Input Sanitization & Security Packages
Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).
Packages in Input Sanitization & Security
Kind
Sort:Used by Most Apps
DOMPurify
DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.
cors
Node.js CORS middleware for Express and Connect that sets standards-compliant headers to control cross-origin browser access.
helmet
Secure Node and Express apps by setting protective HTTP response headers with a single line of middleware.
validator.js
A dependency-free library of 100+ string validators and sanitizers for Node.js and the browser.
markupsafe
Escapes untrusted strings for safe use in HTML and XML markup, preventing injection attacks in templated output.
he
A robust, spec-compliant HTML entity encoder and decoder for JavaScript with full Unicode support.
express-validator
A chainable Express middleware that wraps validator.js to validate and sanitize incoming request data with minimal boilerplate.
slowapi
Rate limiting for Starlette and FastAPI endpoints, adapted from Flask-Limiter.
RE2JS
Linear-time, ReDoS-safe regular expression engine for JavaScript
react-google-recaptcha
React component wrapper for Google reCAPTCHA v2, handling script loading, widget rendering, and the execute/reset API out of the box.
proxy-addr
Determine the real client IP address behind trusted proxies, with full IPv4, IPv6, and CIDR support.
common-tags
A well-tested library of tagged template literal functions for cleaning up multiline strings, HTML, and lists in ES2015+ JavaScript.
Flask-Limiter
Rate limiting for Flask applications with pluggable storage backends and per-route limits
django-csp
Content-Security-Policy header management for Django, with per-view overrides and nonce support.
Bandit
A static analysis tool that scans Python code for common security issues.
csurf
CSRF token middleware for Express — archived by the Express team in 2025 and no longer maintained.
near-membrane
A DOM membrane library for creating fast, secure sandboxed JavaScript environments in the browser.
python-ipware
Retrieve a client's real IP address from HTTP request headers, with proxy handling.
Presidio Analyzer
The PII detection engine behind Presidio, combining NER, regex, and checksum recognizers
serialize-javascript
Serializes JavaScript values-including functions, RegExps, Dates, Maps, Sets, and BigInts-into a superset of JSON that's safe to embed directly in an HTML script tag.
RestrictedPython
Compiles a restricted subset of Python so you can define a trusted boundary for running untrusted code.
simpleeval
A single-file Python library for safely evaluating user-supplied expressions without exposing full eval() access.
confusable_homoglyphs
Detect dangerous Unicode homoglyphs and mixed-script strings to stop impersonation attacks
js-string-escape
Escapes strings into safe JavaScript string literals, correctly handling quotes, backslashes, and all four ECMAScript line-terminator characters.