Package category
Security
Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.
514 packages2 comparisons
Packages compared
514 packages
| Package | Weekly downloads | 12-month change | 52 weeks | Gzip | Last release | Module | Types | Categories |
|---|---|---|---|---|---|---|---|---|
| safe-buffer Safer Node.js Buffer API | 237.9m | +68% | - | 6 years ago 5.2.1 | CommonJS | Bundled | Security | |
| escape-html Escape string for use in HTML | 89.4m | +99% | - | 11 years ago 1.0.3 | - | None | Security | |
| cors Node.js CORS middleware | 58m | +194% | - | 8 months ago 2.8.6 | CommonJS | None | Security, HTTP servers and web frameworks | |
| dompurify DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It runs as JavaScript and works in all modern browsers, as well as in Node.js (via jsdom). DOMPurify is written by security people who have vast background in web a | 45.3m | +303% | - | 1 day ago 3.4.16 | ESM + CommonJS | Bundled | Security, Image processing | |
| express-rate-limit Basic IP rate-limiting middleware for Express. Use to limit repeated requests to public APIs and/or endpoints such as password reset. | 45.1m | +514% | - | 27 days ago 8.7.0 | ESM + CommonJS | Bundled | Security, HTTP servers and web frameworks | |
| micromark-util-sanitize-uri micromark utility to sanitize urls | 41.4m | +232% | - | 1 year ago 2.0.1 | ESM only | Bundled | Security | |
| ssri Standard Subresource Integrity library -- parses, serializes, generates, and verifies integrity metadata according to the SRI spec. | 35.7m | +15% | - | 4 months ago 14.0.0 | CommonJS | None | Security | |
| @nodable/entities Entity parser for XML, HTML, External entites with security and NCR control | 29.2m | - | - | 2 months ago 3.0.0 | ESM only | Bundled | Security | |
| micromark-extension-gfm-tagfilter micromark extension to support GFM tagfilter | 28.8m | +293% | - | 3 years ago 2.0.0 | ESM only | Bundled | Markdown, Parsers and serialisers | |
| secure-json-parse JSON parse with prototype poisoning protection | 26.2m | +197% | - | 11 months ago 4.1.0 | CommonJS | Bundled | Security | |
| validator String validation and sanitization | 18.4m | +39% | - | 5 months ago 13.15.35 | CommonJS | None | Schema validation, Security | |
| is-unsafe Zero-dependency, DOM-free, pure predicate for detecting unsafe strings across HTML, XML, SVG, SQL, SHELL, and REGEX contexts | 15.4m | - | - | 1 month ago 2.0.2 | ESM + CommonJS | Bundled | Security | |
| helmet help secure Express/Connect apps with various HTTP headers | 10.6m | +153% | - | 2 months ago 8.3.0 | ESM + CommonJS | Bundled | Security | |
| escape-goat Escape a string for use in HTML or the inverse | 10.3m | +53% | - | 5 years ago 4.0.0 | ESM only | None | Security | |
| filenamify Convert a string to a valid safe filename | 8.8m | +60% | - | 27 days ago 7.0.3 | ESM only | Bundled | Security | |
| tuf-js JavaScript implementation of The Update Framework (TUF) | 8.3m | +39% | - | 3 months ago 6.0.0 | CommonJS | Bundled | Security | |
| hast-util-sanitize hast utility to sanitize nodes | 8.2m | +615% | - | 1 year ago 5.0.2 | ESM only | Bundled | Security | |
| sanitize-html Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis | 7.9m | +133% | - | 1 month ago 2.17.7 | CommonJS | None | Security | |
| rehype-sanitize rehype plugin to sanitize HTML | 7.6m | +1016% | - | 3 years ago 6.0.0 | ESM only | Bundled | Markdown, Security | |
| sanitize-filename Sanitize a string for use as a filename | 6.9m | +169% | - | 6 months ago 1.6.4 | CommonJS | Bundled | Security | |
| super-regex Make a regular expression time out if it takes too long to execute | 5.6m | +294% | - | 10 months ago 1.1.0 | ESM only | Bundled | Security | |
| function-timeout Make a synchronous function have a timeout | 5.6m | +318% | - | 2 years ago 1.0.2 | ESM only | Bundled | Security | |
| ultrahtml A 1.75kB library for enhancing `html`. `ultrahtml` has zero dependencies and is compatible with any JavaScript runtime. | 5.5m | +292% | - | 2 months ago 1.7.0 | ESM only | Bundled | Security | |
| launder A sanitize module for the people. Built for ApostropheCMS. | 5.2m | +19754% | - | 4 months ago 1.7.1 | CommonJS | None | Security | |
| corser A highly configurable, middleware compatible implementation of CORS. | 5.1m | +49% | - | 10 years ago 2.0.1 | CommonJS | None | Security, HTTP servers and web frameworks | |
| sql-escaper 🛡️ Faster SQL escape and format for JavaScript (Node.js, Bun, and Deno). | 4.8m | - | - | 11 days ago 1.5.2 | ESM + CommonJS | Bundled | Security, TypeScript tooling | |
| rehype-harden A security-focused rehype plugin that filters URLs based on allowed prefixes | 4.3m | +7542% | - | 7 months ago 1.1.8 | ESM only | Bundled | Security, Markdown | |
| xss Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist | 4.2m | +51% | - | 2 years ago 1.0.15 | CommonJS | Bundled | Security | |
| cssfilter Sanitize untrusted CSS with a configuration specified by a Whitelist. 根据白名单过滤CSS | 4.1m | +55% | - | 2 years ago 0.0.11 | CommonJS | None | Security | |
| isomorphic-dompurify Makes it possible to use DOMPurify on server and client in the same way. | 4m | +227% | - | 6 days ago 4.3.0 | ESM + CommonJS | Bundled | Security, Static site generators and meta-frameworks | |
| eslint-plugin-security Security rules for eslint | 3.4m | +207% | - | 3 months ago 4.0.1 | CommonJS | None | Linting and formatting, Security | |
| csp_evaluator Evaluate Content Security Policies for a wide range of bypasses and weaknesses | 3m | +136% | - | 4 months ago 1.1.8 | CommonJS | Bundled | Security | |
| otplib TypeScript-first library for TOTP and HOTP with multi-runtime and plugin support | 2.4m | +275% | - | 1 month ago 13.5.0 | ESM + CommonJS | Bundled | Security, Node.js utilities | |
| to-valid-identifier Convert a string to a valid JavaScript identifier | 2.4m | +11880% | - | 11 months ago 1.0.0 | ESM only | Bundled | Security | |
| rate-limiter-flexible Node.js atomic and non-atomic counters, rate limiting tools, protection from DoS and brute-force attacks at scale | 2m | +95% | - | 7 days ago 11.2.1 | CommonJS | Bundled | Security, HTTP servers and web frameworks | |
| has-cors Detects support for Cross-Origin Resource Sharing | 1.8m | -7% | - | 11 years ago 1.1.0 | CommonJS | None | Security | |
| @fastify/helmet Important security headers for Fastify | 1.6m | +389% | - | 1 month ago 13.1.1 | - | - | Security | |
| is-safe-filename Check if a filename is safe to use in a path join operation | 1.6m | - | - | 7 months ago 0.1.1 | - | - | Security | |
| iron-session Secure, stateless, and cookie-based session library for JavaScript | 1.4m | +294% | - | 25 days ago 9.0.1 | - | - | Security | |
| oxlint-plugin-react-doctor React Doctor rules for oxlint. | 1.2m | - | - | 13 days ago 0.9.14 | - | - | React, Linting and formatting | |
| express-validator Express middleware for the validator module. | 1.1m | +14% | - | 5 months ago 7.3.2 | CommonJS | Bundled | Schema validation, HTTP servers and web frameworks | |
| react-doctor Your agent writes bad React. This catches it | 1.1m | - | - | 13 days ago 0.9.14 | ESM only | Bundled | React, Linting and formatting | |
| quote-js-string Escape a string and wrap it in quotes to produce a safe JavaScript string literal | 1.1m | - | - | 2 months ago 0.1.0 | ESM only | Bundled | Security | |
| zxcvbn realistic password strength estimation | 1.1m | +61% | - | 9 years ago 4.4.2 | CommonJS | None | Authentication and authorisation, Security | |
| @koa/cors Cross-Origin Resource Sharing(CORS) for koa | 1m | - | - | - | 2 years ago 5.0.0 | CommonJS | None | Security |
| @zxcvbn-ts/core Realistic password strength estimation written in typescript | 984.6k | - | - | - | 1 month ago 4.2.0 | ESM + CommonJS | Bundled | Authentication and authorisation, Security |
| @microsoft/mxc-sdk TypeScript SDK for MXC (Microsoft eXecution Containers) | 938.4k | - | - | - | 1 month ago 0.8.0 | ESM only | Bundled | Security |
| strict-url-sanitise Strict URL sanitization with security-focused validation | 908.7k | +922% | - | 1 year ago 0.0.1 | ESM only | Bundled | Security | |
| vm2 vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. | 820.9k | -5% | - | 16 days ago 3.12.2 | CommonJS | Bundled | Security | |
| safe-content-frame Secure iframe rendering for untrusted content using SafeContentFrame | 809k | - | - | 6 days ago 0.0.31 | ESM only | Bundled | Security, UI component libraries |
12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.
- safe-bufferSafer Node.js Buffer API
- escape-htmlEscape string for use in HTML
- corsNode.js CORS middleware
- dompurifyDOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It runs as JavaScript and works in all modern browsers, as well as in Node.js (via jsdom). DOMPurify is written by security people who have vast background in web a
- express-rate-limitBasic IP rate-limiting middleware for Express. Use to limit repeated requests to public APIs and/or endpoints such as password reset.
- micromark-util-sanitize-urimicromark utility to sanitize urls
- ssriStandard Subresource Integrity library -- parses, serializes, generates, and verifies integrity metadata according to the SRI spec.
- @nodable/entitiesEntity parser for XML, HTML, External entites with security and NCR control
- micromark-extension-gfm-tagfiltermicromark extension to support GFM tagfilter
- secure-json-parseJSON parse with prototype poisoning protection
- validatorString validation and sanitization
- is-unsafeZero-dependency, DOM-free, pure predicate for detecting unsafe strings across HTML, XML, SVG, SQL, SHELL, and REGEX contexts
- helmethelp secure Express/Connect apps with various HTTP headers
- escape-goatEscape a string for use in HTML or the inverse
- filenamifyConvert a string to a valid safe filename
- tuf-jsJavaScript implementation of The Update Framework (TUF)
- hast-util-sanitizehast utility to sanitize nodes
- sanitize-htmlClean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis
- rehype-sanitizerehype plugin to sanitize HTML
- sanitize-filenameSanitize a string for use as a filename
- super-regexMake a regular expression time out if it takes too long to execute
- function-timeoutMake a synchronous function have a timeout
- ultrahtmlA 1.75kB library for enhancing `html`. `ultrahtml` has zero dependencies and is compatible with any JavaScript runtime.
- launderA sanitize module for the people. Built for ApostropheCMS.
- corserA highly configurable, middleware compatible implementation of CORS.
- sql-escaper🛡️ Faster SQL escape and format for JavaScript (Node.js, Bun, and Deno).
- rehype-hardenA security-focused rehype plugin that filters URLs based on allowed prefixes
- xssSanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist
- cssfilterSanitize untrusted CSS with a configuration specified by a Whitelist. 根据白名单过滤CSS
- isomorphic-dompurifyMakes it possible to use DOMPurify on server and client in the same way.
- eslint-plugin-securitySecurity rules for eslint
- csp_evaluatorEvaluate Content Security Policies for a wide range of bypasses and weaknesses
- otplibTypeScript-first library for TOTP and HOTP with multi-runtime and plugin support
- to-valid-identifierConvert a string to a valid JavaScript identifier
- rate-limiter-flexibleNode.js atomic and non-atomic counters, rate limiting tools, protection from DoS and brute-force attacks at scale
- has-corsDetects support for Cross-Origin Resource Sharing
- @fastify/helmetImportant security headers for Fastify
- is-safe-filenameCheck if a filename is safe to use in a path join operation
- iron-sessionSecure, stateless, and cookie-based session library for JavaScript
- oxlint-plugin-react-doctorReact Doctor rules for oxlint.
- express-validatorExpress middleware for the validator module.
- react-doctorYour agent writes bad React. This catches it
- quote-js-stringEscape a string and wrap it in quotes to produce a safe JavaScript string literal
- zxcvbnrealistic password strength estimation
- @koa/corsCross-Origin Resource Sharing(CORS) for koa
- @zxcvbn-ts/coreRealistic password strength estimation written in typescript
- @microsoft/mxc-sdkTypeScript SDK for MXC (Microsoft eXecution Containers)
- strict-url-sanitiseStrict URL sanitization with security-focused validation
- vm2vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules.
- safe-content-frameSecure iframe rendering for untrusted content using SafeContentFrame