanitization & Security
Kind
Sort:Used by Most Apps
cors
Node.js CORS middleware for Express and Connect that sets standards-compliant headers to control cross-origin browser access.
helmet
Secure Node and Express apps by setting protective HTTP response headers with a single line of middleware.
express-rate-limit
Basic IP rate-limiting middleware for Express to throttle repeated requests and protect public APIs and sensitive endpoints.
markupsafe
Escapes untrusted strings for safe use in HTML and XML markup, preventing injection attacks in templated output.
rate-limiter-flexible
Atomic and non-atomic counters and rate-limiting tools that protect against DoS and brute-force attacks at any scale
express-validator
A chainable Express middleware that wraps validator.js to validate and sanitize incoming request data with minimal boilerplate.
slowapi
Rate limiting for Starlette and FastAPI endpoints, adapted from Flask-Limiter.
csrf-sync
Stateful CSRF protection for Express using the Synchronizer Token Pattern, built to replace the deprecated csurf package.
Flask-Limiter
Rate limiting for Flask applications with pluggable storage backends and per-route limits
django-csp
Content-Security-Policy header management for Django, with per-view overrides and nonce support.
Bandit
A static analysis tool that scans Python code for common security issues.
csurf
CSRF token middleware for Express — archived by the Express team in 2025 and no longer maintained.
nocache
Tiny Express/Connect middleware that sets HTTP headers to disable client-side response caching.
python-ipware
Retrieve a client's real IP address from HTTP request headers, with proxy handling.
Presidio Analyzer
The PII detection engine behind Presidio, combining NER, regex, and checksum recognizers
RestrictedPython
Compiles a restricted subset of Python so you can define a trusted boundary for running untrusted code.
simpleeval
A single-file Python library for safely evaluating user-supplied expressions without exposing full eval() access.
express-mongo-sanitize
Express middleware that strips MongoDB operator injection payloads from req.body, req.query, req.params, and req.headers before they reach your database queries.
confusable_homoglyphs
Detect dangerous Unicode homoglyphs and mixed-script strings to stop impersonation attacks
altcha
Create and verify ALTCHA proof-of-work CAPTCHA challenges in Python with a zero-dependency, fully typed library.