Package category
Security
Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.
514 packages2 comparisons
Packages compared
514 packages
| Package | Weekly downloads | 12-month change | 52 weeks | Gzip | Last release | Module | Types | Categories |
|---|---|---|---|---|---|---|---|---|
| retire Retire is a tool for detecting use of vulnerable libraries | 146.9k | +70% | - | 1 month ago 5.7.0 | CommonJS | Bundled | Security | |
| @endo/cache-map bounded-size caches having WeakMap-compatible methods | 146.2k | - | - | - | 1 year ago 1.1.0 | ESM only | Bundled | Caching, Security |
| harden-react-markdown A security-focused wrapper for react-markdown that filters URLs based on allowed prefixes | 143.2k | -11% | - | 7 months ago 1.1.8 | CommonJS | Bundled | Markdown, React | |
| dns-prefetch-control Middleware to set X-DNS-Prefetch-Control header. | 137.9k | +13% | - | 7 years ago 0.3.0 | CommonJS | Bundled | Security, HTTP servers and web frameworks | |
| csrf-csrf A utility package to help implement stateless CSRF protection using the Double Submit Cookie Pattern in express. | 137.6k | +180% | - | 1 year ago 4.0.3 | ESM + CommonJS | Bundled | HTTP servers and web frameworks, Security | |
| ienoopen Middleware to set `X-Download-Options` header for IE8 security | 130k | +17% | - | 6 years ago 1.1.1 | CommonJS | Bundled | Security | |
| expect-ct Middleware to set the Expect-CT header | 126k | +21% | - | 6 years ago 1.0.0 | CommonJS | Bundled | Security | |
| csrf-sync A utility package to help implement stateful CSRF protection using the Synchroniser Token Pattern in express. | 122.1k | +137% | - | 1 year ago 4.2.1 | ESM + CommonJS | Bundled | HTTP servers and web frameworks, Security | |
| nuxt-security 🛡️ Security Module for Nuxt based on HTTP Headers and Middleware | 118.6k | +57% | - | 4 months ago 2.6.0 | ESM only | Bundled | Security, Vue | |
| xss-filters Secure XSS Filters - Just sufficient output filtering to prevent XSS! | 117.5k | +34% | - | 10 years ago 1.2.7 | CommonJS | None | Security | |
| vue-dompurify-html Safe replacement for the v-html directive | 116.8k | +42% | - | 1 year ago 5.3.0 | ESM + CommonJS | Bundled | Security, Vue | |
| csp-header Content-Security-Policy header generator | 114.8k | +211% | - | 21 days ago 6.4.0 | ESM + CommonJS | Bundled | Security | |
| @tinyhttp/cors CORS middleware for modern Node.js | 113.6k | - | - | - | 2 years ago 2.0.1 | ESM only | Bundled | Security |
| sql-escape-string Simple SQL string escape. | 109.3k | +117% | - | 8 years ago 1.1.0 | CommonJS | None | Security | |
| sri-toolbox Subresource Integrity tools | 106.6k | -7% | - | 11 years ago 0.2.0 | CommonJS | None | Security | |
| local-web-server A lean, modular web server for rapid full-stack development | 97.3k | -12% | - | 2 years ago 5.4.0 | ESM only | None | Security | |
| tor-proxy-agent A lightweight Node.js wrapper for routing HTTP(S) traffic through Tor, including optional ControlPort circuit rotation. | 96.2k | - | - | 7 months ago 0.1.1 | ESM only | None | Security | |
| angular-auth-oidc-client Angular Lib for OpenID Connect & OAuth2 | 95.4k | +12% | - | 3 days ago 22.0.1 | ESM only | Bundled | Security, Angular | |
| ember-cli-sri SRI generation for Ember CLI | 93.6k | -3% | - | 10 years ago 2.1.1 | - | None | Security | |
| @brandonblack/musig JS implementation of MuSig. 1-dependency MuSig key aggregation, tweaking, and signing. | 92.4k | - | - | - | 3 years ago 0.0.1-alpha.1 | ESM + CommonJS | Bundled | Cryptography and hashing, Security |
| @cdxgen/safer-exec OS-level sandboxing with tracing, auditing, crypto tracing (CBOM), and learning mode for arbitrary binaries. | 91k | - | - | - | today 1.0.1 | ESM only | None | Security, Cryptography and hashing |
| altcha Privacy-first CAPTCHA widget, compliant with global regulations (GDPR/HIPAA/CCPA/LGDP/DPDPA/PIPL) and WCAG accessible. No tracking, self-verifying. | 87.8k | +384% | - | 5 days ago 3.2.3 | ESM + CommonJS | Bundled | Svelte, Security | |
| ssrf-req-filter Module to prevent SSRF when making requests | 87.5k | +162% | - | 2 years ago 1.1.1 | CommonJS | None | Security | |
| @rushstack/eslint-plugin-security An ESLint plugin providing rules that identify common security vulnerabilities for browser applications, Node.js tools, and Node.js services | 82.2k | - | - | - | 10 days ago 0.14.3 | ESM + CommonJS | Bundled | Linting and formatting, Security |
| image-size-next Community-maintained fork of image-size: get dimensions of any image file or buffer. Fixes CVE-2025-71329 and CVE-2025-71330 (DoS via infinite loops). | 81.3k | - | - | 1 month ago 2.1.1 | ESM + CommonJS | Bundled | Image processing, Security | |
| secure-web-token A secure, encrypted, device-bound authentication token library for Node.js — the best alternative to JWT with AES-256-GCM encryption, device fingerprinting, and true logout support. | 81.3k | - | - | 3 months ago 3.0.1 | ESM + CommonJS | Bundled | Authentication and authorisation, Security | |
| supertokens-website frontend sdk for website to be used for auth solution. | 79.8k | +184% | - | 1 year ago 20.1.6 | CommonJS | None | Security, TypeScript tooling | |
| @socketsecurity/bun-security-scanner Bun security scanner for SocketDev | 77.4k | - | - | - | 3 days ago 1.1.3 | CommonJS | Bundled | Security |
| delivery-intel Evidence-driven repo intelligence: DORA metrics, forensic signals, vulnerability scan, and delivery verdict for any GitHub repo. One command, no setup. | 76k | - | - | 14 days ago 1.8.1 | ESM only | Bundled | CLI tools and terminal utilities, Security | |
| schema-inspector Schema-Inspector is a powerful tool to sanitize and validate JS objects. | 73.9k | +145% | - | 2 years ago 2.1.0 | CommonJS | None | Schema validation, Security | |
| next-secure-headers Sets secure response headers for Next.js. | 71.8k | +76% | - | 5 years ago 2.2.0 | CommonJS | None | Security | |
| @cerbos/core Common types used by the Cerbos client libraries | 69.3k | - | - | - | 10 days ago 0.33.1 | ESM only | Bundled | Security, Node.js utilities |
| nosecone Protect your Response with secure headers | 68.5k | +438% | - | 8 days ago 1.13.0 | ESM only | Bundled | Security | |
| @nosecone/next Protect your Next.js application with secure headers | 67.1k | - | - | - | 8 days ago 1.13.0 | ESM only | Bundled | Security |
| owasp-password-strength-test A password-strength tester based upon the OWASP guidelines for enforcing strong passwords. | 63.9k | +48% | - | 11 years ago 1.3.0 | CommonJS | None | Security | |
| nextjs-cors Nextjs-Cors is a node.js package to provide a middleware that can be used to enable CORS with various options in nextjs applications. | 56.2k | +2% | - | 10 months ago 2.2.1 | ESM + CommonJS | Bundled | Security, Static site generators and meta-frameworks | |
| read-env Transform environment variables into JSON object with sanitized values. | 56.1k | +10% | - | 6 years ago 2.0.0 | ESM + CommonJS | Bundled | Configuration, Node.js utilities | |
| @cerbos/api Generated code used by the Cerbos client libraries | 55.4k | - | - | - | 10 days ago 0.11.1 | ESM only | Bundled | Security, Node.js utilities |
| eslint-plugin-redos ESLint plugin for catching ReDoS vulnerability | 54.3k | +105% | - | 1 year ago 4.5.0 | CommonJS | None | Linting and formatting, Security | |
| encrypt-storage Wrapper for encrypted localStorage and sessionStorage in browser | 53.7k | +194% | - | 1 month ago 3.0.4 | ESM + CommonJS | Bundled | Vue, React | |
| @hackbg/miscreant-esm (ESM port) Misuse resistant symmetric encryption library providing AES-SIV (RFC 5297), AES-PMAC-SIV, and STREAM constructions | 52.9k | - | - | - | 3 years ago 0.3.2-patch.3 | ESM + CommonJS | Bundled | Cryptography and hashing, Security |
| arcjet Arcjet runtime security SDK — bot protection, rate limiting, prompt injection detection, PII blocking, and WAF for JavaScript and TypeScript apps | 52.8k | +240% | - | 8 days ago 1.13.0 | ESM only | Bundled | Security | |
| @socketsecurity/socket-patch CLI tool and schema library for applying security patches to dependencies | 50.8k | - | - | - | 28 days ago 4.0.0 | ESM + CommonJS | Bundled | CLI tools and terminal utilities, Security |
| @next-safe/middleware Strict Content-Security-Policy (CSP) for Next.js with composable middleware | 49.1k | - | - | - | 4 years ago 0.10.0 | ESM + CommonJS | Bundled | Security, Static site generators and meta-frameworks |
| @arcjet/next Arcjet runtime security SDK for Next.js — bot protection, rate limiting, prompt injection detection, PII blocking, and WAF | 47.9k | - | - | - | 8 days ago 1.13.0 | ESM only | Bundled | Security |
| yarn-audit-fix The missing `yarn audit fix` | 45.6k | -30% | - | 22 days ago 11.0.4 | ESM only | Bundled | Security | |
| sanitize-s3-objectkey Remove and replace illegal characters in S3 Object Keys | 44.2k | +190% | - | 7 years ago 0.0.1 | CommonJS | None | Cloud SDKs, Security | |
| @varlock/vite-integration Vite plugin to use varlock for .env file loading - adds validation, type-safety, and extra security features | 42.6k | - | - | - | 13 days ago 1.5.2 | ESM only | Bundled | Configuration, Schema validation |
| npm-audit-resolver Aids humans and automation in managing npm audit results | 42k | +0% | - | 3 years ago 3.0.0-RC.0 | CommonJS | Bundled | Security | |
| cross-keychain Cross-platform secret storage | 41.8k | +89101% | - | 11 months ago 1.1.0 | ESM + CommonJS | Bundled | Security |
12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.
- retireRetire is a tool for detecting use of vulnerable libraries
- @endo/cache-mapbounded-size caches having WeakMap-compatible methods
- harden-react-markdownA security-focused wrapper for react-markdown that filters URLs based on allowed prefixes
- dns-prefetch-controlMiddleware to set X-DNS-Prefetch-Control header.
- csrf-csrfA utility package to help implement stateless CSRF protection using the Double Submit Cookie Pattern in express.
- ienoopenMiddleware to set `X-Download-Options` header for IE8 security
- expect-ctMiddleware to set the Expect-CT header
- csrf-syncA utility package to help implement stateful CSRF protection using the Synchroniser Token Pattern in express.
- nuxt-security🛡️ Security Module for Nuxt based on HTTP Headers and Middleware
- xss-filtersSecure XSS Filters - Just sufficient output filtering to prevent XSS!
- vue-dompurify-htmlSafe replacement for the v-html directive
- csp-headerContent-Security-Policy header generator
- @tinyhttp/corsCORS middleware for modern Node.js
- sql-escape-stringSimple SQL string escape.
- sri-toolboxSubresource Integrity tools
- local-web-serverA lean, modular web server for rapid full-stack development
- tor-proxy-agentA lightweight Node.js wrapper for routing HTTP(S) traffic through Tor, including optional ControlPort circuit rotation.
- angular-auth-oidc-clientAngular Lib for OpenID Connect & OAuth2
- ember-cli-sriSRI generation for Ember CLI
- @brandonblack/musigJS implementation of MuSig. 1-dependency MuSig key aggregation, tweaking, and signing.
- @cdxgen/safer-execOS-level sandboxing with tracing, auditing, crypto tracing (CBOM), and learning mode for arbitrary binaries.
- altchaPrivacy-first CAPTCHA widget, compliant with global regulations (GDPR/HIPAA/CCPA/LGDP/DPDPA/PIPL) and WCAG accessible. No tracking, self-verifying.
- ssrf-req-filterModule to prevent SSRF when making requests
- @rushstack/eslint-plugin-securityAn ESLint plugin providing rules that identify common security vulnerabilities for browser applications, Node.js tools, and Node.js services
- image-size-nextCommunity-maintained fork of image-size: get dimensions of any image file or buffer. Fixes CVE-2025-71329 and CVE-2025-71330 (DoS via infinite loops).
- secure-web-tokenA secure, encrypted, device-bound authentication token library for Node.js — the best alternative to JWT with AES-256-GCM encryption, device fingerprinting, and true logout support.
- supertokens-websitefrontend sdk for website to be used for auth solution.
- @socketsecurity/bun-security-scannerBun security scanner for SocketDev
- delivery-intelEvidence-driven repo intelligence: DORA metrics, forensic signals, vulnerability scan, and delivery verdict for any GitHub repo. One command, no setup.
- schema-inspectorSchema-Inspector is a powerful tool to sanitize and validate JS objects.
- next-secure-headersSets secure response headers for Next.js.
- @cerbos/coreCommon types used by the Cerbos client libraries
- noseconeProtect your Response with secure headers
- @nosecone/nextProtect your Next.js application with secure headers
- owasp-password-strength-testA password-strength tester based upon the OWASP guidelines for enforcing strong passwords.
- nextjs-corsNextjs-Cors is a node.js package to provide a middleware that can be used to enable CORS with various options in nextjs applications.
- read-envTransform environment variables into JSON object with sanitized values.
- @cerbos/apiGenerated code used by the Cerbos client libraries
- eslint-plugin-redosESLint plugin for catching ReDoS vulnerability
- encrypt-storageWrapper for encrypted localStorage and sessionStorage in browser
- @hackbg/miscreant-esm(ESM port) Misuse resistant symmetric encryption library providing AES-SIV (RFC 5297), AES-PMAC-SIV, and STREAM constructions
- arcjetArcjet runtime security SDK — bot protection, rate limiting, prompt injection detection, PII blocking, and WAF for JavaScript and TypeScript apps
- @socketsecurity/socket-patchCLI tool and schema library for applying security patches to dependencies
- @next-safe/middlewareStrict Content-Security-Policy (CSP) for Next.js with composable middleware
- @arcjet/nextArcjet runtime security SDK for Next.js — bot protection, rate limiting, prompt injection detection, PII blocking, and WAF
- yarn-audit-fixThe missing `yarn audit fix`
- sanitize-s3-objectkeyRemove and replace illegal characters in S3 Object Keys
- @varlock/vite-integrationVite plugin to use varlock for .env file loading - adds validation, type-safety, and extra security features
- npm-audit-resolverAids humans and automation in managing npm audit results
- cross-keychainCross-platform secret storage