Package category
Security
Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.
514 packages2 comparisons
Packages compared
514 packages
| Package | Weekly downloads | 12-month change | 52 weeks | Gzip | Last release | Module | Types | Categories |
|---|---|---|---|---|---|---|---|---|
| @nodesecure/js-x-ray JavaScript AST XRay analysis | 1.8k | - | - | - | 7 days ago 16.1.0 | ESM only | Bundled | Security |
| eslint-plugin-nestjs-security ESLint plugin for NestJS security — detects missing auth guards, missing validation pipes, unthrottled routes, and exposed private fields. | 1.8k | - | - | 20 days ago 3.1.3 | CommonJS | Bundled | Linting and formatting, Security | |
| rollup-plugin-sri Add subresource integrity tags to all your html files 🔒 | 1.8k | +7% | - | 5 years ago 1.3.4 | ESM + CommonJS | Bundled | Bundler plugins and loaders, Security | |
| pnpm-policy pnpm supply-chain policy for npm maintainers — derive minimumReleaseAge exemptions and build permissions from what you publish | 1.7k | - | - | 8 days ago 0.6.0 | ESM + CommonJS | Bundled | Build tools, Security | |
| @phc/argon2 Node.JS Argon2 password hashing algorithm following the PHC string format | 1.7k | - | - | - | 8 years ago 1.0.9 | CommonJS | None | Cryptography and hashing, Security |
| @authress/sdk Client SDK for Authress authorization as a service. Provides managed authorization api to secure service resources including user data. | 1.7k | - | - | - | 22 days ago 3.2.284 | CommonJS | Bundled | Security |
| storage-encryption Encrypt your client storage (available for TS & JS) | 1.7k | -38% | - | 5 years ago 1.0.16 | CommonJS | Bundled | Cryptography and hashing, React | |
| shugoi Shugoi anti-abuse protection — one-line integration for Node.js | 1.7k | - | - | 1 day ago 0.5.5 | ESM + CommonJS | Bundled | Security | |
| strip-js Strips out all JavaScript code from some HTML text | 1.7k | +63% | - | 8 years ago 1.2.0 | CommonJS | None | Email, Security | |
| btp-guard BTP v5.4.16 The AI Agent Execution Gateway - Sub-35us In-Process Tool Gating, Autonomous Micro-Escrow & SOC 2 Merkle Receipts | 1.7k | - | - | 6 days ago 5.4.16 | ESM only | Bundled | Cryptography and hashing, Security | |
| ethlint Linter to identify and fix Style & Security issues in Solidity | 1.7k | +61% | - | 7 years ago 1.2.5 | CommonJS | None | Blockchain and Web3, Security | |
| @zingage/postgres-multi-tenant-ids PostgreSQL IDs for secure multi-tenant applications | 1.7k | - | - | - | 1 year ago 3.0.1 | ESM only | Bundled | Database clients and drivers, TypeScript tooling |
| validata Type safe data validation and sanitization | 1.6k | +138% | - | 11 months ago 6.0.4 | CommonJS | Bundled | Security, Schema validation | |
| npm-audit-helper Helps you understand your npm audit findings so they're not too overwhelming | 1.6k | +15% | - | 3 years ago 4.0.1 | CommonJS | None | Security | |
| v-sanitize Whitelist-based HTML sanitizer for Vue.js apps. | 1.6k | +11% | - | 2 years ago 0.0.14 | CommonJS | Bundled | Security, Vue | |
| circle-ir High-performance Static Application Security Testing (SAST) library for detecting security vulnerabilities through taint analysis | 1.6k | - | - | today 4.9.26 | ESM + CommonJS | Bundled | Security | |
| @lehcode/soakp Secure OpenAI Key Proxy (SOAKP) facilitates secure usage of the OpenAI API key through a proxy-like application. | 1.6k | - | - | - | 3 years ago 1.1.5 | ESM + CommonJS | Bundled | Security |
| evm-kms-signer AWS/GCP KMS-based Ethereum signer for viem with enterprise-grade security. Sign transactions and messages using keys stored in AWS or GCP KMS without exposing private keys. | 1.5k | - | - | 2 months ago 2.0.4 | ESM + CommonJS | Bundled | Blockchain and Web3, Cloud SDKs | |
| react-secure-link A TypeScript compatible, zero dependency React component to avoid security exploits when opening a link in a new tab. | 1.5k | -25% | - | - 3.2.0 | CommonJS | Bundled | React, Security | |
| secure-filters Anti-XSS filters for security | 1.5k | +41% | - | 9 years ago 1.1.0 | CommonJS | None | Security | |
| gina MVC framework for Node.js and Bun with built-in HTTP/2, multi-bundle architecture, and scope-based data isolation — no Express dependency | 1.5k | +247% | - | 3 days ago 0.6.32 | ESM + CommonJS | Bundled | Database clients and drivers, Security | |
| envsitter Safely inspect and match .env secrets without exposing values | 1.5k | - | - | 8 months ago 0.0.4 | ESM only | Bundled | Configuration, Node.js utilities | |
| fullcourtdefense-cli Full Court Defense CLI — security scanning for AI agents from your terminal | 1.5k | - | - | today 1.35.8 | CommonJS | Bundled | CLI tools and terminal utilities, Security | |
| supply-chain-guard Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros | 1.5k | - | - | 2 days ago 6.2.5 | CommonJS | Bundled | Security, CLI tools and terminal utilities | |
| @neuralegion/cvss The Common Vulnerability Scoring System ([CVSS](https://www.first.org/cvss/)) [score](https://www.first.org/cvss/specification-document#1-2-Scoring) calculator and validator library written in [TypeScript](https://www.typescriptlang.org/). | 1.4k | - | - | - | 1 month ago 1.4.1 | ESM + CommonJS | Bundled | TypeScript tooling, Security |
| @tslite/sanitize TSLite sanitize — fail-closed AST guard against sandbox-escape surfaces (constructor/prototype/__proto__, dangerous globals) + own-only runtime member access. DEFENSE IN DEPTH, not a security boundary (see SECURITY.md). | 1.4k | - | - | - | 4 days ago 1.0.1 | ESM + CommonJS | Bundled | Security |
| loopback-component-passport LoopBack passport integration to support third party logins and account linking | 1.4k | -19% | - | 6 years ago 3.12.0 | CommonJS | None | Security | |
| @enclave-vm/ast A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules | 1.4k | - | - | - | 1 month ago 2.15.2 | ESM + CommonJS | Bundled | Security |
| auth-vir Auth made easy and secure via JWT cookies, CSRF tokens, and password hashing helpers. | 1.4k | +94% | - | 28 days ago 6.0.0 | ESM only | Bundled | Authentication and authorisation, Security | |
| ajv-sanitizer String sanitization with JSON-Schema using Ajv | 1.4k | -41% | - | 4 years ago 1.2.1 | CommonJS | None | Schema validation, Security | |
| @lazy-cjk/str-util-trim Trim whitespace and special characters from strings with customizable options | 1.4k | - | - | - | 13 days ago 1.0.7 | ESM + CommonJS | Bundled | Security |
| @cyberstrike-io/cyberstrike The first open-source AI agent built for offensive security. Autonomous pentesting from your terminal. | 1.4k | - | - | - | 1 month ago 1.1.16 | - | None | Security, CLI tools and terminal utilities |
| depcruise 🚫 Placeholder to prevent dependency confusion. | 1.4k | +85% | - | 1 year ago 1.0.0 | CommonJS | None | Security | |
| @b12k/gitleaks The missing NPM wrapper for Gitleaks | 1.4k | - | - | - | 1 day ago 8.30.1-v.48 | ESM only | None | CLI tools and terminal utilities, Security |
| coap-oscore A Node.js implementation of OSCORE (Object Security for Constrained RESTful Environments) protocol, providing end-to-end security for IoT applications and other constrained environments using CBOR Object Signing and Encryption. | 1.3k | -1% | - | 3 months ago 2.2.3 | CommonJS | Bundled | Security | |
| create-fastify-app A Fastify application generator | 1.3k | +264% | - | - 2.1.6 | CommonJS | None | Database clients and drivers, Security | |
| jsfuzz Coverage Guided Javascript Fuzzer | 1.3k | +91% | - | 5 years ago 1.0.15 | CommonJS | Bundled | Security | |
| yarn-osv-audit Audit Yarn v1 lockfiles against the OSV vulnerability database | 1.3k | - | - | 4 months ago 0.1.8 | ESM only | None | Security | |
| cs-devtest Automatic Husky + Gitleaks + SonarQube setup for any JS/TS project | 1.3k | - | - | 1 month ago 1.2.9 | CommonJS | None | Linting and formatting, TypeScript tooling | |
| @exortek/express-mongo-sanitize Express middleware for NoSQL injection prevention — sanitizes request data | 1.2k | - | - | - | 1 month ago 3.0.1 | ESM + CommonJS | Bundled | Security, HTTP servers and web frameworks |
| minixhr super simpel and small cross-browser xhr | 1.2k | -81% | - | 8 years ago 4.0.0 | CommonJS | None | Security, HTTP clients | |
| gulp-nsp A gulp module that runs Node Security check | 1.2k | +11% | - | 8 years ago 3.0.1 | CommonJS | None | Security | |
| @twin.org/vault-connector-hashicorp HashiCorp Vault connector for transit cryptography and KV secret workflows | 1.2k | - | - | - | 9 days ago 0.10.0 | ESM only | Bundled | Blockchain and Web3, Security |
| strip-html strip html streamingly | 1.2k | +202% | - | 11 years ago 1.0.2 | CommonJS | None | Security | |
| @cedar-policy/mcp-schema-generator-wasm WASM bindings for cedar-policy-mcp-schema-generator, exposing SchemaGenerator to JavaScript/TypeScript. | 1.2k | - | - | - | 1 day ago 0.6.1 | CommonJS | Bundled | Security |
| credential Easy password hashing and verification in Node. Protects against brute force, rainbow tables, and timing attacks. | 1.2k | +17% | - | 9 years ago 2.0.0 | CommonJS | None | Cryptography and hashing, Security | |
| elysia-xss A plugin for Elysia.js that provides XSS (Cross-Site Scripting) protection by sanitizing request body data. | 1.2k | +756% | - | 8 months ago 1.0.4 | ESM + CommonJS | Bundled | Security | |
| isolated-function Run JavaScript from AI agents, plugins, and workflows in a separate Node.js process with strict safety limits. | 1.2k | +233% | - | 3 days ago 0.2.8 | CommonJS | Bundled | Security | |
| ai-sdk-heal Heal broken Vercel AI SDK message arrays before they hit the provider. Fixes orphaned tool calls, missing reasoning signatures, invalid tool names, and other provider rejections. | 1.1k | - | - | 3 months ago 0.2.0 | ESM only | Bundled | Cloud SDKs, Security | |
| agent-jail Portable filesystem sandbox for spawning untrusted subprocesses. One static binary, picks the strongest backend available (uid switch on POSIX, Landlock on Linux 5.13+, or both layered). | 1.1k | - | - | 10 days ago 0.5.0 | CommonJS | Bundled | Security |
12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.
- @nodesecure/js-x-rayJavaScript AST XRay analysis
- eslint-plugin-nestjs-securityESLint plugin for NestJS security — detects missing auth guards, missing validation pipes, unthrottled routes, and exposed private fields.
- rollup-plugin-sriAdd subresource integrity tags to all your html files 🔒
- pnpm-policypnpm supply-chain policy for npm maintainers — derive minimumReleaseAge exemptions and build permissions from what you publish
- @phc/argon2Node.JS Argon2 password hashing algorithm following the PHC string format
- @authress/sdkClient SDK for Authress authorization as a service. Provides managed authorization api to secure service resources including user data.
- storage-encryptionEncrypt your client storage (available for TS & JS)
- shugoiShugoi anti-abuse protection — one-line integration for Node.js
- strip-jsStrips out all JavaScript code from some HTML text
- btp-guardBTP v5.4.16 The AI Agent Execution Gateway - Sub-35us In-Process Tool Gating, Autonomous Micro-Escrow & SOC 2 Merkle Receipts
- ethlintLinter to identify and fix Style & Security issues in Solidity
- @zingage/postgres-multi-tenant-idsPostgreSQL IDs for secure multi-tenant applications
- validataType safe data validation and sanitization
- npm-audit-helperHelps you understand your npm audit findings so they're not too overwhelming
- v-sanitizeWhitelist-based HTML sanitizer for Vue.js apps.
- circle-irHigh-performance Static Application Security Testing (SAST) library for detecting security vulnerabilities through taint analysis
- @lehcode/soakpSecure OpenAI Key Proxy (SOAKP) facilitates secure usage of the OpenAI API key through a proxy-like application.
- evm-kms-signerAWS/GCP KMS-based Ethereum signer for viem with enterprise-grade security. Sign transactions and messages using keys stored in AWS or GCP KMS without exposing private keys.
- react-secure-linkA TypeScript compatible, zero dependency React component to avoid security exploits when opening a link in a new tab.
- secure-filtersAnti-XSS filters for security
- ginaMVC framework for Node.js and Bun with built-in HTTP/2, multi-bundle architecture, and scope-based data isolation — no Express dependency
- envsitterSafely inspect and match .env secrets without exposing values
- fullcourtdefense-cliFull Court Defense CLI — security scanning for AI agents from your terminal
- supply-chain-guardOpen-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros
- @neuralegion/cvssThe Common Vulnerability Scoring System ([CVSS](https://www.first.org/cvss/)) [score](https://www.first.org/cvss/specification-document#1-2-Scoring) calculator and validator library written in [TypeScript](https://www.typescriptlang.org/).
- @tslite/sanitizeTSLite sanitize — fail-closed AST guard against sandbox-escape surfaces (constructor/prototype/__proto__, dangerous globals) + own-only runtime member access. DEFENSE IN DEPTH, not a security boundary (see SECURITY.md).
- loopback-component-passportLoopBack passport integration to support third party logins and account linking
- @enclave-vm/astA production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules
- auth-virAuth made easy and secure via JWT cookies, CSRF tokens, and password hashing helpers.
- ajv-sanitizerString sanitization with JSON-Schema using Ajv
- @lazy-cjk/str-util-trimTrim whitespace and special characters from strings with customizable options
- @cyberstrike-io/cyberstrikeThe first open-source AI agent built for offensive security. Autonomous pentesting from your terminal.
- depcruise🚫 Placeholder to prevent dependency confusion.
- @b12k/gitleaksThe missing NPM wrapper for Gitleaks
- coap-oscoreA Node.js implementation of OSCORE (Object Security for Constrained RESTful Environments) protocol, providing end-to-end security for IoT applications and other constrained environments using CBOR Object Signing and Encryption.
- create-fastify-appA Fastify application generator
- jsfuzzCoverage Guided Javascript Fuzzer
- yarn-osv-auditAudit Yarn v1 lockfiles against the OSV vulnerability database
- cs-devtestAutomatic Husky + Gitleaks + SonarQube setup for any JS/TS project
- @exortek/express-mongo-sanitizeExpress middleware for NoSQL injection prevention — sanitizes request data
- minixhrsuper simpel and small cross-browser xhr
- gulp-nspA gulp module that runs Node Security check
- @twin.org/vault-connector-hashicorpHashiCorp Vault connector for transit cryptography and KV secret workflows
- strip-htmlstrip html streamingly
- @cedar-policy/mcp-schema-generator-wasmWASM bindings for cedar-policy-mcp-schema-generator, exposing SchemaGenerator to JavaScript/TypeScript.
- credentialEasy password hashing and verification in Node. Protects against brute force, rainbow tables, and timing attacks.
- elysia-xssA plugin for Elysia.js that provides XSS (Cross-Site Scripting) protection by sanitizing request body data.
- isolated-functionRun JavaScript from AI agents, plugins, and workflows in a separate Node.js process with strict safety limits.
- ai-sdk-healHeal broken Vercel AI SDK message arrays before they hit the provider. Fixes orphaned tool calls, missing reasoning signatures, invalid tool names, and other provider rejections.
- agent-jailPortable filesystem sandbox for spawning untrusted subprocesses. One static binary, picks the strongest backend available (uid switch on POSIX, Landlock on Linux 5.13+, or both layered).