Input Sanitization & Security Packages
Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).
Packages in Input Sanitization & Security
Kind
Sort:Used by Most Apps
cors
Node.js CORS middleware for Express and Connect that sets standards-compliant headers to control cross-origin browser access.
helmet
Secure Node and Express apps by setting protective HTTP response headers with a single line of middleware.
express-rate-limit
Basic IP rate-limiting middleware for Express to throttle repeated requests and protect public APIs and sensitive endpoints.
markupsafe
Escapes untrusted strings for safe use in HTML and XML markup, preventing injection attacks in templated output.
django-cors-headers
Configurable CORS headers middleware for Django applications
secure
Standard net/http middleware that adds HSTS, CSP, X-Frame-Options, and other security headers to any Go web app in a few lines.
slowapi
Rate limiting for Starlette and FastAPI endpoints, adapted from Flask-Limiter.
hono-rate-limiter
Rate limiting middleware for Hono with pluggable memory, Redis, Cloudflare, and Unstorage backends, plus WebSocket support.
csrf-sync
Stateful CSRF protection for Express using the Synchronizer Token Pattern, built to replace the deprecated csurf package.
Flask-Limiter
Rate limiting for Flask applications with pluggable storage backends and per-route limits
django-csp
Content-Security-Policy header management for Django, with per-view overrides and nonce support.
Bandit
A static analysis tool that scans Python code for common security issues.
csurf
CSRF token middleware for Express — archived by the Express team in 2025 and no longer maintained.
python-ipware
Retrieve a client's real IP address from HTTP request headers, with proxy handling.
Presidio Analyzer
The PII detection engine behind Presidio, combining NER, regex, and checksum recognizers
Laravel CORS
CORS middleware that adds cross-origin headers to Laravel applications.
RestrictedPython
Compiles a restricted subset of Python so you can define a trusted boundary for running untrusted code.
simpleeval
A single-file Python library for safely evaluating user-supplied expressions without exposing full eval() access.
express-mongo-sanitize
Express middleware that strips MongoDB operator injection payloads from req.body, req.query, req.params, and req.headers before they reach your database queries.
confusable_homoglyphs
Detect dangerous Unicode homoglyphs and mixed-script strings to stop impersonation attacks
altcha
Create and verify ALTCHA proof-of-work CAPTCHA challenges in Python with a zero-dependency, fully typed library.