Input Sanitization & Security Packages
Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).
Packages in Input Sanitization & Security
Kind
Sort:Used by Most Apps
DOMPurify
DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.
sanitize-html
Allowlist-based HTML sanitizer that strips XSS vectors from untrusted markup while preserving the tags and attributes you choose to keep.
markupsafe
Escapes untrusted strings for safe use in HTML and XML markup, preventing injection attacks in templated output.
isomorphic-dompurify
Isomorphic wrapper for DOMPurify that sanitizes HTML identically on server and client.
slowapi
Rate limiting for Starlette and FastAPI endpoints, adapted from Flask-Limiter.
sanitize-filename
A basic filename sanitizer for Rust, ported from Node's sanitize-filename
Flask-Limiter
Rate limiting for Flask applications with pluggable storage backends and per-route limits
django-csp
Content-Security-Policy header management for Django, with per-view overrides and nonce support.
Bandit
A static analysis tool that scans Python code for common security issues.
python-ipware
Retrieve a client's real IP address from HTTP request headers, with proxy handling.
Presidio Analyzer
The PII detection engine behind Presidio, combining NER, regex, and checksum recognizers
RestrictedPython
Compiles a restricted subset of Python so you can define a trusted boundary for running untrusted code.
simpleeval
A single-file Python library for safely evaluating user-supplied expressions without exposing full eval() access.
svg-hush
A Rust library and CLI that strips scripting, cross-origin links, and other XSS vectors from untrusted SVG files.
pathvalidate
A zero-dependency Python library that sanitizes and validates filenames, file paths, and LTSV labels across Windows, Linux, macOS, and POSIX platforms.
confusable_homoglyphs
Detect dangerous Unicode homoglyphs and mixed-script strings to stop impersonation attacks
decancer
Rust library that strips unicode confusables, homoglyphs, and leetspeak from text for moderation and search normalization.
HTMLawed
A single-file PHP library that sanitizes HTML input to block XSS attacks and enforce standards-compliant markup.
altcha
Create and verify ALTCHA proof-of-work CAPTCHA challenges in Python with a zero-dependency, fully typed library.