Input Sanitization & Security Packages
Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).
Packages in Input Sanitization & Security
Kind
Sort:Used by Most Apps
DOMPurify
DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.
sanitize-html
Allowlist-based HTML sanitizer that strips XSS vectors from untrusted markup while preserving the tags and attributes you choose to keep.
helmet
Secure Node and Express apps by setting protective HTTP response headers with a single line of middleware.
express-rate-limit
Basic IP rate-limiting middleware for Express to throttle repeated requests and protect public APIs and sensitive endpoints.
markupsafe
Escapes untrusted strings for safe use in HTML and XML markup, preventing injection attacks in templated output.
rate-limiter-flexible
Atomic and non-atomic counters and rate-limiting tools that protect against DoS and brute-force attacks at any scale
bluemonday
A fast, allowlist-based HTML sanitizer for Go that strips XSS vectors from untrusted content while preserving safe markup.
isomorphic-dompurify
Isomorphic wrapper for DOMPurify that sanitizes HTML identically on server and client.
enshrined/svg-sanitize
A PHP SVG/XML sanitizer that strips malicious markup from untrusted SVGs
secure
Standard net/http middleware that adds HSTS, CSP, X-Frame-Options, and other security headers to any Go web app in a few lines.
slowapi
Rate limiting for Starlette and FastAPI endpoints, adapted from Flask-Limiter.
Anthropic Sandbox Runtime
Wraps any command in OS-native filesystem and network sandboxing, without requiring a container.
zxcvbn-ts
A TypeScript rewrite of Dropbox's zxcvbn password strength estimator, with pluggable dictionaries and async matcher support.
altcha
Privacy-first, self-hosted CAPTCHA replacement that proves a visitor is human with invisible proof-of-work instead of puzzles, tracking, or third-party APIs.
hono-rate-limiter
Rate limiting middleware for Hono with pluggable memory, Redis, Cloudflare, and Unstorage backends, plus WebSocket support.
Flask-Limiter
Rate limiting for Flask applications with pluggable storage backends and per-route limits
django-csp
Content-Security-Policy header management for Django, with per-view overrides and nonce support.
Bandit
A static analysis tool that scans Python code for common security issues.
zxcvbn-python
A Python port of Dropbox's zxcvbn - realistic password strength estimation with crack-time estimates and specific improvement feedback.
vue-dompurify-html
A DOMPurify-backed replacement for Vue's v-html directive that sanitizes bound HTML to prevent XSS.
python-ipware
Retrieve a client's real IP address from HTTP request headers, with proxy handling.
Presidio Analyzer
The PII detection engine behind Presidio, combining NER, regex, and checksum recognizers
Mews Purifier
A Laravel integration of HTMLPurifier that sanitizes user-supplied HTML to prevent XSS while preserving safe, well-formed markup.
Gregwar Captcha
Generate distorted CAPTCHA images in PHP to stop bots.