Packages

Input Sanitization & Security Packages

Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).

123 packages

Packages in Input Sanitization & Security

89Health
Library npm

DOMPurify

DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.

17,413
Apache 2.0
Used by 135
50Health
Library npm

cors

Node.js CORS middleware for Express and Connect that sets standards-compliant headers to control cross-origin browser access.

6,195
MIT
Used by 79
71Health
Library npm

helmet

Secure Node and Express apps by setting protective HTTP response headers with a single line of middleware.

10,736
MIT
Used by 32
75Health
Library npm

validator.js

A dependency-free library of 100+ string validators and sanitizers for Node.js and the browser.

23,736
MIT
Used by 26
45Health
Library PyPI

markupsafe

Escapes untrusted strings for safe use in HTML and XML markup, preventing injection attacks in templated output.

697
BSD 3
Used by 20
40Health
Library npm

he

A robust, spec-compliant HTML entity encoder and decoder for JavaScript with full Unicode support.

3,595
MIT
Used by 11
79Health
Library npm

express-validator

A chainable Express middleware that wraps validator.js to validate and sanitize incoming request data with minimal boilerplate.

6,233
MIT
Used by 8
53Health
Library PyPI

slowapi

Rate limiting for Starlette and FastAPI endpoints, adapted from Flask-Limiter.

2,064
MIT
Used by 6
77Health
Library npm

RE2JS

Linear-time, ReDoS-safe regular expression engine for JavaScript

206
MIT
Used by 6
40Health
SDK npm

react-google-recaptcha

React component wrapper for Google reCAPTCHA v2, handling script loading, widget rendering, and the execute/reset API out of the box.

1,082
MIT
Used by 5
65Health
Library npm

proxy-addr

Determine the real client IP address behind trusted proxies, with full IPv4, IPv6, and CIDR support.

141
MIT
Used by 4
42Health
Library npm

common-tags

A well-tested library of tagged template literal functions for cleaning up multiline strings, HTML, and lists in ES2015+ JavaScript.

2,025
MIT
Used by 3
48Health
Library PyPI

Flask-Limiter

Rate limiting for Flask applications with pluggable storage backends and per-route limits

1,207
MIT
Used by 3
45Health
Library PyPI

django-csp

Content-Security-Policy header management for Django, with per-view overrides and nonce support.

624
BSD 3
Used by 3
76Health
Tool PyPI

Bandit

A static analysis tool that scans Python code for common security issues.

8,285
Apache 2.0
Used by 2
43Health
Library npm

csurf

CSRF token middleware for Express — archived by the Express team in 2025 and no longer maintained.

2,305
MIT
Used by 2
75Health
Library npm

near-membrane

A DOM membrane library for creating fast, secure sandboxed JavaScript environments in the browser.

133
MIT
Used by 2
51Health
Library PyPI

python-ipware

Retrieve a client's real IP address from HTTP request headers, with proxy handling.

43
MIT
Used by 2
89Health
Library PyPI

Presidio Analyzer

The PII detection engine behind Presidio, combining NER, regex, and checksum recognizers

11,062
MIT
Used by 1
68Health
Library npm

serialize-javascript

Serializes JavaScript values-including functions, RegExps, Dates, Maps, Sets, and BigInts-into a superset of JSON that's safe to embed directly in an HTML script tag.

2,923
BSD 3
Used by 1
65Health
Library PyPI

RestrictedPython

Compiles a restricted subset of Python so you can define a trusted boundary for running untrusted code.

743
Other
Used by 1
70Health
Library PyPI

simpleeval

A single-file Python library for safely evaluating user-supplied expressions without exposing full eval() access.

613
MIT
Used by 1
31Health
Library PyPI

confusable_homoglyphs

Detect dangerous Unicode homoglyphs and mixed-script strings to stop impersonation attacks

166
MIT
Used by 1
25Health
Library npm

js-string-escape

Escapes strings into safe JavaScript string literals, correctly handling quotes, backslashes, and all four ECMAScript line-terminator characters.

71
MIT
Used by 1

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers