Skip to content
JS
Package category

Security

Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.

514 packages2 comparisons

Packages compared

514 packages
PackageWeekly downloads12-month change52 weeksGzipLast releaseModuleTypesCategories
@nodesecure/js-x-ray
JavaScript AST XRay analysis
1.8k---7 days ago
16.1.0
ESM onlyBundledSecurity
eslint-plugin-nestjs-security
ESLint plugin for NestJS security — detects missing auth guards, missing validation pipes, unthrottled routes, and exposed private fields.
1.8k--20 days ago
3.1.3
CommonJSBundledLinting and formatting, Security
rollup-plugin-sri
Add subresource integrity tags to all your html files 🔒
1.8k+7%-5 years ago
1.3.4
ESM + CommonJSBundledBundler plugins and loaders, Security
pnpm-policy
pnpm supply-chain policy for npm maintainers — derive minimumReleaseAge exemptions and build permissions from what you publish
1.7k--8 days ago
0.6.0
ESM + CommonJSBundledBuild tools, Security
@phc/argon2
Node.JS Argon2 password hashing algorithm following the PHC string format
1.7k---8 years ago
1.0.9
CommonJSNoneCryptography and hashing, Security
@authress/sdk
Client SDK for Authress authorization as a service. Provides managed authorization api to secure service resources including user data.
1.7k---22 days ago
3.2.284
CommonJSBundledSecurity
storage-encryption
Encrypt your client storage (available for TS & JS)
1.7k-38%-5 years ago
1.0.16
CommonJSBundledCryptography and hashing, React
shugoi
Shugoi anti-abuse protection — one-line integration for Node.js
1.7k--1 day ago
0.5.5
ESM + CommonJSBundledSecurity
strip-js
Strips out all JavaScript code from some HTML text
1.7k+63%-8 years ago
1.2.0
CommonJSNoneEmail, Security
btp-guard
BTP v5.4.16 The AI Agent Execution Gateway - Sub-35us In-Process Tool Gating, Autonomous Micro-Escrow & SOC 2 Merkle Receipts
1.7k--6 days ago
5.4.16
ESM onlyBundledCryptography and hashing, Security
ethlint
Linter to identify and fix Style & Security issues in Solidity
1.7k+61%-7 years ago
1.2.5
CommonJSNoneBlockchain and Web3, Security
@zingage/postgres-multi-tenant-ids
PostgreSQL IDs for secure multi-tenant applications
1.7k---1 year ago
3.0.1
ESM onlyBundledDatabase clients and drivers, TypeScript tooling
validata
Type safe data validation and sanitization
1.6k+138%-11 months ago
6.0.4
CommonJSBundledSecurity, Schema validation
npm-audit-helper
Helps you understand your npm audit findings so they're not too overwhelming
1.6k+15%-3 years ago
4.0.1
CommonJSNoneSecurity
v-sanitize
Whitelist-based HTML sanitizer for Vue.js apps.
1.6k+11%-2 years ago
0.0.14
CommonJSBundledSecurity, Vue
circle-ir
High-performance Static Application Security Testing (SAST) library for detecting security vulnerabilities through taint analysis
1.6k--today
4.9.26
ESM + CommonJSBundledSecurity
@lehcode/soakp
Secure OpenAI Key Proxy (SOAKP) facilitates secure usage of the OpenAI API key through a proxy-like application.
1.6k---3 years ago
1.1.5
ESM + CommonJSBundledSecurity
evm-kms-signer
AWS/GCP KMS-based Ethereum signer for viem with enterprise-grade security. Sign transactions and messages using keys stored in AWS or GCP KMS without exposing private keys.
1.5k--2 months ago
2.0.4
ESM + CommonJSBundledBlockchain and Web3, Cloud SDKs
react-secure-link
A TypeScript compatible, zero dependency React component to avoid security exploits when opening a link in a new tab.
1.5k-25%--
3.2.0
CommonJSBundledReact, Security
secure-filters
Anti-XSS filters for security
1.5k+41%-9 years ago
1.1.0
CommonJSNoneSecurity
gina
MVC framework for Node.js and Bun with built-in HTTP/2, multi-bundle architecture, and scope-based data isolation — no Express dependency
1.5k+247%-3 days ago
0.6.32
ESM + CommonJSBundledDatabase clients and drivers, Security
envsitter
Safely inspect and match .env secrets without exposing values
1.5k--8 months ago
0.0.4
ESM onlyBundledConfiguration, Node.js utilities
fullcourtdefense-cli
Full Court Defense CLI — security scanning for AI agents from your terminal
1.5k--today
1.35.8
CommonJSBundledCLI tools and terminal utilities, Security
supply-chain-guard
Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros
1.5k--2 days ago
6.2.5
CommonJSBundledSecurity, CLI tools and terminal utilities
@neuralegion/cvss
The Common Vulnerability Scoring System ([CVSS](https://www.first.org/cvss/)) [score](https://www.first.org/cvss/specification-document#1-2-Scoring) calculator and validator library written in [TypeScript](https://www.typescriptlang.org/).
1.4k---1 month ago
1.4.1
ESM + CommonJSBundledTypeScript tooling, Security
@tslite/sanitize
TSLite sanitize — fail-closed AST guard against sandbox-escape surfaces (constructor/prototype/__proto__, dangerous globals) + own-only runtime member access. DEFENSE IN DEPTH, not a security boundary (see SECURITY.md).
1.4k---4 days ago
1.0.1
ESM + CommonJSBundledSecurity
loopback-component-passport
LoopBack passport integration to support third party logins and account linking
1.4k-19%-6 years ago
3.12.0
CommonJSNoneSecurity
@enclave-vm/ast
A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules
1.4k---1 month ago
2.15.2
ESM + CommonJSBundledSecurity
auth-vir
Auth made easy and secure via JWT cookies, CSRF tokens, and password hashing helpers.
1.4k+94%-28 days ago
6.0.0
ESM onlyBundledAuthentication and authorisation, Security
ajv-sanitizer
String sanitization with JSON-Schema using Ajv
1.4k-41%-4 years ago
1.2.1
CommonJSNoneSchema validation, Security
@lazy-cjk/str-util-trim
Trim whitespace and special characters from strings with customizable options
1.4k---13 days ago
1.0.7
ESM + CommonJSBundledSecurity
@cyberstrike-io/cyberstrike
The first open-source AI agent built for offensive security. Autonomous pentesting from your terminal.
1.4k---1 month ago
1.1.16
-NoneSecurity, CLI tools and terminal utilities
depcruise
🚫 Placeholder to prevent dependency confusion.
1.4k+85%-1 year ago
1.0.0
CommonJSNoneSecurity
@b12k/gitleaks
The missing NPM wrapper for Gitleaks
1.4k---1 day ago
8.30.1-v.48
ESM onlyNoneCLI tools and terminal utilities, Security
coap-oscore
A Node.js implementation of OSCORE (Object Security for Constrained RESTful Environments) protocol, providing end-to-end security for IoT applications and other constrained environments using CBOR Object Signing and Encryption.
1.3k-1%-3 months ago
2.2.3
CommonJSBundledSecurity
create-fastify-app
A Fastify application generator
1.3k+264%--
2.1.6
CommonJSNoneDatabase clients and drivers, Security
jsfuzz
Coverage Guided Javascript Fuzzer
1.3k+91%-5 years ago
1.0.15
CommonJSBundledSecurity
yarn-osv-audit
Audit Yarn v1 lockfiles against the OSV vulnerability database
1.3k--4 months ago
0.1.8
ESM onlyNoneSecurity
cs-devtest
Automatic Husky + Gitleaks + SonarQube setup for any JS/TS project
1.3k--1 month ago
1.2.9
CommonJSNoneLinting and formatting, TypeScript tooling
@exortek/express-mongo-sanitize
Express middleware for NoSQL injection prevention — sanitizes request data
1.2k---1 month ago
3.0.1
ESM + CommonJSBundledSecurity, HTTP servers and web frameworks
minixhr
super simpel and small cross-browser xhr
1.2k-81%-8 years ago
4.0.0
CommonJSNoneSecurity, HTTP clients
gulp-nsp
A gulp module that runs Node Security check
1.2k+11%-8 years ago
3.0.1
CommonJSNoneSecurity
@twin.org/vault-connector-hashicorp
HashiCorp Vault connector for transit cryptography and KV secret workflows
1.2k---9 days ago
0.10.0
ESM onlyBundledBlockchain and Web3, Security
strip-html
strip html streamingly
1.2k+202%-11 years ago
1.0.2
CommonJSNoneSecurity
@cedar-policy/mcp-schema-generator-wasm
WASM bindings for cedar-policy-mcp-schema-generator, exposing SchemaGenerator to JavaScript/TypeScript.
1.2k---1 day ago
0.6.1
CommonJSBundledSecurity
credential
Easy password hashing and verification in Node. Protects against brute force, rainbow tables, and timing attacks.
1.2k+17%-9 years ago
2.0.0
CommonJSNoneCryptography and hashing, Security
elysia-xss
A plugin for Elysia.js that provides XSS (Cross-Site Scripting) protection by sanitizing request body data.
1.2k+756%-8 months ago
1.0.4
ESM + CommonJSBundledSecurity
isolated-function
Run JavaScript from AI agents, plugins, and workflows in a separate Node.js process with strict safety limits.
1.2k+233%-3 days ago
0.2.8
CommonJSBundledSecurity
ai-sdk-heal
Heal broken Vercel AI SDK message arrays before they hit the provider. Fixes orphaned tool calls, missing reasoning signatures, invalid tool names, and other provider rejections.
1.1k--3 months ago
0.2.0
ESM onlyBundledCloud SDKs, Security
agent-jail
Portable filesystem sandbox for spawning untrusted subprocesses. One static binary, picks the strongest backend available (uid switch on POSIX, Landlock on Linux 5.13+, or both layered).
1.1k--10 days ago
0.5.0
CommonJSBundledSecurity

12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.

  • @nodesecure/js-x-rayJavaScript AST XRay analysis
  • eslint-plugin-nestjs-securityESLint plugin for NestJS security — detects missing auth guards, missing validation pipes, unthrottled routes, and exposed private fields.
  • rollup-plugin-sriAdd subresource integrity tags to all your html files 🔒
  • pnpm-policypnpm supply-chain policy for npm maintainers — derive minimumReleaseAge exemptions and build permissions from what you publish
  • @phc/argon2Node.JS Argon2 password hashing algorithm following the PHC string format
  • @authress/sdkClient SDK for Authress authorization as a service. Provides managed authorization api to secure service resources including user data.
  • storage-encryptionEncrypt your client storage (available for TS & JS)
  • shugoiShugoi anti-abuse protection — one-line integration for Node.js
  • strip-jsStrips out all JavaScript code from some HTML text
  • btp-guardBTP v5.4.16 The AI Agent Execution Gateway - Sub-35us In-Process Tool Gating, Autonomous Micro-Escrow & SOC 2 Merkle Receipts
  • ethlintLinter to identify and fix Style & Security issues in Solidity
  • @zingage/postgres-multi-tenant-idsPostgreSQL IDs for secure multi-tenant applications
  • validataType safe data validation and sanitization
  • npm-audit-helperHelps you understand your npm audit findings so they're not too overwhelming
  • v-sanitizeWhitelist-based HTML sanitizer for Vue.js apps.
  • circle-irHigh-performance Static Application Security Testing (SAST) library for detecting security vulnerabilities through taint analysis
  • @lehcode/soakpSecure OpenAI Key Proxy (SOAKP) facilitates secure usage of the OpenAI API key through a proxy-like application.
  • evm-kms-signerAWS/GCP KMS-based Ethereum signer for viem with enterprise-grade security. Sign transactions and messages using keys stored in AWS or GCP KMS without exposing private keys.
  • react-secure-linkA TypeScript compatible, zero dependency React component to avoid security exploits when opening a link in a new tab.
  • secure-filtersAnti-XSS filters for security
  • ginaMVC framework for Node.js and Bun with built-in HTTP/2, multi-bundle architecture, and scope-based data isolation — no Express dependency
  • envsitterSafely inspect and match .env secrets without exposing values
  • fullcourtdefense-cliFull Court Defense CLI — security scanning for AI agents from your terminal
  • supply-chain-guardOpen-source supply-chain security scanner for npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 350+ threat indicators acros
  • @neuralegion/cvssThe Common Vulnerability Scoring System ([CVSS](https://www.first.org/cvss/)) [score](https://www.first.org/cvss/specification-document#1-2-Scoring) calculator and validator library written in [TypeScript](https://www.typescriptlang.org/).
  • @tslite/sanitizeTSLite sanitize — fail-closed AST guard against sandbox-escape surfaces (constructor/prototype/__proto__, dangerous globals) + own-only runtime member access. DEFENSE IN DEPTH, not a security boundary (see SECURITY.md).
  • loopback-component-passportLoopBack passport integration to support third party logins and account linking
  • @enclave-vm/astA production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules
  • auth-virAuth made easy and secure via JWT cookies, CSRF tokens, and password hashing helpers.
  • ajv-sanitizerString sanitization with JSON-Schema using Ajv
  • @lazy-cjk/str-util-trimTrim whitespace and special characters from strings with customizable options
  • @cyberstrike-io/cyberstrikeThe first open-source AI agent built for offensive security. Autonomous pentesting from your terminal.
  • depcruise🚫 Placeholder to prevent dependency confusion.
  • @b12k/gitleaksThe missing NPM wrapper for Gitleaks
  • coap-oscoreA Node.js implementation of OSCORE (Object Security for Constrained RESTful Environments) protocol, providing end-to-end security for IoT applications and other constrained environments using CBOR Object Signing and Encryption.
  • create-fastify-appA Fastify application generator
  • jsfuzzCoverage Guided Javascript Fuzzer
  • yarn-osv-auditAudit Yarn v1 lockfiles against the OSV vulnerability database
  • cs-devtestAutomatic Husky + Gitleaks + SonarQube setup for any JS/TS project
  • @exortek/express-mongo-sanitizeExpress middleware for NoSQL injection prevention — sanitizes request data
  • minixhrsuper simpel and small cross-browser xhr
  • gulp-nspA gulp module that runs Node Security check
  • @twin.org/vault-connector-hashicorpHashiCorp Vault connector for transit cryptography and KV secret workflows
  • strip-htmlstrip html streamingly
  • @cedar-policy/mcp-schema-generator-wasmWASM bindings for cedar-policy-mcp-schema-generator, exposing SchemaGenerator to JavaScript/TypeScript.
  • credentialEasy password hashing and verification in Node. Protects against brute force, rainbow tables, and timing attacks.
  • elysia-xssA plugin for Elysia.js that provides XSS (Cross-Site Scripting) protection by sanitizing request body data.
  • isolated-functionRun JavaScript from AI agents, plugins, and workflows in a separate Node.js process with strict safety limits.
  • ai-sdk-healHeal broken Vercel AI SDK message arrays before they hit the provider. Fixes orphaned tool calls, missing reasoning signatures, invalid tool names, and other provider rejections.
  • agent-jailPortable filesystem sandbox for spawning untrusted subprocesses. One static binary, picks the strongest backend available (uid switch on POSIX, Landlock on Linux 5.13+, or both layered).