Package category
Security
Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.
514 packages2 comparisons
Packages compared
514 packages
| Package | Weekly downloads | 12-month change | 52 weeks | Gzip | Last release | Module | Types | Categories |
|---|---|---|---|---|---|---|---|---|
| audit-resolve-core Core modules for audit-resolve.json file and logic of its processing | 41.8k | +2% | - | 4 years ago 3.0.0-3 | - | None | Security | |
| @aikidosec/firewall Zen by Aikido is an embedded Application Firewall that autonomously protects Node.js apps against common and critical attacks, provides rate limiting, detects malicious traffic (including bots), and more. | 40.8k | - | - | - | 7 days ago 1.8.42 | CommonJS | Bundled | Database clients and drivers, Security |
| @cerbos/grpc Client library for interacting with the Cerbos policy decision point service over gRPC from server-side Node.js applications | 39.2k | - | - | - | 10 days ago 0.29.1 | ESM only | Bundled | Security, Node.js utilities |
| node-app-attest A JavaScript implementation of the App Attest protocol, which checks whether clients connecting to your server are valid instances of your app. | 36.9k | +2571% | - | 7 months ago 1.0.1 | ESM only | Bundled | Security | |
| eslint-plugin-security-node Create a security plugin for node.js | 36k | -3% | - | 2 years ago 1.1.4 | CommonJS | None | Linting and formatting, Security | |
| @zxcvbn-ts/matcher-pwned HaveIBeenPwned Matcher for zxcvbn-ts | 34.8k | - | - | - | 1 month ago 4.1.3 | ESM + CommonJS | Bundled | Security |
| nsp The Node Security (nodesecurity.io) command line interface | 33k | -17% | - | - 3.2.1 | CommonJS | None | Security | |
| mongo-sanitize Helper to sanitize mongodb queries against query selector injections | 31.7k | +8% | - | 6 years ago 1.1.0 | CommonJS | None | Security | |
| @stacksjs/sanitizer A fast, native Bun-powered HTML sanitizer with DOMPurify-like features. Protection against XSS and malicious content. | 31.6k | - | - | - | today 0.2.312 | ESM only | Bundled | Security |
| @vscode/sandbox-runtime A general-purpose tool for wrapping security boundaries around arbitrary processes. | 29.9k | - | - | - | 4 months ago 0.0.1 | ESM only | Bundled | Security |
| @snyk/protect Snyk protect library and utility | 29k | - | - | - | 1 day ago 1.1307.4 | CommonJS | Bundled | Security |
| kcors Cross-Origin Resource Sharing(CORS) for koa | 28.1k | +6% | - | 8 years ago 2.2.2 | CommonJS | None | Security | |
| sveltekit-rate-limiter A modular rate limiter for SvelteKit. Use in password resets, account registration, etc. | 27.2k | +301% | - | 28 days ago 0.8.0 | ESM only | Bundled | Svelte, Queues and background jobs | |
| exceljs-hardened Unofficial security-hardened fork of exceljs, patching known unpatched vulnerabilities in the upstream (unmaintained) project. Not affiliated with the original exceljs maintainers. | 27.1k | - | - | 1 month ago 5.0.0 | CommonJS | Bundled | PDF and documents, Security | |
| koa-cors CORS middleware for Koa | 26.7k | +46% | - | 11 years ago 0.0.16 | CommonJS | None | Security | |
| @hono-rate-limiter/redis <div align="center"> | 26.6k | - | - | - | 2 years ago 0.1.4 | ESM + CommonJS | Bundled | Security, Database clients and drivers |
| personnummer Validate Swedish personal identity numbers | 25.9k | +73% | - | 3 years ago 3.2.1 | ESM + CommonJS | Bundled | Schema validation, Security | |
| openzeppelin-solidity Secure Smart Contract library for Solidity | 25.4k | -5% | - | 5 years ago 3.4.2 | - | None | Blockchain and Web3, Security | |
| express-caja-sanitizer An express middleware inspired from express-sanitizer but additionally sanitizes URL params. It also gives an option to provide a preprocessor function to decide whether a (key, value) pair should be sanitized or not. | 25.1k | +618% | - | 10 years ago 1.0.1 | CommonJS | None | Security, HTTP servers and web frameworks | |
| @redactpii/node Zero dependencies, blazing fast regex-based PII redaction with optional compliance dashboard integration. The modern fork of the abandoned 786k-download library. | 25k | - | - | - | 5 months ago 1.0.17 | ESM + CommonJS | Bundled | Node.js utilities, Security |
| node-esapi OSWASP ESAPI4JS encoders port to node module | 24.4k | +116% | - | 12 years ago 0.0.1 | CommonJS | None | Security | |
| @cerbos/http Client library for interacting with the Cerbos policy decision point service over HTTP from browser-based applications | 24.4k | - | - | - | 10 days ago 0.30.1 | ESM only | Bundled | DOM and browser utilities, Security |
| wsemi A support package for web developer. | 24k | +153% | - | 3 days ago 1.9.3 | CommonJS | None | Cryptography and hashing, Utility libraries | |
| anti-trojan-source Detect trojan source attacks that employ unicode bidi attacks to inject malicious code | 23.9k | +20% | - | 17 days ago 1.13.0 | ESM + CommonJS | None | Security | |
| agent-sanitizer Defend an agent against hidden-content injection: strip payload-capable invisible Unicode and ANSI, splice out human-invisible HTML, and flag data-exfil URLs in untrusted text before any model sees it. | 23.9k | - | - | 3 days ago 2.58.6 | ESM only | Bundled | Security | |
| @humanspeak/svelte-markdown Markdown and HTML renderer for Svelte 5 — built for rendering streaming AI agent output from Claude Code, ChatGPT, and agentic workflows. XSS-safe defaults, streaming-aware sanitization, token caching, TypeScript types, and Svelte 5 runes. | 23.5k | - | - | - | 2 days ago 1.9.2 | ESM only | Bundled | Markdown, Caching |
| @yottameta/yotta-guardian Yuandun (元盾) — cross-agent dangerous tool-call guardrail: a deterministic rule engine + pluggable intent verifier (model-agnostic) that evaluates exec/write/edit/read/run/shell calls and provides audit logs. Triggers when an agent is about to run a high-r | 23.5k | - | - | - | 5 days ago 0.1.5 | - | None | Security |
| openapi-security-handler A library to process OpenAPI security definitions in parallel. | 23.5k | -28% | - | 3 years ago 12.1.3 | CommonJS | Bundled | Documentation tooling, Security | |
| @lavamoat/git-safe-dependencies Opinionated dependency linter for your git/github dependencies | 23.3k | - | - | - | 21 days ago 1.0.2 | CommonJS | None | Security |
| eslint-plugin-jam3 Jam3 eslint plugin for react | 22.8k | -36% | - | 6 years ago 0.2.3 | CommonJS | None | Linting and formatting, Security | |
| reproduce Validate a package's reproducibility against it's published repository information. | 22.5k | +128237% | - | 1 year ago 1.2.0 | ESM only | Bundled | Security | |
| hibp An unofficial TypeScript SDK for the 'Have I been pwned?' service. | 22.5k | +86% | - | 8 months ago 15.2.1 | ESM only | Bundled | Security | |
| @produtype/core Deterministic CLI and library that analyzes a web application repository and reports how far it is from production-ready for the kind of product it is meant to be. | 22.5k | - | - | - | 1 day ago 1.34.0 | ESM + CommonJS | Bundled | Security |
| vuln-vects A powerful, flexible CVSS parser, calculator and validator written for JavaScript/TypeScript. | 22.1k | -67% | - | 4 years ago 1.1.0 | CommonJS | Bundled | TypeScript tooling, Security | |
| @pulumi/compliance-policy-manager This repository contains a growing set of Compliance Policies to validate your infrastructure using Pulumi's Crossguard Policy-as-Code framework. | 20.8k | - | - | - | 1 year ago 0.1.6 | - | Bundled | Security |
| @capgo/capacitor-is-root Jailbreak/Root Detection Plugin for Capacitor | 20.5k | - | - | - | 9 days ago 8.1.19 | ESM + CommonJS | Bundled | Security |
| strict-transport-security Middleware to add Strict-Transport-Security header. | 20k | +172% | - | 5 years ago 0.3.0 | CommonJS | None | Security | |
| react-native-recaptcha-that-works ⚛ A reCAPTCHA bridge for React Native that works. | 19.8k | +15% | - | 3 years ago 2.0.0 | CommonJS | Bundled | React, Security | |
| sasl-plain JavaScript implementation of PLAIN SASL mechanism. | 19.7k | +122% | - | 13 years ago 0.1.0 | CommonJS | None | Authentication and authorisation, Security | |
| safe-expr-eval Secure expression evaluator - Drop-in replacement for expr-eval without CVE-2025-12735 vulnerability | 19.4k | - | - | 4 months ago 1.0.4 | CommonJS | Bundled | Security | |
| egg-security security plugin in egg framework | 19.4k | -18% | - | 2 months ago 3.8.1 | - | None | Security | |
| @dr.pogodin/csurf CSRF token middleware for ExpressJS | 19.3k | - | - | - | 3 days ago 1.18.1 | ESM only | Bundled | HTTP servers and web frameworks, Security |
| safe-fetch A `fetch()` wrapper that implements Double Submit Cookies CSRF protection. | 19.1k | +7% | - | 10 years ago 0.2.1 | CommonJS | None | Security | |
| @capgo/capacitor-app-attest App Attest on iOS, Play Integrity on Android, and optional device fraud signals for Capacitor | 19k | - | - | - | 3 days ago 8.2.9 | ESM + CommonJS | Bundled | Security |
| postmate A powerful, simple, promise-based postMessage library | 19k | +31% | - | 6 years ago 1.5.2 | ESM + CommonJS | None | Promises and async control flow, Security | |
| @capgo/capacitor-privacy-screen Protect app content in Android screenshots and obscure the iOS app switcher snapshot. | 18.9k | - | - | - | 9 days ago 8.3.10 | ESM + CommonJS | Bundled | Security |
| egg-jsonp jsonp support for egg | 18.6k | -11% | - | 8 years ago 2.0.0 | - | None | Security | |
| @earendil-works/gondolin Alpine Linux sandbox for running untrusted code with controlled filesystem and network access | 18k | - | - | - | 4 months ago 0.12.0 | ESM + CommonJS | Bundled | Security |
| vite-plugin-csp-guard A Vite plugin that lets SPA applications generate a Content Security Policy (CSP). | 17.9k | +127% | - | 5 months ago 4.0.1 | ESM only | Bundled | Security, Bundler plugins and loaders | |
| @andersmyrmel/vard Lightweight prompt injection detection for LLM applications. Zod-inspired chainable API for prompt security. | 17.8k | - | - | - | 1 month ago 1.2.1 | ESM only | Bundled | Security |
12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.
- audit-resolve-coreCore modules for audit-resolve.json file and logic of its processing
- @aikidosec/firewallZen by Aikido is an embedded Application Firewall that autonomously protects Node.js apps against common and critical attacks, provides rate limiting, detects malicious traffic (including bots), and more.
- @cerbos/grpcClient library for interacting with the Cerbos policy decision point service over gRPC from server-side Node.js applications
- node-app-attestA JavaScript implementation of the App Attest protocol, which checks whether clients connecting to your server are valid instances of your app.
- eslint-plugin-security-nodeCreate a security plugin for node.js
- @zxcvbn-ts/matcher-pwnedHaveIBeenPwned Matcher for zxcvbn-ts
- nspThe Node Security (nodesecurity.io) command line interface
- mongo-sanitizeHelper to sanitize mongodb queries against query selector injections
- @stacksjs/sanitizerA fast, native Bun-powered HTML sanitizer with DOMPurify-like features. Protection against XSS and malicious content.
- @vscode/sandbox-runtimeA general-purpose tool for wrapping security boundaries around arbitrary processes.
- @snyk/protectSnyk protect library and utility
- kcorsCross-Origin Resource Sharing(CORS) for koa
- sveltekit-rate-limiterA modular rate limiter for SvelteKit. Use in password resets, account registration, etc.
- exceljs-hardenedUnofficial security-hardened fork of exceljs, patching known unpatched vulnerabilities in the upstream (unmaintained) project. Not affiliated with the original exceljs maintainers.
- koa-corsCORS middleware for Koa
- @hono-rate-limiter/redis<div align="center">
- personnummerValidate Swedish personal identity numbers
- openzeppelin-soliditySecure Smart Contract library for Solidity
- express-caja-sanitizerAn express middleware inspired from express-sanitizer but additionally sanitizes URL params. It also gives an option to provide a preprocessor function to decide whether a (key, value) pair should be sanitized or not.
- @redactpii/nodeZero dependencies, blazing fast regex-based PII redaction with optional compliance dashboard integration. The modern fork of the abandoned 786k-download library.
- node-esapiOSWASP ESAPI4JS encoders port to node module
- @cerbos/httpClient library for interacting with the Cerbos policy decision point service over HTTP from browser-based applications
- wsemiA support package for web developer.
- anti-trojan-sourceDetect trojan source attacks that employ unicode bidi attacks to inject malicious code
- agent-sanitizerDefend an agent against hidden-content injection: strip payload-capable invisible Unicode and ANSI, splice out human-invisible HTML, and flag data-exfil URLs in untrusted text before any model sees it.
- @humanspeak/svelte-markdownMarkdown and HTML renderer for Svelte 5 — built for rendering streaming AI agent output from Claude Code, ChatGPT, and agentic workflows. XSS-safe defaults, streaming-aware sanitization, token caching, TypeScript types, and Svelte 5 runes.
- @yottameta/yotta-guardianYuandun (元盾) — cross-agent dangerous tool-call guardrail: a deterministic rule engine + pluggable intent verifier (model-agnostic) that evaluates exec/write/edit/read/run/shell calls and provides audit logs. Triggers when an agent is about to run a high-r
- openapi-security-handlerA library to process OpenAPI security definitions in parallel.
- @lavamoat/git-safe-dependenciesOpinionated dependency linter for your git/github dependencies
- eslint-plugin-jam3Jam3 eslint plugin for react
- reproduceValidate a package's reproducibility against it's published repository information.
- hibpAn unofficial TypeScript SDK for the 'Have I been pwned?' service.
- @produtype/coreDeterministic CLI and library that analyzes a web application repository and reports how far it is from production-ready for the kind of product it is meant to be.
- vuln-vectsA powerful, flexible CVSS parser, calculator and validator written for JavaScript/TypeScript.
- @pulumi/compliance-policy-managerThis repository contains a growing set of Compliance Policies to validate your infrastructure using Pulumi's Crossguard Policy-as-Code framework.
- @capgo/capacitor-is-rootJailbreak/Root Detection Plugin for Capacitor
- strict-transport-securityMiddleware to add Strict-Transport-Security header.
- react-native-recaptcha-that-works⚛ A reCAPTCHA bridge for React Native that works.
- sasl-plainJavaScript implementation of PLAIN SASL mechanism.
- safe-expr-evalSecure expression evaluator - Drop-in replacement for expr-eval without CVE-2025-12735 vulnerability
- egg-securitysecurity plugin in egg framework
- @dr.pogodin/csurfCSRF token middleware for ExpressJS
- safe-fetchA `fetch()` wrapper that implements Double Submit Cookies CSRF protection.
- @capgo/capacitor-app-attestApp Attest on iOS, Play Integrity on Android, and optional device fraud signals for Capacitor
- postmateA powerful, simple, promise-based postMessage library
- @capgo/capacitor-privacy-screenProtect app content in Android screenshots and obscure the iOS app switcher snapshot.
- egg-jsonpjsonp support for egg
- @earendil-works/gondolinAlpine Linux sandbox for running untrusted code with controlled filesystem and network access
- vite-plugin-csp-guardA Vite plugin that lets SPA applications generate a Content Security Policy (CSP).
- @andersmyrmel/vardLightweight prompt injection detection for LLM applications. Zod-inspired chainable API for prompt security.