Skip to content
JS
Package category

Security

Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.

514 packages2 comparisons

Packages compared

514 packages
PackageWeekly downloads12-month change52 weeksGzipLast releaseModuleTypesCategories
dtrim
A tool for trimming deep/lenghty javascript structures. Some potential usages are: debugging, logging or data sanitization.
17.5k+31%-7 months ago
1.13.3
CommonJSBundledSecurity
@cap.js/widget
The self-hosted CAPTCHA for the modern web.
17.3k---1 day ago
0.1.58
CommonJSBundledCryptography and hashing, Security
csp-toolkit
A comprehensive toolkit for working with Content Security Policy (CSP) directives in TypeScript.
17.3k+116%-5 months ago
1.5.0
ESM + CommonJSBundledSecurity
express-security.txt
[![Build Status](https://travis-ci.org/gergelyke/express-security.txt.svg?branch=master)](https://travis-ci.org/gergelyke/express-security.txt)
17k+143%-8 years ago
2.0.0
CommonJSNoneSecurity
@hasna/hooks
Open source hooks library for AI coding agents - Install safety, quality, and automation hooks with a single command
16.5k---today
0.10.9
ESM onlyBundledCLI tools and terminal utilities, TypeScript tooling
express-csp-header
Content-Security-Policy middleware for Express
16.3k+29%-21 days ago
6.4.0
ESM + CommonJSBundledSecurity
@varlock/nextjs-integration
drop-in replacement for @next/env that uses varlock to load .env files with validation and extra security features
16k---24 days ago
1.2.2
CommonJSBundledConfiguration, Schema validation
crypto-toolkit-ts
Modern Cryptography & Hashing Toolkit - a misuse-resistant, high-level cryptography library for TypeScript/Node.js
15.4k--16 days ago
1.1.0
ESM + CommonJSBundledCryptography and hashing, Security
permix
Permix is a lightweight, framework-agnostic, type-safe permissions management library for JavaScript applications on the client and server sides.
15.4k+752%-11 days ago
4.3.0
ESM onlyBundledSecurity, TypeScript tooling
sasl-scram-sha-1
JavaScript implementation of SCRAM-SHA-1 SASL mechanism.
15.2k+123%-6 months ago
1.4.0
CommonJSNoneAuthentication and authorisation, Security
sasl-anonymous
JavaScript implementation of ANONYMOUS SASL mechanism.
15.1k+110%-13 years ago
0.1.0
CommonJSNoneAuthentication and authorisation, Security
mlkem
An ML-KEM/CRYSTALS-KYBER implementation written in TypeScript for various JavaScript runtimes
15k+828%-6 months ago
2.7.0
ESM + CommonJSBundledCryptography and hashing, TypeScript tooling
blitzstrike
Blitz Strike — a universal MCP security-audit toolbelt. BLITZ sweeps the attack surface, EAGLE-EYE traces source-to-sink, STRIKE verifies live. 57 attack chains, 130-tool catalog, intelligence data layer. One server, every agent.
14.9k--6 days ago
2.4.92
ESM onlyNoneSecurity
ember-css-url
A helper for safely embedding URLs in style properties
14.8k+12%-4 years ago
1.0.0
CommonJSNoneURLs and query strings, Security
fold-to-ascii
A JavaScript port of the Apache Lucene ASCII Folding Filter that converts alphabetic, numeric, and symbolic Unicode characters which are not in the first 127 ASCII characters (the "Basic Latin" Unicode block) into a ASCII equivalents, if they exist.
14.6k-26%-4 years ago
5.0.1
CommonJSNoneSecurity
@pulumi/compliance-policies-unit-test-helpers
This repository contains a growing set of Compliance Policies to validate your infrastructure using Pulumi's Crossguard Policy-as-Code framework.
14.2k---1 year ago
0.1.6
-BundledSecurity
express-brute
A brute-force protection middleware for express routes that rate limits incoming requests
13.6k+43%-9 years ago
1.0.1
-NoneSecurity
@cerbos/hub
Client library for interacting with Cerbos Hub from server-side Node.js applications
13.4k---10 days ago
0.6.2
ESM onlyBundledSecurity, Node.js utilities
@lavamoat/webpack
LavaMoat Webpack plugin for running dependencies in Compartments without eval
13k---21 days ago
2.3.0
CommonJSBundledSecurity, Bundler plugins and loaders
csp-typed-directives
Provides type information for all CSP directives and related headers' directives; as well as a basic utility funtion that helps convert the typed properties to the header content's policy string.
12.8k+102%-3 years ago
1.1.10
ESM + CommonJSBundledSecurity, TypeScript tooling
showdown-xss-filter
XSS filter extension for showdown
12.6k+2%-10 years ago
0.2.0
CommonJSNoneSecurity
@siva_raja/uxsp
UXSP JavaScript/TypeScript Browser SDK
12.6k---12 days ago
1.3.0
ESM onlyBundledCryptography and hashing, Security
miscreant
Misuse resistant symmetric encryption library providing AES-SIV (RFC 5297), AES-PMAC-SIV, and STREAM constructions
12.5k-35%-8 years ago
0.3.2
CommonJSBundledCryptography and hashing, Security
clamdjs
A ClamAV client on node.js
12.5k+74%-7 years ago
1.0.2
CommonJSNoneSecurity
sanitize-filename-ts
Sanitize a string for use as a filename
12.4k+1%-7 years ago
1.0.2
CommonJSBundledSecurity
appattest-checker-node
Node.JS library to check/verify iOS App Attest attestations & assertions
12.3k+1477%-1 year ago
1.0.3
CommonJSBundledSecurity
express-xss-sanitizer
Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack.
12.1k-65%-6 months ago
2.0.2
CommonJSNoneSecurity, HTTP servers and web frameworks
permissions-policy
Middleware to set the Permissions-Policy HTTP header
11.9k-11%-5 years ago
0.6.0
CommonJSBundledSecurity, HTTP servers and web frameworks
vite-plugin-csp
Create CSP meta tags and header configs from all sources in the final Vite html
11.8k+104%-4 years ago
1.1.2
ESM + CommonJSBundledBundler plugins and loaders, Security
@tracespace/xml-id
XML ID utilities for tracespace projects
11.7k---4 years ago
4.2.7
CommonJSBundledSecurity
@nichtsam/helmet
Helps secure applications by setting HTTP response headers. Inspired by [`helmet`](https://github.com/helmetjs/helmet) and [`http-helmet`](https://github.com/mcansh/http-helmet).
11.2k---6 months ago
0.3.3
ESM onlyNoneSecurity
utf8-sanitize
A performant zero-dependency utility to clean UTF-8 text, fix mojibake from latin1, verify string length, and sanitize input
11.1k+20077%-1 year ago
1.0.2
CommonJSNoneSecurity
payload-totp
Add an extra security layer to PayloadCMS using a Time-based One-time Password (TOTP).
11k+1997%-15 days ago
3.0.3
ESM onlyBundledSecurity
ssl-checker
Zero-dependency SSL/TLS certificate checker for Node.js — HTTPS, SMTP, IMAP, POP3, FTP via STARTTLS
11k+250%-5 months ago
3.0.1
ESM + CommonJSBundledCLI tools and terminal utilities, Security
is-local-address
Statically check whether a hostname or IP is a local, loopback, private, or link-local address.
11k+400%-1 month ago
2.3.6
CommonJSBundledSecurity, URLs and query strings
express-sanitizer
Express middleware for the sanitizer module.
10.8k+111%-5 years ago
1.0.6
CommonJSNoneSecurity, HTTP servers and web frameworks
@gotgenes/pi-permission-system
Permission enforcement extension for the Pi coding agent.
10.7k---today
34.0.0
ESM onlyBundledSecurity
gitleaks-secret-scanner
A powerful, intelligent wrapper for the Gitleaks engine that provides accurate and safe secret scanning for local pre-commit hooks and CI/CD pipelines.
10.6k+762%-8 months ago
2.1.1
CommonJSNoneSecurity
pin-github-action
Pin your GitHub Actions to specific versions automatically!
10.6k+62%-1 month ago
3.5.2
ESM onlyNoneSecurity
node-red-contrib-oauth2
The node-red-contrib-oauth2 is a Node-RED node that provides an OAuth2 authentication flow. This node uses the OAuth2 protocol to obtain an access token, which can be used to make authenticated API requests.
10.3k+275%-2 years ago
6.2.1
-NoneSecurity, Authentication and authorisation
got-ssrf
Protect Got requests from SSRF
10.3k+253%-2 years ago
3.0.0
ESM onlyBundledHTTP clients, Security
@socketsecurity/lib
Core utilities and infrastructure for Socket.dev security tools
10.3k---3 days ago
7.0.3
CommonJSBundledSecurity
ehbp
JavaScript client for Encrypted HTTP Body Protocol (EHBP)
10k+4612%-1 month ago
0.3.2
ESM + CommonJSBundledCryptography and hashing, Security
@mattkrick/sanitize-svg
a small script to remove script tags from SVGs
9.8k---1 year ago
0.4.1
CommonJSBundledSecurity
nestjs-doctor
The deterministic NestJS devtool that catches AI mistakes. Static analysis for NestJS with a health score, diagnostics and an interactive report.
9.8k--12 days ago
0.9.9
ESM onlyBundledSecurity, TypeScript tooling
tinfoil
Tinfoil secure OpenAI client wrapper
9.8k+1288%-1 month ago
1.2.1
ESM onlyBundledSecurity
mongo-escape
Escape variables to prevent NoSQL injection in MongoDB
9.7k+250%-9 years ago
2.0.6
CommonJSNoneSecurity, Database clients and drivers
@barkleapp/css-sanitizer
A CSS sanitizer to prevent XSS attacks
9.6k---2 years ago
1.0.0
CommonJSNoneSecurity
recaptcha2
Easy API for Google reCAPTCHA version 2 for Node.js and Express
9.5k-14%-7 years ago
1.3.3
CommonJSNoneSecurity, HTTP servers and web frameworks
decancer
A library that removes common unicode confusables/homoglyphs from strings.
9.3k+5598%-9 days ago
4.0.0
CommonJSBundledSecurity, Strings and text

12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.

  • dtrimA tool for trimming deep/lenghty javascript structures. Some potential usages are: debugging, logging or data sanitization.
  • @cap.js/widgetThe self-hosted CAPTCHA for the modern web.
  • csp-toolkitA comprehensive toolkit for working with Content Security Policy (CSP) directives in TypeScript.
  • express-security.txt[![Build Status](https://travis-ci.org/gergelyke/express-security.txt.svg?branch=master)](https://travis-ci.org/gergelyke/express-security.txt)
  • @hasna/hooksOpen source hooks library for AI coding agents - Install safety, quality, and automation hooks with a single command
  • express-csp-headerContent-Security-Policy middleware for Express
  • @varlock/nextjs-integrationdrop-in replacement for @next/env that uses varlock to load .env files with validation and extra security features
  • crypto-toolkit-tsModern Cryptography & Hashing Toolkit - a misuse-resistant, high-level cryptography library for TypeScript/Node.js
  • permixPermix is a lightweight, framework-agnostic, type-safe permissions management library for JavaScript applications on the client and server sides.
  • sasl-scram-sha-1JavaScript implementation of SCRAM-SHA-1 SASL mechanism.
  • sasl-anonymousJavaScript implementation of ANONYMOUS SASL mechanism.
  • mlkemAn ML-KEM/CRYSTALS-KYBER implementation written in TypeScript for various JavaScript runtimes
  • blitzstrikeBlitz Strike — a universal MCP security-audit toolbelt. BLITZ sweeps the attack surface, EAGLE-EYE traces source-to-sink, STRIKE verifies live. 57 attack chains, 130-tool catalog, intelligence data layer. One server, every agent.
  • ember-css-urlA helper for safely embedding URLs in style properties
  • fold-to-asciiA JavaScript port of the Apache Lucene ASCII Folding Filter that converts alphabetic, numeric, and symbolic Unicode characters which are not in the first 127 ASCII characters (the "Basic Latin" Unicode block) into a ASCII equivalents, if they exist.
  • @pulumi/compliance-policies-unit-test-helpersThis repository contains a growing set of Compliance Policies to validate your infrastructure using Pulumi's Crossguard Policy-as-Code framework.
  • express-bruteA brute-force protection middleware for express routes that rate limits incoming requests
  • @cerbos/hubClient library for interacting with Cerbos Hub from server-side Node.js applications
  • @lavamoat/webpackLavaMoat Webpack plugin for running dependencies in Compartments without eval
  • csp-typed-directivesProvides type information for all CSP directives and related headers' directives; as well as a basic utility funtion that helps convert the typed properties to the header content's policy string.
  • showdown-xss-filterXSS filter extension for showdown
  • @siva_raja/uxspUXSP JavaScript/TypeScript Browser SDK
  • miscreantMisuse resistant symmetric encryption library providing AES-SIV (RFC 5297), AES-PMAC-SIV, and STREAM constructions
  • clamdjsA ClamAV client on node.js
  • sanitize-filename-tsSanitize a string for use as a filename
  • appattest-checker-nodeNode.JS library to check/verify iOS App Attest attestations & assertions
  • express-xss-sanitizerExpress 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack.
  • permissions-policyMiddleware to set the Permissions-Policy HTTP header
  • vite-plugin-cspCreate CSP meta tags and header configs from all sources in the final Vite html
  • @tracespace/xml-idXML ID utilities for tracespace projects
  • @nichtsam/helmetHelps secure applications by setting HTTP response headers. Inspired by [`helmet`](https://github.com/helmetjs/helmet) and [`http-helmet`](https://github.com/mcansh/http-helmet).
  • utf8-sanitizeA performant zero-dependency utility to clean UTF-8 text, fix mojibake from latin1, verify string length, and sanitize input
  • payload-totpAdd an extra security layer to PayloadCMS using a Time-based One-time Password (TOTP).
  • ssl-checkerZero-dependency SSL/TLS certificate checker for Node.js — HTTPS, SMTP, IMAP, POP3, FTP via STARTTLS
  • is-local-addressStatically check whether a hostname or IP is a local, loopback, private, or link-local address.
  • express-sanitizerExpress middleware for the sanitizer module.
  • @gotgenes/pi-permission-systemPermission enforcement extension for the Pi coding agent.
  • gitleaks-secret-scannerA powerful, intelligent wrapper for the Gitleaks engine that provides accurate and safe secret scanning for local pre-commit hooks and CI/CD pipelines.
  • pin-github-actionPin your GitHub Actions to specific versions automatically!
  • node-red-contrib-oauth2The node-red-contrib-oauth2 is a Node-RED node that provides an OAuth2 authentication flow. This node uses the OAuth2 protocol to obtain an access token, which can be used to make authenticated API requests.
  • got-ssrfProtect Got requests from SSRF
  • @socketsecurity/libCore utilities and infrastructure for Socket.dev security tools
  • ehbpJavaScript client for Encrypted HTTP Body Protocol (EHBP)
  • @mattkrick/sanitize-svga small script to remove script tags from SVGs
  • nestjs-doctorThe deterministic NestJS devtool that catches AI mistakes. Static analysis for NestJS with a health score, diagnostics and an interactive report.
  • tinfoilTinfoil secure OpenAI client wrapper
  • mongo-escapeEscape variables to prevent NoSQL injection in MongoDB
  • @barkleapp/css-sanitizerA CSS sanitizer to prevent XSS attacks
  • recaptcha2Easy API for Google reCAPTCHA version 2 for Node.js and Express
  • decancerA library that removes common unicode confusables/homoglyphs from strings.