Skip to content
JS
Package category

Security

Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.

514 packages2 comparisons

Packages compared

514 packages
PackageWeekly downloads12-month change52 weeksGzipLast releaseModuleTypesCategories
csrf
primary logic behind csrf tokens
806.2k+17%-7 years ago
3.1.0
-NoneSecurity
@openzeppelin/contracts
Secure Smart Contract library for Solidity
760.9k---6 months ago
5.6.1
-NoneBlockchain and Web3, Security
eslint-plugin-no-unsanitized
ESLint rule to disallow unsanitized code
702.6k+162%-7 months ago
4.1.5
CommonJSNoneLinting and formatting, Security
@tracetail/js
TraceTail JavaScript SDK for browser fingerprinting
695k---3 months ago
2.3.15
ESM onlyBundledSecurity
content-security-policy-parser
Parse Content Security Policy directives.
544.1k+303%-2 years ago
0.6.0
ESM + CommonJSBundledSecurity
npm-audit-report
Given a response from the npm security api, render it into a variety of security reports
508.7k-17%-4 months ago
8.0.0
CommonJSNoneSecurity
@hpke/core
A Hybrid Public Key Encryption (HPKE) core module for various JavaScript runtimes
504.1k---6 months ago
1.9.0
ESM + CommonJSBundledCryptography and hashing, Security
@hpke/common
A Hybrid Public Key Encryption (HPKE) internal-use common module for @hpke family modules.
503.3k---6 months ago
1.10.1
ESM + CommonJSBundledCryptography and hashing, Security
snyk
snyk library and cli utility
496.4k+10%-1 day ago
1.1307.4
-NoneSecurity
content-security-policy-builder
Build Content Security Policy directives.
483.5k+24%-1 year ago
2.3.0
ESM + CommonJSBundledSecurity
@hpke/chacha20poly1305
A Hybrid Public Key Encryption (HPKE) module extension for ChaCha20/Poly1305
447.5k---6 months ago
1.8.0
ESM + CommonJSBundledCryptography and hashing, Security
recheck
The trustworthy ReDoS checker
424.9k+597%-1 year ago
4.5.0
CommonJSBundledSecurity
helmet-csp
Content Security Policy middleware
416.3k+5%-2 months ago
4.1.0
CommonJSBundledSecurity
@sanity/webhook
Toolkit for dealing with GROQ-powered webhooks delivered by Sanity.io
376.8k---2 years ago
4.0.4
ESM + CommonJSBundledSecurity
hsts
HTTP Strict Transport Security middleware.
368.7k+1%-7 years ago
2.2.0
-NoneSecurity
x-xss-protection
Middleware to disable the X-XSS-Protection header
353k-1%-6 years ago
2.0.0
CommonJSBundledSecurity
audit-ci
Audits NPM, Yarn, and PNPM projects in CI environments
351k+87%-2 years ago
7.1.0
ESM + CommonJSBundledSecurity
remix-utils
This package contains simple utility functions to use with [React Router](https://reactrouter.com/).
349.1k+90%-3 months ago
10.0.0
ESM onlyBundledReact, Utility libraries
hide-powered-by
Middleware to remove the X-Powered-By header
348.2k-2%-7 years ago
1.1.0
CommonJSBundledSecurity, HTTP servers and web frameworks
dont-sniff-mimetype
Middleware to prevent mimetype from being sniffed
347.7k-8%-7 years ago
1.1.0
CommonJSBundledSecurity, HTTP servers and web frameworks
referrer-policy
Middleware to set the Referrer-Policy HTTP header
340.5k-9%-7 years ago
1.2.0
CommonJSBundledSecurity, HTTP servers and web frameworks
feature-policy
Middleware to set the Feature-Policy HTTP header
336.5k+7%-5 years ago
0.6.0
CommonJSBundledSecurity, HTTP servers and web frameworks
helmet-crossdomain
Set the X-Permitted-Cross-Domain-Policies header in Express apps
324.4k+1%-7 years ago
0.5.0
CommonJSBundledHTTP servers and web frameworks, Security
csurf
CSRF token middleware
322.6k-11%-6 years ago
1.11.0
-NoneHTTP servers and web frameworks, Security
@tracetail/vue
Vue SDK for TraceTail browser fingerprinting - over 99.5% accuracy
306k---3 months ago
2.3.15
ESM + CommonJSBundledVue, Security
@anthropic-ai/sandbox-runtime
Anthropic Sandbox Runtime (ASRT) - A general-purpose tool for wrapping security boundaries around arbitrary processes
287.6k---6 days ago
0.0.77
ESM onlyBundledSecurity
lockfile-lint
A CLI to lint a lockfile for security policies
284.4k+71%-1 month ago
5.0.1
-NoneLinting and formatting, Security
@openfga/sdk
JavaScript and Node.js SDK for OpenFGA
266.8k---1 month ago
0.9.7
CommonJSBundledSecurity
ae-cvss-calculator
A CVSS vector modeling and score calculation implementation for all CVSS versions by {metæffekt}.
265.4k+158%-2 months ago
1.0.13
CommonJSBundledSecurity
cors-gate
Gate requests based on CORS data.
253.4k+15%--
1.1.3
CommonJSNoneSecurity
@jetbrains/websandbox
A sandbox library for runnung javascript inside HTML5 sandboxed iframe
253.1k---1 month ago
1.4.1
CommonJSBundledSecurity
clamscan
Use Node JS to scan files on your server with ClamAV's clamscan/clamdscan binary or via TCP to a remote server or local UNIX Domain socket. This is especially useful for scanning uploaded files provided by un-trusted sources.
244k+69%-1 year ago
2.4.0
CommonJSNoneSecurity, Node.js utilities
koa-helmet
Security header middleware collection for koa
242.7k+21%-8 months ago
9.0.0
ESM + CommonJSBundledSecurity
@hpke/dhkem-x25519
A Hybrid Public Key Encryption (HPKE) module extension for X25519
234.4k---6 months ago
1.8.0
ESM + CommonJSBundledCryptography and hashing, Security
@tracetail/angular
Angular SDK for TraceTail browser fingerprinting - over 99.5% accuracy
227.3k---3 months ago
2.3.15
ESM + CommonJSBundledAngular, Security
@sap/xssec
XS Advanced Container Security API for node.js
226.8k---1 month ago
4.15.0
CommonJSBundledSecurity
vue-meta
Manage HTML metadata in Vue.js components with ssr support
221.3k-21%-6 years ago
2.4.0
ESM + CommonJSBundledVue, Static site generators and meta-frameworks
express-mongo-sanitize
Sanitize your express payload to prevent MongoDB operator injection.
202.9k+10%-4 years ago
2.2.0
CommonJSBundledHTTP servers and web frameworks, Security
eslint-plugin-no-secrets
An eslint rule that searches for potential secrets/keys in code
201.6k+76%-6 months ago
2.3.3
CommonJSBundledLinting and formatting, Security
ses
Hardened JavaScript for Fearless Cooperation
200.5k+41%-1 month ago
2.3.0
ESM + CommonJSBundledSecurity
hpke-js
A Hybrid Public Key Encryption (HPKE) module for various JavaScript runtimes
200.3k+308%-6 months ago
1.8.0
ESM + CommonJSBundledCryptography and hashing, Security
@hpke/dhkem-x448
A Hybrid Public Key Encryption (HPKE) module extension for X448
200.2k---6 months ago
1.8.0
ESM + CommonJSBundledCryptography and hashing, Security
request-filtering-agent
An http(s).Agent implementation that block request Private IP address.
181.2k+105%-2 months ago
3.2.1
ESM onlyBundledSecurity
hpp
Express middleware to protect against HTTP Parameter Pollution attacks
173.8k+91%-6 years ago
0.2.3
CommonJSNoneSecurity, HTTP servers and web frameworks
@escape.tech/graphql-armor
Dead-simple, yet highly customizable security middleware for Apollo GraphQL servers shield
170.2k---8 months ago
3.2.0
ESM + CommonJSBundledGraphQL, Security
@aparajita/capacitor-biometric-auth
Provides access to the native biometric auth & device security APIs for Capacitor 7+ apps
161.2k---7 months ago
10.0.0
ESM + CommonJSBundledAuthentication and authorisation, Security
frameguard
Middleware to set X-Frame-Options headers
160.3k+25%-5 years ago
4.0.0
CommonJSBundledSecurity
@n8n/expression-runtime
Secure, isolated expression evaluation runtime for n8n
154.3k---9 days ago
0.31.1
ESM + CommonJSBundledSecurity, CLI tools and terminal utilities
@endo/immutable-arraybuffer
Immutable ArrayBuffer (the shim!)
152.6k---1 month ago
2.0.0
ESM onlyBundledPolyfills and shims, Security
better-npm-audit
Reshape into a better npm audit for the community and encourage more people to include security audit into their process.
150k+38%-2 years ago
3.11.0
CommonJSNoneSecurity, Node.js utilities

12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.

  • csrfprimary logic behind csrf tokens
  • @openzeppelin/contractsSecure Smart Contract library for Solidity
  • eslint-plugin-no-unsanitizedESLint rule to disallow unsanitized code
  • @tracetail/jsTraceTail JavaScript SDK for browser fingerprinting
  • content-security-policy-parserParse Content Security Policy directives.
  • npm-audit-reportGiven a response from the npm security api, render it into a variety of security reports
  • @hpke/coreA Hybrid Public Key Encryption (HPKE) core module for various JavaScript runtimes
  • @hpke/commonA Hybrid Public Key Encryption (HPKE) internal-use common module for @hpke family modules.
  • snyksnyk library and cli utility
  • content-security-policy-builderBuild Content Security Policy directives.
  • @hpke/chacha20poly1305A Hybrid Public Key Encryption (HPKE) module extension for ChaCha20/Poly1305
  • recheckThe trustworthy ReDoS checker
  • helmet-cspContent Security Policy middleware
  • @sanity/webhookToolkit for dealing with GROQ-powered webhooks delivered by Sanity.io
  • hstsHTTP Strict Transport Security middleware.
  • x-xss-protectionMiddleware to disable the X-XSS-Protection header
  • audit-ciAudits NPM, Yarn, and PNPM projects in CI environments
  • remix-utilsThis package contains simple utility functions to use with [React Router](https://reactrouter.com/).
  • hide-powered-byMiddleware to remove the X-Powered-By header
  • dont-sniff-mimetypeMiddleware to prevent mimetype from being sniffed
  • referrer-policyMiddleware to set the Referrer-Policy HTTP header
  • feature-policyMiddleware to set the Feature-Policy HTTP header
  • helmet-crossdomainSet the X-Permitted-Cross-Domain-Policies header in Express apps
  • csurfCSRF token middleware
  • @tracetail/vueVue SDK for TraceTail browser fingerprinting - over 99.5% accuracy
  • @anthropic-ai/sandbox-runtimeAnthropic Sandbox Runtime (ASRT) - A general-purpose tool for wrapping security boundaries around arbitrary processes
  • lockfile-lintA CLI to lint a lockfile for security policies
  • @openfga/sdkJavaScript and Node.js SDK for OpenFGA
  • ae-cvss-calculatorA CVSS vector modeling and score calculation implementation for all CVSS versions by {metæffekt}.
  • cors-gateGate requests based on CORS data.
  • @jetbrains/websandboxA sandbox library for runnung javascript inside HTML5 sandboxed iframe
  • clamscanUse Node JS to scan files on your server with ClamAV's clamscan/clamdscan binary or via TCP to a remote server or local UNIX Domain socket. This is especially useful for scanning uploaded files provided by un-trusted sources.
  • koa-helmetSecurity header middleware collection for koa
  • @hpke/dhkem-x25519A Hybrid Public Key Encryption (HPKE) module extension for X25519
  • @tracetail/angularAngular SDK for TraceTail browser fingerprinting - over 99.5% accuracy
  • @sap/xssecXS Advanced Container Security API for node.js
  • vue-metaManage HTML metadata in Vue.js components with ssr support
  • express-mongo-sanitizeSanitize your express payload to prevent MongoDB operator injection.
  • eslint-plugin-no-secretsAn eslint rule that searches for potential secrets/keys in code
  • sesHardened JavaScript for Fearless Cooperation
  • hpke-jsA Hybrid Public Key Encryption (HPKE) module for various JavaScript runtimes
  • @hpke/dhkem-x448A Hybrid Public Key Encryption (HPKE) module extension for X448
  • request-filtering-agentAn http(s).Agent implementation that block request Private IP address.
  • hppExpress middleware to protect against HTTP Parameter Pollution attacks
  • @escape.tech/graphql-armorDead-simple, yet highly customizable security middleware for Apollo GraphQL servers shield
  • @aparajita/capacitor-biometric-authProvides access to the native biometric auth & device security APIs for Capacitor 7+ apps
  • frameguardMiddleware to set X-Frame-Options headers
  • @n8n/expression-runtimeSecure, isolated expression evaluation runtime for n8n
  • @endo/immutable-arraybufferImmutable ArrayBuffer (the shim!)
  • better-npm-auditReshape into a better npm audit for the community and encourage more people to include security audit into their process.