rehype-sanitize

A unified rehype plugin that sanitizes HTML to prevent XSS by dropping anything a schema does not explicitly allow.

Library
npm
v6.0.0
222 stars
MIT License

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
37 /100 Needs Attention
Development Activity 0
Maintenance 20
Community 48
Maturity 60
Momentum 20

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
88 /100 Excellent
Architecture 88
Code Quality 95
Innovation 85
Learning Curve 70

rehype-sanitize is a rehype (unified) plugin that makes HTML safe by cleaning a hast syntax tree against a configurable schema, dropping any element or attribute that is not explicitly allowed. It defaults to GitHub’s sanitation rules, so untrusted markup, inline event handlers, dangerous URLs, and injected scripts are stripped out before rendering.

Built on hast-util-sanitize, it slots into any unified/rehype pipeline between parsing and stringifying. It is the standard way to defend against cross-site scripting when rendering user-authored or plugin-generated HTML, and its schema can be extended to safely permit math, syntax highlighting, or other trusted markup.

What You Get

  • A drop-in rehype plugin that sanitizes a hast tree against a configurable allowlist schema.
  • A secure default schema (defaultSchema) modeled on GitHub’s sanitation rules, requiring no configuration to be safe.
  • Protection against XSS, DOM clobbering (via user-content- id/name prefixing), dangerous URLs, and inline event handlers.
  • Full TypeScript types (via JSDoc) and ESM-only distribution with 100% type and test coverage.
  • Extensible schemas so you can safely opt in to math, syntax highlighting, or other trusted markup.

Common Use Cases

  • Sanitizing user-authored HTML or Markdown-derived HTML before rendering it on a page.
  • Hardening a rehype/remark content pipeline against XSS from untrusted authors or third-party plugins.
  • Allowing specific trusted classes so plugins like rehype-katex or rehype-highlight can run safely.
  • Preventing DOM clobbering when generating heading IDs from user content.

Under The Hood

Architecture

The package is intentionally tiny. index.js re-exports defaultSchema from hast-util-sanitize and the default plugin from lib/index.js. lib/index.js defines rehypeSanitize(options), which returns a unified transformer that calls sanitize(tree, options) on the incoming hast Root and returns the cleaned tree. All actual sanitation logic lives in the underlying hast-util-sanitize utility; this plugin is the thin unified-integration layer that lets you drop sanitation into a .use() chain between parse and stringify.

Tech Stack

Written in modern ESM JavaScript (Node 16+), typed entirely through JSDoc with TypeScript checking (tsconfig.json, type-coverage at 100%). Runtime dependencies are just hast-util-sanitize (the sanitizer) and @types/hast (types). Tooling includes xo and prettier for linting/formatting, c8 for coverage, and the built-in node:test runner. The build compiles type declarations with tsc.

Code Quality

Quality is high and rigorously enforced: test.js uses node:test to verify the public API surface, default sanitation of an onmouseover attribute, and schema-merged options, with c8 enforcing 100% line coverage and type-coverage enforcing 100% typed coverage in strict mode. The code is small, documented with JSDoc, and follows consistent unified-ecosystem conventions.

API Design

The public API is minimal and ergonomic: a default export used as .use(rehypeSanitize[, schema]) plus a named defaultSchema export for extension. Being safe by default with zero configuration is the key DX win, and the extensive README documents real-world schema-extension recipes (math, highlighting, DOM-clobbering mitigation). Familiarity with hast/unified is needed only for advanced schema customization.

Used by 33 apps in this directory

TypeScript
49%
AGPL 3.0

Banana Slides

AI Design Tools · Productivity

15,667

AI-native PPT generator with Vibe editing, multi-LLM support, and fully editable PPTX export

View details
84
Repo Health
82
Technical
71
Dependency
Built with
TypeScript 49%
Python 46%
Updated 1 weeks ago
Swift
62%
GPL 3.0

cmux

AI Development · Developer Tools

27,452

A native, Ghostty-based macOS terminal with vertical tabs, agent-aware notifications, and a scriptable browser built for running many parallel AI coding agent sessions instead of juggling tmux panes.

View details
84
Repo Health
81
Technical
69
Dependency
Built with
Swift 62%
Rust 13%
Updated 1 weeks ago
TypeScript
84%
Apache 2.0

Continue

AI Code Assistants · AI Development · Automation

36,049

Open-source coding agent for VS Code, JetBrains, and CLI with support for 30+ LLM providers.

View details
73
Repo Health
88
Technical
62
Dependency
Built with
TypeScript 84%
Updated 1 weeks ago
Rust
67%
Other

DefGuard

Authentication · Networking · Security

2,849

Self-hosted secure remote access that unifies WireGuard VPN, identity management, and connection-level MFA in one open-source platform.

View details
84
Repo Health
82
Technical
72
Dependency
Built with
Rust 67%
TypeScript 31%
Updated 2 weeks ago
Go
62%
Apache 2.0

Harness Open Source

Code Editors · Developer Tools · Devops

38,450

A unified open source DevOps platform combining Git hosting, CI/CD pipelines, cloud development environments, and artifact registries in a single self-hosted system.

View details
89
Repo Health
79
Technical
64
Dependency
Built with
Go 62%
TypeScript 33%
Updated 2 weeks ago
TypeScript
100%
Apache 2.0

ILLA Builder

Design Tools · Developer Tools · Low Code Platforms

12,327

Open-source low-code platform for building internal tools with drag-and-drop UI, reactive data bindings, and real-time collaboration.

View details
56
Repo Health
71
Technical
63
Dependency
Built with
TypeScript 100%
Updated 4 months ago
Python
64%
Other

Keep

Automation · Devops · Monitoring

12,359

The open-source AIOps and alert management platform that unifies 130+ monitoring tools into a single pane of glass with AI-powered correlation, deduplication, and workflow automation.

View details
89
Repo Health
79
Technical
66
Dependency
Built with
Python 64%
TypeScript 36%
Updated 2 weeks ago
TypeScript
98%
Other

Kibana

Analytics · Monitoring

21,301

Your open source window into the Elastic Stack — query, visualize, and act on data stored in Elasticsearch with real-time dashboards, AI-assisted search, and automated alerting.

View details
98
Repo Health
87
Technical
63
Dependency
Built with
TypeScript 98%
Updated 1 weeks ago
Python
69%
MIT

Langflow

AI Agents · AI Development

155,319

Build, test, and deploy AI agents and RAG workflows visually with native API and MCP server export.

View details
90
Repo Health
85
Technical
65
Dependency
Built with
Python 69%
TypeScript 22%
Updated 1 weeks ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers