Skip to content
JS
Package category

Security

Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.

514 packages2 comparisons

Packages compared

514 packages
PackageWeekly downloads12-month change52 weeksGzipLast releaseModuleTypesCategories
audit-resolve-core
Core modules for audit-resolve.json file and logic of its processing
41.8k+2%-4 years ago
3.0.0-3
-NoneSecurity
@aikidosec/firewall
Zen by Aikido is an embedded Application Firewall that autonomously protects Node.js apps against common and critical attacks, provides rate limiting, detects malicious traffic (including bots), and more.
40.8k---7 days ago
1.8.42
CommonJSBundledDatabase clients and drivers, Security
@cerbos/grpc
Client library for interacting with the Cerbos policy decision point service over gRPC from server-side Node.js applications
39.2k---10 days ago
0.29.1
ESM onlyBundledSecurity, Node.js utilities
node-app-attest
A JavaScript implementation of the App Attest protocol, which checks whether clients connecting to your server are valid instances of your app.
36.9k+2571%-7 months ago
1.0.1
ESM onlyBundledSecurity
eslint-plugin-security-node
Create a security plugin for node.js
36k-3%-2 years ago
1.1.4
CommonJSNoneLinting and formatting, Security
@zxcvbn-ts/matcher-pwned
HaveIBeenPwned Matcher for zxcvbn-ts
34.8k---1 month ago
4.1.3
ESM + CommonJSBundledSecurity
nsp
The Node Security (nodesecurity.io) command line interface
33k-17%--
3.2.1
CommonJSNoneSecurity
mongo-sanitize
Helper to sanitize mongodb queries against query selector injections
31.7k+8%-6 years ago
1.1.0
CommonJSNoneSecurity
@stacksjs/sanitizer
A fast, native Bun-powered HTML sanitizer with DOMPurify-like features. Protection against XSS and malicious content.
31.6k---today
0.2.312
ESM onlyBundledSecurity
@vscode/sandbox-runtime
A general-purpose tool for wrapping security boundaries around arbitrary processes.
29.9k---4 months ago
0.0.1
ESM onlyBundledSecurity
@snyk/protect
Snyk protect library and utility
29k---1 day ago
1.1307.4
CommonJSBundledSecurity
kcors
Cross-Origin Resource Sharing(CORS) for koa
28.1k+6%-8 years ago
2.2.2
CommonJSNoneSecurity
sveltekit-rate-limiter
A modular rate limiter for SvelteKit. Use in password resets, account registration, etc.
27.2k+301%-28 days ago
0.8.0
ESM onlyBundledSvelte, Queues and background jobs
exceljs-hardened
Unofficial security-hardened fork of exceljs, patching known unpatched vulnerabilities in the upstream (unmaintained) project. Not affiliated with the original exceljs maintainers.
27.1k--1 month ago
5.0.0
CommonJSBundledPDF and documents, Security
koa-cors
CORS middleware for Koa
26.7k+46%-11 years ago
0.0.16
CommonJSNoneSecurity
@hono-rate-limiter/redis
<div align="center">
26.6k---2 years ago
0.1.4
ESM + CommonJSBundledSecurity, Database clients and drivers
personnummer
Validate Swedish personal identity numbers
25.9k+73%-3 years ago
3.2.1
ESM + CommonJSBundledSchema validation, Security
openzeppelin-solidity
Secure Smart Contract library for Solidity
25.4k-5%-5 years ago
3.4.2
-NoneBlockchain and Web3, Security
express-caja-sanitizer
An express middleware inspired from express-sanitizer but additionally sanitizes URL params. It also gives an option to provide a preprocessor function to decide whether a (key, value) pair should be sanitized or not.
25.1k+618%-10 years ago
1.0.1
CommonJSNoneSecurity, HTTP servers and web frameworks
@redactpii/node
Zero dependencies, blazing fast regex-based PII redaction with optional compliance dashboard integration. The modern fork of the abandoned 786k-download library.
25k---5 months ago
1.0.17
ESM + CommonJSBundledNode.js utilities, Security
node-esapi
OSWASP ESAPI4JS encoders port to node module
24.4k+116%-12 years ago
0.0.1
CommonJSNoneSecurity
@cerbos/http
Client library for interacting with the Cerbos policy decision point service over HTTP from browser-based applications
24.4k---10 days ago
0.30.1
ESM onlyBundledDOM and browser utilities, Security
wsemi
A support package for web developer.
24k+153%-3 days ago
1.9.3
CommonJSNoneCryptography and hashing, Utility libraries
anti-trojan-source
Detect trojan source attacks that employ unicode bidi attacks to inject malicious code
23.9k+20%-17 days ago
1.13.0
ESM + CommonJSNoneSecurity
agent-sanitizer
Defend an agent against hidden-content injection: strip payload-capable invisible Unicode and ANSI, splice out human-invisible HTML, and flag data-exfil URLs in untrusted text before any model sees it.
23.9k--3 days ago
2.58.6
ESM onlyBundledSecurity
@humanspeak/svelte-markdown
Markdown and HTML renderer for Svelte 5 — built for rendering streaming AI agent output from Claude Code, ChatGPT, and agentic workflows. XSS-safe defaults, streaming-aware sanitization, token caching, TypeScript types, and Svelte 5 runes.
23.5k---2 days ago
1.9.2
ESM onlyBundledMarkdown, Caching
@yottameta/yotta-guardian
Yuandun (元盾) — cross-agent dangerous tool-call guardrail: a deterministic rule engine + pluggable intent verifier (model-agnostic) that evaluates exec/write/edit/read/run/shell calls and provides audit logs. Triggers when an agent is about to run a high-r
23.5k---5 days ago
0.1.5
-NoneSecurity
openapi-security-handler
A library to process OpenAPI security definitions in parallel.
23.5k-28%-3 years ago
12.1.3
CommonJSBundledDocumentation tooling, Security
@lavamoat/git-safe-dependencies
Opinionated dependency linter for your git/github dependencies
23.3k---21 days ago
1.0.2
CommonJSNoneSecurity
eslint-plugin-jam3
Jam3 eslint plugin for react
22.8k-36%-6 years ago
0.2.3
CommonJSNoneLinting and formatting, Security
reproduce
Validate a package's reproducibility against it's published repository information.
22.5k+128237%-1 year ago
1.2.0
ESM onlyBundledSecurity
hibp
An unofficial TypeScript SDK for the 'Have I been pwned?' service.
22.5k+86%-8 months ago
15.2.1
ESM onlyBundledSecurity
@produtype/core
Deterministic CLI and library that analyzes a web application repository and reports how far it is from production-ready for the kind of product it is meant to be.
22.5k---1 day ago
1.34.0
ESM + CommonJSBundledSecurity
vuln-vects
A powerful, flexible CVSS parser, calculator and validator written for JavaScript/TypeScript.
22.1k-67%-4 years ago
1.1.0
CommonJSBundledTypeScript tooling, Security
@pulumi/compliance-policy-manager
This repository contains a growing set of Compliance Policies to validate your infrastructure using Pulumi's Crossguard Policy-as-Code framework.
20.8k---1 year ago
0.1.6
-BundledSecurity
@capgo/capacitor-is-root
Jailbreak/Root Detection Plugin for Capacitor
20.5k---9 days ago
8.1.19
ESM + CommonJSBundledSecurity
strict-transport-security
Middleware to add Strict-Transport-Security header.
20k+172%-5 years ago
0.3.0
CommonJSNoneSecurity
react-native-recaptcha-that-works
⚛ A reCAPTCHA bridge for React Native that works.
19.8k+15%-3 years ago
2.0.0
CommonJSBundledReact, Security
sasl-plain
JavaScript implementation of PLAIN SASL mechanism.
19.7k+122%-13 years ago
0.1.0
CommonJSNoneAuthentication and authorisation, Security
safe-expr-eval
Secure expression evaluator - Drop-in replacement for expr-eval without CVE-2025-12735 vulnerability
19.4k--4 months ago
1.0.4
CommonJSBundledSecurity
egg-security
security plugin in egg framework
19.4k-18%-2 months ago
3.8.1
-NoneSecurity
@dr.pogodin/csurf
CSRF token middleware for ExpressJS
19.3k---3 days ago
1.18.1
ESM onlyBundledHTTP servers and web frameworks, Security
safe-fetch
A `fetch()` wrapper that implements Double Submit Cookies CSRF protection.
19.1k+7%-10 years ago
0.2.1
CommonJSNoneSecurity
@capgo/capacitor-app-attest
App Attest on iOS, Play Integrity on Android, and optional device fraud signals for Capacitor
19k---3 days ago
8.2.9
ESM + CommonJSBundledSecurity
postmate
A powerful, simple, promise-based postMessage library
19k+31%-6 years ago
1.5.2
ESM + CommonJSNonePromises and async control flow, Security
@capgo/capacitor-privacy-screen
Protect app content in Android screenshots and obscure the iOS app switcher snapshot.
18.9k---9 days ago
8.3.10
ESM + CommonJSBundledSecurity
egg-jsonp
jsonp support for egg
18.6k-11%-8 years ago
2.0.0
-NoneSecurity
@earendil-works/gondolin
Alpine Linux sandbox for running untrusted code with controlled filesystem and network access
18k---4 months ago
0.12.0
ESM + CommonJSBundledSecurity
vite-plugin-csp-guard
A Vite plugin that lets SPA applications generate a Content Security Policy (CSP).
17.9k+127%-5 months ago
4.0.1
ESM onlyBundledSecurity, Bundler plugins and loaders
@andersmyrmel/vard
Lightweight prompt injection detection for LLM applications. Zod-inspired chainable API for prompt security.
17.8k---1 month ago
1.2.1
ESM onlyBundledSecurity

12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.

  • audit-resolve-coreCore modules for audit-resolve.json file and logic of its processing
  • @aikidosec/firewallZen by Aikido is an embedded Application Firewall that autonomously protects Node.js apps against common and critical attacks, provides rate limiting, detects malicious traffic (including bots), and more.
  • @cerbos/grpcClient library for interacting with the Cerbos policy decision point service over gRPC from server-side Node.js applications
  • node-app-attestA JavaScript implementation of the App Attest protocol, which checks whether clients connecting to your server are valid instances of your app.
  • eslint-plugin-security-nodeCreate a security plugin for node.js
  • @zxcvbn-ts/matcher-pwnedHaveIBeenPwned Matcher for zxcvbn-ts
  • nspThe Node Security (nodesecurity.io) command line interface
  • mongo-sanitizeHelper to sanitize mongodb queries against query selector injections
  • @stacksjs/sanitizerA fast, native Bun-powered HTML sanitizer with DOMPurify-like features. Protection against XSS and malicious content.
  • @vscode/sandbox-runtimeA general-purpose tool for wrapping security boundaries around arbitrary processes.
  • @snyk/protectSnyk protect library and utility
  • kcorsCross-Origin Resource Sharing(CORS) for koa
  • sveltekit-rate-limiterA modular rate limiter for SvelteKit. Use in password resets, account registration, etc.
  • exceljs-hardenedUnofficial security-hardened fork of exceljs, patching known unpatched vulnerabilities in the upstream (unmaintained) project. Not affiliated with the original exceljs maintainers.
  • koa-corsCORS middleware for Koa
  • @hono-rate-limiter/redis<div align="center">
  • personnummerValidate Swedish personal identity numbers
  • openzeppelin-soliditySecure Smart Contract library for Solidity
  • express-caja-sanitizerAn express middleware inspired from express-sanitizer but additionally sanitizes URL params. It also gives an option to provide a preprocessor function to decide whether a (key, value) pair should be sanitized or not.
  • @redactpii/nodeZero dependencies, blazing fast regex-based PII redaction with optional compliance dashboard integration. The modern fork of the abandoned 786k-download library.
  • node-esapiOSWASP ESAPI4JS encoders port to node module
  • @cerbos/httpClient library for interacting with the Cerbos policy decision point service over HTTP from browser-based applications
  • wsemiA support package for web developer.
  • anti-trojan-sourceDetect trojan source attacks that employ unicode bidi attacks to inject malicious code
  • agent-sanitizerDefend an agent against hidden-content injection: strip payload-capable invisible Unicode and ANSI, splice out human-invisible HTML, and flag data-exfil URLs in untrusted text before any model sees it.
  • @humanspeak/svelte-markdownMarkdown and HTML renderer for Svelte 5 — built for rendering streaming AI agent output from Claude Code, ChatGPT, and agentic workflows. XSS-safe defaults, streaming-aware sanitization, token caching, TypeScript types, and Svelte 5 runes.
  • @yottameta/yotta-guardianYuandun (元盾) — cross-agent dangerous tool-call guardrail: a deterministic rule engine + pluggable intent verifier (model-agnostic) that evaluates exec/write/edit/read/run/shell calls and provides audit logs. Triggers when an agent is about to run a high-r
  • openapi-security-handlerA library to process OpenAPI security definitions in parallel.
  • @lavamoat/git-safe-dependenciesOpinionated dependency linter for your git/github dependencies
  • eslint-plugin-jam3Jam3 eslint plugin for react
  • reproduceValidate a package's reproducibility against it's published repository information.
  • hibpAn unofficial TypeScript SDK for the 'Have I been pwned?' service.
  • @produtype/coreDeterministic CLI and library that analyzes a web application repository and reports how far it is from production-ready for the kind of product it is meant to be.
  • vuln-vectsA powerful, flexible CVSS parser, calculator and validator written for JavaScript/TypeScript.
  • @pulumi/compliance-policy-managerThis repository contains a growing set of Compliance Policies to validate your infrastructure using Pulumi's Crossguard Policy-as-Code framework.
  • @capgo/capacitor-is-rootJailbreak/Root Detection Plugin for Capacitor
  • strict-transport-securityMiddleware to add Strict-Transport-Security header.
  • react-native-recaptcha-that-works⚛ A reCAPTCHA bridge for React Native that works.
  • sasl-plainJavaScript implementation of PLAIN SASL mechanism.
  • safe-expr-evalSecure expression evaluator - Drop-in replacement for expr-eval without CVE-2025-12735 vulnerability
  • egg-securitysecurity plugin in egg framework
  • @dr.pogodin/csurfCSRF token middleware for ExpressJS
  • safe-fetchA `fetch()` wrapper that implements Double Submit Cookies CSRF protection.
  • @capgo/capacitor-app-attestApp Attest on iOS, Play Integrity on Android, and optional device fraud signals for Capacitor
  • postmateA powerful, simple, promise-based postMessage library
  • @capgo/capacitor-privacy-screenProtect app content in Android screenshots and obscure the iOS app switcher snapshot.
  • egg-jsonpjsonp support for egg
  • @earendil-works/gondolinAlpine Linux sandbox for running untrusted code with controlled filesystem and network access
  • vite-plugin-csp-guardA Vite plugin that lets SPA applications generate a Content Security Policy (CSP).
  • @andersmyrmel/vardLightweight prompt injection detection for LLM applications. Zod-inspired chainable API for prompt security.