Input Sanitization & Security Packages
Input sanitization, XSS prevention, and application-security utilities that clean untrusted input before it reaches your rendering or storage layer (DOMPurify).
Packages in Input Sanitization & Security
Kind
Sort:Used by Most Apps
DOMPurify
DOM-only, uber-tolerant XSS sanitizer for HTML, MathML, and SVG that runs in the browser and on the server.
sanitize-html
Allowlist-based HTML sanitizer that strips XSS vectors from untrusted markup while preserving the tags and attributes you choose to keep.
rehype-sanitize
A unified rehype plugin that sanitizes HTML to prevent XSS by dropping anything a schema does not explicitly allow.
markupsafe
Escapes untrusted strings for safe use in HTML and XML markup, preventing injection attacks in templated output.
bluemonday
A fast, allowlist-based HTML sanitizer for Go that strips XSS vectors from untrusted content while preserving safe markup.
isomorphic-dompurify
Isomorphic wrapper for DOMPurify that sanitizes HTML identically on server and client.
express-validator
A chainable Express middleware that wraps validator.js to validate and sanitize incoming request data with minimal boilerplate.
slowapi
Rate limiting for Starlette and FastAPI endpoints, adapted from Flask-Limiter.
Flask-Limiter
Rate limiting for Flask applications with pluggable storage backends and per-route limits
django-csp
Content-Security-Policy header management for Django, with per-view overrides and nonce support.
Bandit
A static analysis tool that scans Python code for common security issues.
vue-dompurify-html
A DOMPurify-backed replacement for Vue's v-html directive that sanitizes bound HTML to prevent XSS.
python-ipware
Retrieve a client's real IP address from HTTP request headers, with proxy handling.
Presidio Analyzer
The PII detection engine behind Presidio, combining NER, regex, and checksum recognizers
Mews Purifier
A Laravel integration of HTMLPurifier that sanitizes user-supplied HTML to prevent XSS while preserving safe, well-formed markup.
RestrictedPython
Compiles a restricted subset of Python so you can define a trusted boundary for running untrusted code.
ammonia
A fast, allowlist-based HTML sanitization library for Rust built on the html5ever browser-grade parser.
simpleeval
A single-file Python library for safely evaluating user-supplied expressions without exposing full eval() access.
svg-hush
A Rust library and CLI that strips scripting, cross-origin links, and other XSS vectors from untrusted SVG files.
confusable_homoglyphs
Detect dangerous Unicode homoglyphs and mixed-script strings to stop impersonation attacks
HTMLawed
A single-file PHP library that sanitizes HTML input to block XSS attacks and enforce standards-compliant markup.
altcha
Create and verify ALTCHA proof-of-work CAPTCHA challenges in Python with a zero-dependency, fully typed library.