Skip to content
JS
Package category

Security

Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.

514 packages2 comparisons

Packages compared

514 packages
PackageWeekly downloads12-month change52 weeksGzipLast releaseModuleTypesCategories
retire
Retire is a tool for detecting use of vulnerable libraries
146.9k+70%-1 month ago
5.7.0
CommonJSBundledSecurity
@endo/cache-map
bounded-size caches having WeakMap-compatible methods
146.2k---1 year ago
1.1.0
ESM onlyBundledCaching, Security
harden-react-markdown
A security-focused wrapper for react-markdown that filters URLs based on allowed prefixes
143.2k-11%-7 months ago
1.1.8
CommonJSBundledMarkdown, React
dns-prefetch-control
Middleware to set X-DNS-Prefetch-Control header.
137.9k+13%-7 years ago
0.3.0
CommonJSBundledSecurity, HTTP servers and web frameworks
csrf-csrf
A utility package to help implement stateless CSRF protection using the Double Submit Cookie Pattern in express.
137.6k+180%-1 year ago
4.0.3
ESM + CommonJSBundledHTTP servers and web frameworks, Security
ienoopen
Middleware to set `X-Download-Options` header for IE8 security
130k+17%-6 years ago
1.1.1
CommonJSBundledSecurity
expect-ct
Middleware to set the Expect-CT header
126k+21%-6 years ago
1.0.0
CommonJSBundledSecurity
csrf-sync
A utility package to help implement stateful CSRF protection using the Synchroniser Token Pattern in express.
122.1k+137%-1 year ago
4.2.1
ESM + CommonJSBundledHTTP servers and web frameworks, Security
nuxt-security
🛡️ Security Module for Nuxt based on HTTP Headers and Middleware
118.6k+57%-4 months ago
2.6.0
ESM onlyBundledSecurity, Vue
xss-filters
Secure XSS Filters - Just sufficient output filtering to prevent XSS!
117.5k+34%-10 years ago
1.2.7
CommonJSNoneSecurity
vue-dompurify-html
Safe replacement for the v-html directive
116.8k+42%-1 year ago
5.3.0
ESM + CommonJSBundledSecurity, Vue
csp-header
Content-Security-Policy header generator
114.8k+211%-21 days ago
6.4.0
ESM + CommonJSBundledSecurity
@tinyhttp/cors
CORS middleware for modern Node.js
113.6k---2 years ago
2.0.1
ESM onlyBundledSecurity
sql-escape-string
Simple SQL string escape.
109.3k+117%-8 years ago
1.1.0
CommonJSNoneSecurity
sri-toolbox
Subresource Integrity tools
106.6k-7%-11 years ago
0.2.0
CommonJSNoneSecurity
local-web-server
A lean, modular web server for rapid full-stack development
97.3k-12%-2 years ago
5.4.0
ESM onlyNoneSecurity
tor-proxy-agent
A lightweight Node.js wrapper for routing HTTP(S) traffic through Tor, including optional ControlPort circuit rotation.
96.2k--7 months ago
0.1.1
ESM onlyNoneSecurity
angular-auth-oidc-client
Angular Lib for OpenID Connect & OAuth2
95.4k+12%-3 days ago
22.0.1
ESM onlyBundledSecurity, Angular
ember-cli-sri
SRI generation for Ember CLI
93.6k-3%-10 years ago
2.1.1
-NoneSecurity
@brandonblack/musig
JS implementation of MuSig. 1-dependency MuSig key aggregation, tweaking, and signing.
92.4k---3 years ago
0.0.1-alpha.1
ESM + CommonJSBundledCryptography and hashing, Security
@cdxgen/safer-exec
OS-level sandboxing with tracing, auditing, crypto tracing (CBOM), and learning mode for arbitrary binaries.
91k---today
1.0.1
ESM onlyNoneSecurity, Cryptography and hashing
altcha
Privacy-first CAPTCHA widget, compliant with global regulations (GDPR/HIPAA/CCPA/LGDP/DPDPA/PIPL) and WCAG accessible. No tracking, self-verifying.
87.8k+384%-5 days ago
3.2.3
ESM + CommonJSBundledSvelte, Security
ssrf-req-filter
Module to prevent SSRF when making requests
87.5k+162%-2 years ago
1.1.1
CommonJSNoneSecurity
@rushstack/eslint-plugin-security
An ESLint plugin providing rules that identify common security vulnerabilities for browser applications, Node.js tools, and Node.js services
82.2k---10 days ago
0.14.3
ESM + CommonJSBundledLinting and formatting, Security
image-size-next
Community-maintained fork of image-size: get dimensions of any image file or buffer. Fixes CVE-2025-71329 and CVE-2025-71330 (DoS via infinite loops).
81.3k--1 month ago
2.1.1
ESM + CommonJSBundledImage processing, Security
secure-web-token
A secure, encrypted, device-bound authentication token library for Node.js — the best alternative to JWT with AES-256-GCM encryption, device fingerprinting, and true logout support.
81.3k--3 months ago
3.0.1
ESM + CommonJSBundledAuthentication and authorisation, Security
supertokens-website
frontend sdk for website to be used for auth solution.
79.8k+184%-1 year ago
20.1.6
CommonJSNoneSecurity, TypeScript tooling
@socketsecurity/bun-security-scanner
Bun security scanner for SocketDev
77.4k---3 days ago
1.1.3
CommonJSBundledSecurity
delivery-intel
Evidence-driven repo intelligence: DORA metrics, forensic signals, vulnerability scan, and delivery verdict for any GitHub repo. One command, no setup.
76k--14 days ago
1.8.1
ESM onlyBundledCLI tools and terminal utilities, Security
schema-inspector
Schema-Inspector is a powerful tool to sanitize and validate JS objects.
73.9k+145%-2 years ago
2.1.0
CommonJSNoneSchema validation, Security
next-secure-headers
Sets secure response headers for Next.js.
71.8k+76%-5 years ago
2.2.0
CommonJSNoneSecurity
@cerbos/core
Common types used by the Cerbos client libraries
69.3k---10 days ago
0.33.1
ESM onlyBundledSecurity, Node.js utilities
nosecone
Protect your Response with secure headers
68.5k+438%-8 days ago
1.13.0
ESM onlyBundledSecurity
@nosecone/next
Protect your Next.js application with secure headers
67.1k---8 days ago
1.13.0
ESM onlyBundledSecurity
owasp-password-strength-test
A password-strength tester based upon the OWASP guidelines for enforcing strong passwords.
63.9k+48%-11 years ago
1.3.0
CommonJSNoneSecurity
nextjs-cors
Nextjs-Cors is a node.js package to provide a middleware that can be used to enable CORS with various options in nextjs applications.
56.2k+2%-10 months ago
2.2.1
ESM + CommonJSBundledSecurity, Static site generators and meta-frameworks
read-env
Transform environment variables into JSON object with sanitized values.
56.1k+10%-6 years ago
2.0.0
ESM + CommonJSBundledConfiguration, Node.js utilities
@cerbos/api
Generated code used by the Cerbos client libraries
55.4k---10 days ago
0.11.1
ESM onlyBundledSecurity, Node.js utilities
eslint-plugin-redos
ESLint plugin for catching ReDoS vulnerability
54.3k+105%-1 year ago
4.5.0
CommonJSNoneLinting and formatting, Security
encrypt-storage
Wrapper for encrypted localStorage and sessionStorage in browser
53.7k+194%-1 month ago
3.0.4
ESM + CommonJSBundledVue, React
@hackbg/miscreant-esm
(ESM port) Misuse resistant symmetric encryption library providing AES-SIV (RFC 5297), AES-PMAC-SIV, and STREAM constructions
52.9k---3 years ago
0.3.2-patch.3
ESM + CommonJSBundledCryptography and hashing, Security
arcjet
Arcjet runtime security SDK — bot protection, rate limiting, prompt injection detection, PII blocking, and WAF for JavaScript and TypeScript apps
52.8k+240%-8 days ago
1.13.0
ESM onlyBundledSecurity
@socketsecurity/socket-patch
CLI tool and schema library for applying security patches to dependencies
50.8k---28 days ago
4.0.0
ESM + CommonJSBundledCLI tools and terminal utilities, Security
@next-safe/middleware
Strict Content-Security-Policy (CSP) for Next.js with composable middleware
49.1k---4 years ago
0.10.0
ESM + CommonJSBundledSecurity, Static site generators and meta-frameworks
@arcjet/next
Arcjet runtime security SDK for Next.js — bot protection, rate limiting, prompt injection detection, PII blocking, and WAF
47.9k---8 days ago
1.13.0
ESM onlyBundledSecurity
yarn-audit-fix
The missing `yarn audit fix`
45.6k-30%-22 days ago
11.0.4
ESM onlyBundledSecurity
sanitize-s3-objectkey
Remove and replace illegal characters in S3 Object Keys
44.2k+190%-7 years ago
0.0.1
CommonJSNoneCloud SDKs, Security
@varlock/vite-integration
Vite plugin to use varlock for .env file loading - adds validation, type-safety, and extra security features
42.6k---13 days ago
1.5.2
ESM onlyBundledConfiguration, Schema validation
npm-audit-resolver
Aids humans and automation in managing npm audit results
42k+0%-3 years ago
3.0.0-RC.0
CommonJSBundledSecurity
cross-keychain
Cross-platform secret storage
41.8k+89101%-11 months ago
1.1.0
ESM + CommonJSBundledSecurity

12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.

  • retireRetire is a tool for detecting use of vulnerable libraries
  • @endo/cache-mapbounded-size caches having WeakMap-compatible methods
  • harden-react-markdownA security-focused wrapper for react-markdown that filters URLs based on allowed prefixes
  • dns-prefetch-controlMiddleware to set X-DNS-Prefetch-Control header.
  • csrf-csrfA utility package to help implement stateless CSRF protection using the Double Submit Cookie Pattern in express.
  • ienoopenMiddleware to set `X-Download-Options` header for IE8 security
  • expect-ctMiddleware to set the Expect-CT header
  • csrf-syncA utility package to help implement stateful CSRF protection using the Synchroniser Token Pattern in express.
  • nuxt-security🛡️ Security Module for Nuxt based on HTTP Headers and Middleware
  • xss-filtersSecure XSS Filters - Just sufficient output filtering to prevent XSS!
  • vue-dompurify-htmlSafe replacement for the v-html directive
  • csp-headerContent-Security-Policy header generator
  • @tinyhttp/corsCORS middleware for modern Node.js
  • sql-escape-stringSimple SQL string escape.
  • sri-toolboxSubresource Integrity tools
  • local-web-serverA lean, modular web server for rapid full-stack development
  • tor-proxy-agentA lightweight Node.js wrapper for routing HTTP(S) traffic through Tor, including optional ControlPort circuit rotation.
  • angular-auth-oidc-clientAngular Lib for OpenID Connect & OAuth2
  • ember-cli-sriSRI generation for Ember CLI
  • @brandonblack/musigJS implementation of MuSig. 1-dependency MuSig key aggregation, tweaking, and signing.
  • @cdxgen/safer-execOS-level sandboxing with tracing, auditing, crypto tracing (CBOM), and learning mode for arbitrary binaries.
  • altchaPrivacy-first CAPTCHA widget, compliant with global regulations (GDPR/HIPAA/CCPA/LGDP/DPDPA/PIPL) and WCAG accessible. No tracking, self-verifying.
  • ssrf-req-filterModule to prevent SSRF when making requests
  • @rushstack/eslint-plugin-securityAn ESLint plugin providing rules that identify common security vulnerabilities for browser applications, Node.js tools, and Node.js services
  • image-size-nextCommunity-maintained fork of image-size: get dimensions of any image file or buffer. Fixes CVE-2025-71329 and CVE-2025-71330 (DoS via infinite loops).
  • secure-web-tokenA secure, encrypted, device-bound authentication token library for Node.js — the best alternative to JWT with AES-256-GCM encryption, device fingerprinting, and true logout support.
  • supertokens-websitefrontend sdk for website to be used for auth solution.
  • @socketsecurity/bun-security-scannerBun security scanner for SocketDev
  • delivery-intelEvidence-driven repo intelligence: DORA metrics, forensic signals, vulnerability scan, and delivery verdict for any GitHub repo. One command, no setup.
  • schema-inspectorSchema-Inspector is a powerful tool to sanitize and validate JS objects.
  • next-secure-headersSets secure response headers for Next.js.
  • @cerbos/coreCommon types used by the Cerbos client libraries
  • noseconeProtect your Response with secure headers
  • @nosecone/nextProtect your Next.js application with secure headers
  • owasp-password-strength-testA password-strength tester based upon the OWASP guidelines for enforcing strong passwords.
  • nextjs-corsNextjs-Cors is a node.js package to provide a middleware that can be used to enable CORS with various options in nextjs applications.
  • read-envTransform environment variables into JSON object with sanitized values.
  • @cerbos/apiGenerated code used by the Cerbos client libraries
  • eslint-plugin-redosESLint plugin for catching ReDoS vulnerability
  • encrypt-storageWrapper for encrypted localStorage and sessionStorage in browser
  • @hackbg/miscreant-esm(ESM port) Misuse resistant symmetric encryption library providing AES-SIV (RFC 5297), AES-PMAC-SIV, and STREAM constructions
  • arcjetArcjet runtime security SDK — bot protection, rate limiting, prompt injection detection, PII blocking, and WAF for JavaScript and TypeScript apps
  • @socketsecurity/socket-patchCLI tool and schema library for applying security patches to dependencies
  • @next-safe/middlewareStrict Content-Security-Policy (CSP) for Next.js with composable middleware
  • @arcjet/nextArcjet runtime security SDK for Next.js — bot protection, rate limiting, prompt injection detection, PII blocking, and WAF
  • yarn-audit-fixThe missing `yarn audit fix`
  • sanitize-s3-objectkeyRemove and replace illegal characters in S3 Object Keys
  • @varlock/vite-integrationVite plugin to use varlock for .env file loading - adds validation, type-safety, and extra security features
  • npm-audit-resolverAids humans and automation in managing npm audit results
  • cross-keychainCross-platform secret storage