Package category
Security
Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.
514 packages2 comparisons
Packages compared
514 packages
| Package | Weekly downloads | 12-month change | 52 weeks | Gzip | Last release | Module | Types | Categories |
|---|---|---|---|---|---|---|---|---|
| dtrim A tool for trimming deep/lenghty javascript structures. Some potential usages are: debugging, logging or data sanitization. | 17.5k | +31% | - | 7 months ago 1.13.3 | CommonJS | Bundled | Security | |
| @cap.js/widget The self-hosted CAPTCHA for the modern web. | 17.3k | - | - | - | 1 day ago 0.1.58 | CommonJS | Bundled | Cryptography and hashing, Security |
| csp-toolkit A comprehensive toolkit for working with Content Security Policy (CSP) directives in TypeScript. | 17.3k | +116% | - | 5 months ago 1.5.0 | ESM + CommonJS | Bundled | Security | |
| express-security.txt [](https://travis-ci.org/gergelyke/express-security.txt) | 17k | +143% | - | 8 years ago 2.0.0 | CommonJS | None | Security | |
| @hasna/hooks Open source hooks library for AI coding agents - Install safety, quality, and automation hooks with a single command | 16.5k | - | - | - | today 0.10.9 | ESM only | Bundled | CLI tools and terminal utilities, TypeScript tooling |
| express-csp-header Content-Security-Policy middleware for Express | 16.3k | +29% | - | 21 days ago 6.4.0 | ESM + CommonJS | Bundled | Security | |
| @varlock/nextjs-integration drop-in replacement for @next/env that uses varlock to load .env files with validation and extra security features | 16k | - | - | - | 24 days ago 1.2.2 | CommonJS | Bundled | Configuration, Schema validation |
| crypto-toolkit-ts Modern Cryptography & Hashing Toolkit - a misuse-resistant, high-level cryptography library for TypeScript/Node.js | 15.4k | - | - | 16 days ago 1.1.0 | ESM + CommonJS | Bundled | Cryptography and hashing, Security | |
| permix Permix is a lightweight, framework-agnostic, type-safe permissions management library for JavaScript applications on the client and server sides. | 15.4k | +752% | - | 11 days ago 4.3.0 | ESM only | Bundled | Security, TypeScript tooling | |
| sasl-scram-sha-1 JavaScript implementation of SCRAM-SHA-1 SASL mechanism. | 15.2k | +123% | - | 6 months ago 1.4.0 | CommonJS | None | Authentication and authorisation, Security | |
| sasl-anonymous JavaScript implementation of ANONYMOUS SASL mechanism. | 15.1k | +110% | - | 13 years ago 0.1.0 | CommonJS | None | Authentication and authorisation, Security | |
| mlkem An ML-KEM/CRYSTALS-KYBER implementation written in TypeScript for various JavaScript runtimes | 15k | +828% | - | 6 months ago 2.7.0 | ESM + CommonJS | Bundled | Cryptography and hashing, TypeScript tooling | |
| blitzstrike Blitz Strike — a universal MCP security-audit toolbelt. BLITZ sweeps the attack surface, EAGLE-EYE traces source-to-sink, STRIKE verifies live. 57 attack chains, 130-tool catalog, intelligence data layer. One server, every agent. | 14.9k | - | - | 6 days ago 2.4.92 | ESM only | None | Security | |
| ember-css-url A helper for safely embedding URLs in style properties | 14.8k | +12% | - | 4 years ago 1.0.0 | CommonJS | None | URLs and query strings, Security | |
| fold-to-ascii A JavaScript port of the Apache Lucene ASCII Folding Filter that converts alphabetic, numeric, and symbolic Unicode characters which are not in the first 127 ASCII characters (the "Basic Latin" Unicode block) into a ASCII equivalents, if they exist. | 14.6k | -26% | - | 4 years ago 5.0.1 | CommonJS | None | Security | |
| @pulumi/compliance-policies-unit-test-helpers This repository contains a growing set of Compliance Policies to validate your infrastructure using Pulumi's Crossguard Policy-as-Code framework. | 14.2k | - | - | - | 1 year ago 0.1.6 | - | Bundled | Security |
| express-brute A brute-force protection middleware for express routes that rate limits incoming requests | 13.6k | +43% | - | 9 years ago 1.0.1 | - | None | Security | |
| @cerbos/hub Client library for interacting with Cerbos Hub from server-side Node.js applications | 13.4k | - | - | - | 10 days ago 0.6.2 | ESM only | Bundled | Security, Node.js utilities |
| @lavamoat/webpack LavaMoat Webpack plugin for running dependencies in Compartments without eval | 13k | - | - | - | 21 days ago 2.3.0 | CommonJS | Bundled | Security, Bundler plugins and loaders |
| csp-typed-directives Provides type information for all CSP directives and related headers' directives; as well as a basic utility funtion that helps convert the typed properties to the header content's policy string. | 12.8k | +102% | - | 3 years ago 1.1.10 | ESM + CommonJS | Bundled | Security, TypeScript tooling | |
| showdown-xss-filter XSS filter extension for showdown | 12.6k | +2% | - | 10 years ago 0.2.0 | CommonJS | None | Security | |
| @siva_raja/uxsp UXSP JavaScript/TypeScript Browser SDK | 12.6k | - | - | - | 12 days ago 1.3.0 | ESM only | Bundled | Cryptography and hashing, Security |
| miscreant Misuse resistant symmetric encryption library providing AES-SIV (RFC 5297), AES-PMAC-SIV, and STREAM constructions | 12.5k | -35% | - | 8 years ago 0.3.2 | CommonJS | Bundled | Cryptography and hashing, Security | |
| clamdjs A ClamAV client on node.js | 12.5k | +74% | - | 7 years ago 1.0.2 | CommonJS | None | Security | |
| sanitize-filename-ts Sanitize a string for use as a filename | 12.4k | +1% | - | 7 years ago 1.0.2 | CommonJS | Bundled | Security | |
| appattest-checker-node Node.JS library to check/verify iOS App Attest attestations & assertions | 12.3k | +1477% | - | 1 year ago 1.0.3 | CommonJS | Bundled | Security | |
| express-xss-sanitizer Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack. | 12.1k | -65% | - | 6 months ago 2.0.2 | CommonJS | None | Security, HTTP servers and web frameworks | |
| permissions-policy Middleware to set the Permissions-Policy HTTP header | 11.9k | -11% | - | 5 years ago 0.6.0 | CommonJS | Bundled | Security, HTTP servers and web frameworks | |
| vite-plugin-csp Create CSP meta tags and header configs from all sources in the final Vite html | 11.8k | +104% | - | 4 years ago 1.1.2 | ESM + CommonJS | Bundled | Bundler plugins and loaders, Security | |
| @tracespace/xml-id XML ID utilities for tracespace projects | 11.7k | - | - | - | 4 years ago 4.2.7 | CommonJS | Bundled | Security |
| @nichtsam/helmet Helps secure applications by setting HTTP response headers. Inspired by [`helmet`](https://github.com/helmetjs/helmet) and [`http-helmet`](https://github.com/mcansh/http-helmet). | 11.2k | - | - | - | 6 months ago 0.3.3 | ESM only | None | Security |
| utf8-sanitize A performant zero-dependency utility to clean UTF-8 text, fix mojibake from latin1, verify string length, and sanitize input | 11.1k | +20077% | - | 1 year ago 1.0.2 | CommonJS | None | Security | |
| payload-totp Add an extra security layer to PayloadCMS using a Time-based One-time Password (TOTP). | 11k | +1997% | - | 15 days ago 3.0.3 | ESM only | Bundled | Security | |
| ssl-checker Zero-dependency SSL/TLS certificate checker for Node.js — HTTPS, SMTP, IMAP, POP3, FTP via STARTTLS | 11k | +250% | - | 5 months ago 3.0.1 | ESM + CommonJS | Bundled | CLI tools and terminal utilities, Security | |
| is-local-address Statically check whether a hostname or IP is a local, loopback, private, or link-local address. | 11k | +400% | - | 1 month ago 2.3.6 | CommonJS | Bundled | Security, URLs and query strings | |
| express-sanitizer Express middleware for the sanitizer module. | 10.8k | +111% | - | 5 years ago 1.0.6 | CommonJS | None | Security, HTTP servers and web frameworks | |
| @gotgenes/pi-permission-system Permission enforcement extension for the Pi coding agent. | 10.7k | - | - | - | today 34.0.0 | ESM only | Bundled | Security |
| gitleaks-secret-scanner A powerful, intelligent wrapper for the Gitleaks engine that provides accurate and safe secret scanning for local pre-commit hooks and CI/CD pipelines. | 10.6k | +762% | - | 8 months ago 2.1.1 | CommonJS | None | Security | |
| pin-github-action Pin your GitHub Actions to specific versions automatically! | 10.6k | +62% | - | 1 month ago 3.5.2 | ESM only | None | Security | |
| node-red-contrib-oauth2 The node-red-contrib-oauth2 is a Node-RED node that provides an OAuth2 authentication flow. This node uses the OAuth2 protocol to obtain an access token, which can be used to make authenticated API requests. | 10.3k | +275% | - | 2 years ago 6.2.1 | - | None | Security, Authentication and authorisation | |
| got-ssrf Protect Got requests from SSRF | 10.3k | +253% | - | 2 years ago 3.0.0 | ESM only | Bundled | HTTP clients, Security | |
| @socketsecurity/lib Core utilities and infrastructure for Socket.dev security tools | 10.3k | - | - | - | 3 days ago 7.0.3 | CommonJS | Bundled | Security |
| ehbp JavaScript client for Encrypted HTTP Body Protocol (EHBP) | 10k | +4612% | - | 1 month ago 0.3.2 | ESM + CommonJS | Bundled | Cryptography and hashing, Security | |
| @mattkrick/sanitize-svg a small script to remove script tags from SVGs | 9.8k | - | - | - | 1 year ago 0.4.1 | CommonJS | Bundled | Security |
| nestjs-doctor The deterministic NestJS devtool that catches AI mistakes. Static analysis for NestJS with a health score, diagnostics and an interactive report. | 9.8k | - | - | 12 days ago 0.9.9 | ESM only | Bundled | Security, TypeScript tooling | |
| tinfoil Tinfoil secure OpenAI client wrapper | 9.8k | +1288% | - | 1 month ago 1.2.1 | ESM only | Bundled | Security | |
| mongo-escape Escape variables to prevent NoSQL injection in MongoDB | 9.7k | +250% | - | 9 years ago 2.0.6 | CommonJS | None | Security, Database clients and drivers | |
| @barkleapp/css-sanitizer A CSS sanitizer to prevent XSS attacks | 9.6k | - | - | - | 2 years ago 1.0.0 | CommonJS | None | Security |
| recaptcha2 Easy API for Google reCAPTCHA version 2 for Node.js and Express | 9.5k | -14% | - | 7 years ago 1.3.3 | CommonJS | None | Security, HTTP servers and web frameworks | |
| decancer A library that removes common unicode confusables/homoglyphs from strings. | 9.3k | +5598% | - | 9 days ago 4.0.0 | CommonJS | Bundled | Security, Strings and text |
12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.
- dtrimA tool for trimming deep/lenghty javascript structures. Some potential usages are: debugging, logging or data sanitization.
- @cap.js/widgetThe self-hosted CAPTCHA for the modern web.
- csp-toolkitA comprehensive toolkit for working with Content Security Policy (CSP) directives in TypeScript.
- express-security.txt[](https://travis-ci.org/gergelyke/express-security.txt)
- @hasna/hooksOpen source hooks library for AI coding agents - Install safety, quality, and automation hooks with a single command
- express-csp-headerContent-Security-Policy middleware for Express
- @varlock/nextjs-integrationdrop-in replacement for @next/env that uses varlock to load .env files with validation and extra security features
- crypto-toolkit-tsModern Cryptography & Hashing Toolkit - a misuse-resistant, high-level cryptography library for TypeScript/Node.js
- permixPermix is a lightweight, framework-agnostic, type-safe permissions management library for JavaScript applications on the client and server sides.
- sasl-scram-sha-1JavaScript implementation of SCRAM-SHA-1 SASL mechanism.
- sasl-anonymousJavaScript implementation of ANONYMOUS SASL mechanism.
- mlkemAn ML-KEM/CRYSTALS-KYBER implementation written in TypeScript for various JavaScript runtimes
- blitzstrikeBlitz Strike — a universal MCP security-audit toolbelt. BLITZ sweeps the attack surface, EAGLE-EYE traces source-to-sink, STRIKE verifies live. 57 attack chains, 130-tool catalog, intelligence data layer. One server, every agent.
- ember-css-urlA helper for safely embedding URLs in style properties
- fold-to-asciiA JavaScript port of the Apache Lucene ASCII Folding Filter that converts alphabetic, numeric, and symbolic Unicode characters which are not in the first 127 ASCII characters (the "Basic Latin" Unicode block) into a ASCII equivalents, if they exist.
- @pulumi/compliance-policies-unit-test-helpersThis repository contains a growing set of Compliance Policies to validate your infrastructure using Pulumi's Crossguard Policy-as-Code framework.
- express-bruteA brute-force protection middleware for express routes that rate limits incoming requests
- @cerbos/hubClient library for interacting with Cerbos Hub from server-side Node.js applications
- @lavamoat/webpackLavaMoat Webpack plugin for running dependencies in Compartments without eval
- csp-typed-directivesProvides type information for all CSP directives and related headers' directives; as well as a basic utility funtion that helps convert the typed properties to the header content's policy string.
- showdown-xss-filterXSS filter extension for showdown
- @siva_raja/uxspUXSP JavaScript/TypeScript Browser SDK
- miscreantMisuse resistant symmetric encryption library providing AES-SIV (RFC 5297), AES-PMAC-SIV, and STREAM constructions
- clamdjsA ClamAV client on node.js
- sanitize-filename-tsSanitize a string for use as a filename
- appattest-checker-nodeNode.JS library to check/verify iOS App Attest attestations & assertions
- express-xss-sanitizerExpress 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack.
- permissions-policyMiddleware to set the Permissions-Policy HTTP header
- vite-plugin-cspCreate CSP meta tags and header configs from all sources in the final Vite html
- @tracespace/xml-idXML ID utilities for tracespace projects
- @nichtsam/helmetHelps secure applications by setting HTTP response headers. Inspired by [`helmet`](https://github.com/helmetjs/helmet) and [`http-helmet`](https://github.com/mcansh/http-helmet).
- utf8-sanitizeA performant zero-dependency utility to clean UTF-8 text, fix mojibake from latin1, verify string length, and sanitize input
- payload-totpAdd an extra security layer to PayloadCMS using a Time-based One-time Password (TOTP).
- ssl-checkerZero-dependency SSL/TLS certificate checker for Node.js — HTTPS, SMTP, IMAP, POP3, FTP via STARTTLS
- is-local-addressStatically check whether a hostname or IP is a local, loopback, private, or link-local address.
- express-sanitizerExpress middleware for the sanitizer module.
- @gotgenes/pi-permission-systemPermission enforcement extension for the Pi coding agent.
- gitleaks-secret-scannerA powerful, intelligent wrapper for the Gitleaks engine that provides accurate and safe secret scanning for local pre-commit hooks and CI/CD pipelines.
- pin-github-actionPin your GitHub Actions to specific versions automatically!
- node-red-contrib-oauth2The node-red-contrib-oauth2 is a Node-RED node that provides an OAuth2 authentication flow. This node uses the OAuth2 protocol to obtain an access token, which can be used to make authenticated API requests.
- got-ssrfProtect Got requests from SSRF
- @socketsecurity/libCore utilities and infrastructure for Socket.dev security tools
- ehbpJavaScript client for Encrypted HTTP Body Protocol (EHBP)
- @mattkrick/sanitize-svga small script to remove script tags from SVGs
- nestjs-doctorThe deterministic NestJS devtool that catches AI mistakes. Static analysis for NestJS with a health score, diagnostics and an interactive report.
- tinfoilTinfoil secure OpenAI client wrapper
- mongo-escapeEscape variables to prevent NoSQL injection in MongoDB
- @barkleapp/css-sanitizerA CSS sanitizer to prevent XSS attacks
- recaptcha2Easy API for Google reCAPTCHA version 2 for Node.js and Express
- decancerA library that removes common unicode confusables/homoglyphs from strings.