Package category
Security
Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.
514 packages2 comparisons
Packages compared
514 packages
| Package | Weekly downloads | 12-month change | 52 weeks | Gzip | Last release | Module | Types | Categories |
|---|---|---|---|---|---|---|---|---|
| csrf primary logic behind csrf tokens | 806.2k | +17% | - | 7 years ago 3.1.0 | - | None | Security | |
| @openzeppelin/contracts Secure Smart Contract library for Solidity | 760.9k | - | - | - | 6 months ago 5.6.1 | - | None | Blockchain and Web3, Security |
| eslint-plugin-no-unsanitized ESLint rule to disallow unsanitized code | 702.6k | +162% | - | 7 months ago 4.1.5 | CommonJS | None | Linting and formatting, Security | |
| @tracetail/js TraceTail JavaScript SDK for browser fingerprinting | 695k | - | - | - | 3 months ago 2.3.15 | ESM only | Bundled | Security |
| content-security-policy-parser Parse Content Security Policy directives. | 544.1k | +303% | - | 2 years ago 0.6.0 | ESM + CommonJS | Bundled | Security | |
| npm-audit-report Given a response from the npm security api, render it into a variety of security reports | 508.7k | -17% | - | 4 months ago 8.0.0 | CommonJS | None | Security | |
| @hpke/core A Hybrid Public Key Encryption (HPKE) core module for various JavaScript runtimes | 504.1k | - | - | - | 6 months ago 1.9.0 | ESM + CommonJS | Bundled | Cryptography and hashing, Security |
| @hpke/common A Hybrid Public Key Encryption (HPKE) internal-use common module for @hpke family modules. | 503.3k | - | - | - | 6 months ago 1.10.1 | ESM + CommonJS | Bundled | Cryptography and hashing, Security |
| snyk snyk library and cli utility | 496.4k | +10% | - | 1 day ago 1.1307.4 | - | None | Security | |
| content-security-policy-builder Build Content Security Policy directives. | 483.5k | +24% | - | 1 year ago 2.3.0 | ESM + CommonJS | Bundled | Security | |
| @hpke/chacha20poly1305 A Hybrid Public Key Encryption (HPKE) module extension for ChaCha20/Poly1305 | 447.5k | - | - | - | 6 months ago 1.8.0 | ESM + CommonJS | Bundled | Cryptography and hashing, Security |
| recheck The trustworthy ReDoS checker | 424.9k | +597% | - | 1 year ago 4.5.0 | CommonJS | Bundled | Security | |
| helmet-csp Content Security Policy middleware | 416.3k | +5% | - | 2 months ago 4.1.0 | CommonJS | Bundled | Security | |
| @sanity/webhook Toolkit for dealing with GROQ-powered webhooks delivered by Sanity.io | 376.8k | - | - | - | 2 years ago 4.0.4 | ESM + CommonJS | Bundled | Security |
| hsts HTTP Strict Transport Security middleware. | 368.7k | +1% | - | 7 years ago 2.2.0 | - | None | Security | |
| x-xss-protection Middleware to disable the X-XSS-Protection header | 353k | -1% | - | 6 years ago 2.0.0 | CommonJS | Bundled | Security | |
| audit-ci Audits NPM, Yarn, and PNPM projects in CI environments | 351k | +87% | - | 2 years ago 7.1.0 | ESM + CommonJS | Bundled | Security | |
| remix-utils This package contains simple utility functions to use with [React Router](https://reactrouter.com/). | 349.1k | +90% | - | 3 months ago 10.0.0 | ESM only | Bundled | React, Utility libraries | |
| hide-powered-by Middleware to remove the X-Powered-By header | 348.2k | -2% | - | 7 years ago 1.1.0 | CommonJS | Bundled | Security, HTTP servers and web frameworks | |
| dont-sniff-mimetype Middleware to prevent mimetype from being sniffed | 347.7k | -8% | - | 7 years ago 1.1.0 | CommonJS | Bundled | Security, HTTP servers and web frameworks | |
| referrer-policy Middleware to set the Referrer-Policy HTTP header | 340.5k | -9% | - | 7 years ago 1.2.0 | CommonJS | Bundled | Security, HTTP servers and web frameworks | |
| feature-policy Middleware to set the Feature-Policy HTTP header | 336.5k | +7% | - | 5 years ago 0.6.0 | CommonJS | Bundled | Security, HTTP servers and web frameworks | |
| helmet-crossdomain Set the X-Permitted-Cross-Domain-Policies header in Express apps | 324.4k | +1% | - | 7 years ago 0.5.0 | CommonJS | Bundled | HTTP servers and web frameworks, Security | |
| csurf CSRF token middleware | 322.6k | -11% | - | 6 years ago 1.11.0 | - | None | HTTP servers and web frameworks, Security | |
| @tracetail/vue Vue SDK for TraceTail browser fingerprinting - over 99.5% accuracy | 306k | - | - | - | 3 months ago 2.3.15 | ESM + CommonJS | Bundled | Vue, Security |
| @anthropic-ai/sandbox-runtime Anthropic Sandbox Runtime (ASRT) - A general-purpose tool for wrapping security boundaries around arbitrary processes | 287.6k | - | - | - | 6 days ago 0.0.77 | ESM only | Bundled | Security |
| lockfile-lint A CLI to lint a lockfile for security policies | 284.4k | +71% | - | 1 month ago 5.0.1 | - | None | Linting and formatting, Security | |
| @openfga/sdk JavaScript and Node.js SDK for OpenFGA | 266.8k | - | - | - | 1 month ago 0.9.7 | CommonJS | Bundled | Security |
| ae-cvss-calculator A CVSS vector modeling and score calculation implementation for all CVSS versions by {metæffekt}. | 265.4k | +158% | - | 2 months ago 1.0.13 | CommonJS | Bundled | Security | |
| cors-gate Gate requests based on CORS data. | 253.4k | +15% | - | - 1.1.3 | CommonJS | None | Security | |
| @jetbrains/websandbox A sandbox library for runnung javascript inside HTML5 sandboxed iframe | 253.1k | - | - | - | 1 month ago 1.4.1 | CommonJS | Bundled | Security |
| clamscan Use Node JS to scan files on your server with ClamAV's clamscan/clamdscan binary or via TCP to a remote server or local UNIX Domain socket. This is especially useful for scanning uploaded files provided by un-trusted sources. | 244k | +69% | - | 1 year ago 2.4.0 | CommonJS | None | Security, Node.js utilities | |
| koa-helmet Security header middleware collection for koa | 242.7k | +21% | - | 8 months ago 9.0.0 | ESM + CommonJS | Bundled | Security | |
| @hpke/dhkem-x25519 A Hybrid Public Key Encryption (HPKE) module extension for X25519 | 234.4k | - | - | - | 6 months ago 1.8.0 | ESM + CommonJS | Bundled | Cryptography and hashing, Security |
| @tracetail/angular Angular SDK for TraceTail browser fingerprinting - over 99.5% accuracy | 227.3k | - | - | - | 3 months ago 2.3.15 | ESM + CommonJS | Bundled | Angular, Security |
| @sap/xssec XS Advanced Container Security API for node.js | 226.8k | - | - | - | 1 month ago 4.15.0 | CommonJS | Bundled | Security |
| vue-meta Manage HTML metadata in Vue.js components with ssr support | 221.3k | -21% | - | 6 years ago 2.4.0 | ESM + CommonJS | Bundled | Vue, Static site generators and meta-frameworks | |
| express-mongo-sanitize Sanitize your express payload to prevent MongoDB operator injection. | 202.9k | +10% | - | 4 years ago 2.2.0 | CommonJS | Bundled | HTTP servers and web frameworks, Security | |
| eslint-plugin-no-secrets An eslint rule that searches for potential secrets/keys in code | 201.6k | +76% | - | 6 months ago 2.3.3 | CommonJS | Bundled | Linting and formatting, Security | |
| ses Hardened JavaScript for Fearless Cooperation | 200.5k | +41% | - | 1 month ago 2.3.0 | ESM + CommonJS | Bundled | Security | |
| hpke-js A Hybrid Public Key Encryption (HPKE) module for various JavaScript runtimes | 200.3k | +308% | - | 6 months ago 1.8.0 | ESM + CommonJS | Bundled | Cryptography and hashing, Security | |
| @hpke/dhkem-x448 A Hybrid Public Key Encryption (HPKE) module extension for X448 | 200.2k | - | - | - | 6 months ago 1.8.0 | ESM + CommonJS | Bundled | Cryptography and hashing, Security |
| request-filtering-agent An http(s).Agent implementation that block request Private IP address. | 181.2k | +105% | - | 2 months ago 3.2.1 | ESM only | Bundled | Security | |
| hpp Express middleware to protect against HTTP Parameter Pollution attacks | 173.8k | +91% | - | 6 years ago 0.2.3 | CommonJS | None | Security, HTTP servers and web frameworks | |
| @escape.tech/graphql-armor Dead-simple, yet highly customizable security middleware for Apollo GraphQL servers shield | 170.2k | - | - | - | 8 months ago 3.2.0 | ESM + CommonJS | Bundled | GraphQL, Security |
| @aparajita/capacitor-biometric-auth Provides access to the native biometric auth & device security APIs for Capacitor 7+ apps | 161.2k | - | - | - | 7 months ago 10.0.0 | ESM + CommonJS | Bundled | Authentication and authorisation, Security |
| frameguard Middleware to set X-Frame-Options headers | 160.3k | +25% | - | 5 years ago 4.0.0 | CommonJS | Bundled | Security | |
| @n8n/expression-runtime Secure, isolated expression evaluation runtime for n8n | 154.3k | - | - | - | 9 days ago 0.31.1 | ESM + CommonJS | Bundled | Security, CLI tools and terminal utilities |
| @endo/immutable-arraybuffer Immutable ArrayBuffer (the shim!) | 152.6k | - | - | - | 1 month ago 2.0.0 | ESM only | Bundled | Polyfills and shims, Security |
| better-npm-audit Reshape into a better npm audit for the community and encourage more people to include security audit into their process. | 150k | +38% | - | 2 years ago 3.11.0 | CommonJS | None | Security, Node.js utilities |
12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.
- csrfprimary logic behind csrf tokens
- @openzeppelin/contractsSecure Smart Contract library for Solidity
- eslint-plugin-no-unsanitizedESLint rule to disallow unsanitized code
- @tracetail/jsTraceTail JavaScript SDK for browser fingerprinting
- content-security-policy-parserParse Content Security Policy directives.
- npm-audit-reportGiven a response from the npm security api, render it into a variety of security reports
- @hpke/coreA Hybrid Public Key Encryption (HPKE) core module for various JavaScript runtimes
- @hpke/commonA Hybrid Public Key Encryption (HPKE) internal-use common module for @hpke family modules.
- snyksnyk library and cli utility
- content-security-policy-builderBuild Content Security Policy directives.
- @hpke/chacha20poly1305A Hybrid Public Key Encryption (HPKE) module extension for ChaCha20/Poly1305
- recheckThe trustworthy ReDoS checker
- helmet-cspContent Security Policy middleware
- @sanity/webhookToolkit for dealing with GROQ-powered webhooks delivered by Sanity.io
- hstsHTTP Strict Transport Security middleware.
- x-xss-protectionMiddleware to disable the X-XSS-Protection header
- audit-ciAudits NPM, Yarn, and PNPM projects in CI environments
- remix-utilsThis package contains simple utility functions to use with [React Router](https://reactrouter.com/).
- hide-powered-byMiddleware to remove the X-Powered-By header
- dont-sniff-mimetypeMiddleware to prevent mimetype from being sniffed
- referrer-policyMiddleware to set the Referrer-Policy HTTP header
- feature-policyMiddleware to set the Feature-Policy HTTP header
- helmet-crossdomainSet the X-Permitted-Cross-Domain-Policies header in Express apps
- csurfCSRF token middleware
- @tracetail/vueVue SDK for TraceTail browser fingerprinting - over 99.5% accuracy
- @anthropic-ai/sandbox-runtimeAnthropic Sandbox Runtime (ASRT) - A general-purpose tool for wrapping security boundaries around arbitrary processes
- lockfile-lintA CLI to lint a lockfile for security policies
- @openfga/sdkJavaScript and Node.js SDK for OpenFGA
- ae-cvss-calculatorA CVSS vector modeling and score calculation implementation for all CVSS versions by {metæffekt}.
- cors-gateGate requests based on CORS data.
- @jetbrains/websandboxA sandbox library for runnung javascript inside HTML5 sandboxed iframe
- clamscanUse Node JS to scan files on your server with ClamAV's clamscan/clamdscan binary or via TCP to a remote server or local UNIX Domain socket. This is especially useful for scanning uploaded files provided by un-trusted sources.
- koa-helmetSecurity header middleware collection for koa
- @hpke/dhkem-x25519A Hybrid Public Key Encryption (HPKE) module extension for X25519
- @tracetail/angularAngular SDK for TraceTail browser fingerprinting - over 99.5% accuracy
- @sap/xssecXS Advanced Container Security API for node.js
- vue-metaManage HTML metadata in Vue.js components with ssr support
- express-mongo-sanitizeSanitize your express payload to prevent MongoDB operator injection.
- eslint-plugin-no-secretsAn eslint rule that searches for potential secrets/keys in code
- sesHardened JavaScript for Fearless Cooperation
- hpke-jsA Hybrid Public Key Encryption (HPKE) module for various JavaScript runtimes
- @hpke/dhkem-x448A Hybrid Public Key Encryption (HPKE) module extension for X448
- request-filtering-agentAn http(s).Agent implementation that block request Private IP address.
- hppExpress middleware to protect against HTTP Parameter Pollution attacks
- @escape.tech/graphql-armorDead-simple, yet highly customizable security middleware for Apollo GraphQL servers shield
- @aparajita/capacitor-biometric-authProvides access to the native biometric auth & device security APIs for Capacitor 7+ apps
- frameguardMiddleware to set X-Frame-Options headers
- @n8n/expression-runtimeSecure, isolated expression evaluation runtime for n8n
- @endo/immutable-arraybufferImmutable ArrayBuffer (the shim!)
- better-npm-auditReshape into a better npm audit for the community and encourage more people to include security audit into their process.