Skip to content
JS
Package category

Security

Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.

514 packages2 comparisons

Packages compared

514 packages
PackageWeekly downloads12-month change52 weeksGzipLast releaseModuleTypesCategories
@mondaydotcomorg/atp-provenance
CAMEL-inspired provenance security for LLM applications - track data origin and enforce security policies
9.2k---4 months ago
0.22.3
ESM + CommonJSBundledAI and machine learning, Security
@hint/utils-connector-tools
hint tools for connectors
9.1k---2 years ago
4.0.42
CommonJSBundledAccessibility, Security
hint
The linting tool for the web
9.1k-36%-2 years ago
7.1.13
CommonJSBundledAccessibility, Security
vue-safe-html
A Vue directive which renders sanitised HTML dynamically
9k+152%-2 years ago
3.0.1
ESM + CommonJSNoneSecurity, Vue
react-native-screenguard
A React Native library for preventing your app from screenshots and screen recordings, with powerful event detection capabilities.
9k+61%-5 months ago
2.0.2
ESM + CommonJSBundledSecurity, React
@xarf/xarf
XARF v4 (eXtended Abuse Reporting Format) parser and generator for JavaScript/TypeScript - supports XARF spec v4.2.0 with backward compatibility for v3
8.9k---3 months ago
1.1.0
ESM + CommonJSBundledParsers and serialisers, Security
@hint/configuration-development
webhint's recommended hints configuration for development
8.9k---2 years ago
8.3.20
CommonJSNoneBundlers, TypeScript tooling
popostmate
A powerful, simple, promise-based postMessage library
8.8k+50%-3 years ago
2.0.0
ESM + CommonJSBundledSecurity
nono-ts
Node.js/TypeScript bindings for nono capability-based sandboxing
8.7k--7 months ago
0.3.0
CommonJSBundledSecurity
@interlace/eslint-devkit
Toolkit for building ESLint plugins in TypeScript — AST helpers, type utilities, rule-creation scaffolding, security benchmarks, and SARIF output.
8.7k---2 days ago
1.19.8
ESM + CommonJSBundledLinting and formatting, TypeScript tooling
ldap-authentication
A simple async nodejs library for LDAP user authentication
8.7k-6%-18 days ago
4.4.1
ESM + CommonJSBundledAuthentication and authorisation, Security
@vierofernando/decancer-linux-arm64-gnu
A library that removes common unicode confusables/homoglyphs from strings. (Binary port for linux-arm64-gnu)
8.7k---9 days ago
4.0.0
CommonJSNoneSecurity, Strings and text
ecc-agentshield
Security auditor for AI agent configurations. Scans Claude Code setups for vulnerabilities, misconfigs, and injection risks.
8.6k--15 days ago
1.6.0
ESM onlyBundledSecurity
dumb-passwords
Guard your users from security problems that start by having dumb passwords
8.6k+51%-10 years ago
0.2.1
CommonJSNoneSecurity
@sanity-labs/secret-scan
Secret detection library for chat and paste contexts. 1,100+ rules from TruffleHog detectors.
8.4k---7 months ago
1.1.0
ESM + CommonJSBundledSecurity
ecc-universal
Harness-native agent operating system for Codex, OpenCode, Cursor, Gemini, Claude Code, and terminal workflows - skills, hooks, rules, MCP conventions, and operator control-plane patterns
8.2k--16 days ago
2.2.1
-NoneSecurity, Testing
yub
Yubico Yubikey API Client for Node.js
8.2k-48%-10 years ago
0.11.1
CommonJSNoneAuthentication and authorisation, Security
@socketsecurity/registry
Socket Registry - Core utilities and infrastructure for Socket.dev security tools
8.1k---1 month ago
2.0.5
CommonJSBundledSecurity
node-red-contrib-credentials
Provides a credentials node to store one or more private values; preventing export to flows or version control.
8.1k-66%-2 years ago
0.2.3
-NoneSecurity
@uploadcare/signed-uploads
@uploadcare/signed-uploads secures uploads to Uploadcare. On the server it mints the credentials the Upload API expects: JWTs for the `Authorization: Bearer` scheme, with optional endpoint scope and operation limits, and the legacy {secureSignature, secur
8k---2 days ago
6.22.0
ESM + CommonJSBundledCryptography and hashing, TypeScript tooling
@snyk/fix
Snyk fix library and utility
8k---2 days ago
1.1307.4
CommonJSBundledSecurity
fleetctl
Installer for the fleetctl CLI tool
7.9k+372%-4 days ago
4.92.0
-NoneSecurity
@vantasdk/vanta-mcp-server
Model Context Protocol server for Vanta's security compliance platform
7.8k---6 months ago
1.2.0
ESM onlyNoneSecurity
astro-remote
Render remote HTML or Markdown content in Astro with full control over the output.
7.7k+51%-1 year ago
0.3.4
ESM onlyBundledSecurity, Static site generators and meta-frameworks
@hint/configuration-web-recommended
webhint's recommended hints configuration for live websites
7.4k---2 years ago
8.2.24
CommonJSNoneAccessibility, Security
@remix-run/html-template
HTML template tag with auto-escaping for JavaScript
7.4k---4 months ago
0.3.1
ESM onlyBundledSecurity
content-filter
A simple but powerful content-filter. Also provides protection against NoSQL (like MongoDB) injection attacks on Node.js
7.4k+570%-8 years ago
1.1.2
CommonJSNoneDatabase clients and drivers, Security
@arcjet/skills
Versioned Agent Skills for the Arcjet JavaScript SDK, shipped with TanStack Intent
7.3k---8 days ago
1.13.0
ESM onlyBundledSecurity
@hint/utils-types
Common types package
7.2k---3 years ago
1.2.1
CommonJSBundledAccessibility, Security
@hint/utils-fs
utils for filesystem
7.2k---3 years ago
1.0.16
CommonJSBundledFiles and file systems, Security
html-escape
Escape string for use in html
7.1k+59%-10 years ago
2.0.0
CommonJSNoneSecurity
fix-react2shell-next
Fix the React 2 Shell vulnerability (CVE-2025-66478) in Next.js apps with one command
7.1k--9 months ago
1.1.4
CommonJSNoneReact, Security
owasp-dependency-check
A Node.js wrapper for the OWASP dependency-check-cli.
6.9k-18%-8 months ago
1.0.1
ESM onlyNoneSecurity
@remix-run/cors-middleware
Middleware for handling CORS in Fetch API servers
6.9k---6 days ago
0.2.0
ESM onlyBundledSecurity
skillcap-lock
Review what an Agent Skill can newly do, not just what bytes changed.
6.9k--1 month ago
0.3.0
ESM onlyNoneCLI tools and terminal utilities, Security
cve-lite-cli
Developer-friendly CLI for scanning JS/TS projects for dependency vulnerabilities using local lockfiles and OSV
6.9k--2 days ago
1.37.0
ESM onlyNoneSecurity, CLI tools and terminal utilities
@remix-run/csrf-middleware
Middleware for CSRF protection in Fetch API servers
6.8k---6 days ago
0.1.10
ESM onlyBundledSecurity
@remix-run/cop-middleware
Middleware for tokenless cross-origin protection in Fetch API servers
6.7k---6 days ago
0.1.10
ESM onlyBundledSecurity
@tinkoff/ng-dompurify
Inclusive Angular API for DOMPurify
6.6k---3 years ago
4.0.0
ESM + CommonJSBundledSecurity, Angular
local-cors-proxy
Simple proxy to bypass CORS issues. This was built as a local dev only solution to enable prototyping against existing APIs without having to worry about CORS.
6.6k-61%-6 years ago
1.1.0
CommonJSNoneSecurity
cc-safety-net
A coding agent CLI hook - block destructive commands and secret file access
6.6k--2 days ago
2.4.6
ESM onlyBundledSecurity, CLI tools and terminal utilities
redefine
A lightweight utility for ES6 like classes and an easier ES5 aware object properties definition introducing new, performance oriented, patterns.
6.5k+28%-11 years ago
0.2.1
CommonJSNoneSecurity
@mondaydotcomorg/agent-toolkit-frozen
Security placeholder — claimed to prevent dependency confusion. This package name was found as an unregistered npm alias in a production codebase.
6.3k---3 months ago
0.0.1
CommonJSNoneSecurity
nestjs-rate-limiter
Highly configurable and extensible rate limiter library
6.1k+32%-4 years ago
3.1.0
CommonJSNoneSecurity
@endo/stream
Foundation for async iterators as streams
6k---5 months ago
1.3.1
ESM onlyBundledPromises and async control flow, Security
cap-widget
The self-hosted CAPTCHA for the modern web.
6k--1 day ago
0.1.58
CommonJSBundledCryptography and hashing, Security
@hpke/hybridkem-x-wing
A Hybrid Public Key Encryption (HPKE) module extension for X-Wing: general-purpose hybrid post-quantum KEM.
5.9k---6 months ago
0.7.0
ESM + CommonJSBundledCryptography and hashing, Security
vue-coerce-props
Coerce props to custom values
5.7k-64%-7 years ago
1.0.0
ESM + CommonJSNoneVue, Security
@doyensec/csp-evaluator
npm porting of the Google CSP evaluator library
5.7k---7 years ago
1.0.3
CommonJSNoneSecurity
@doyensec/electronegativity
Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications
5.7k---3 years ago
1.10.3
CommonJSNoneSecurity

12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.

  • @mondaydotcomorg/atp-provenanceCAMEL-inspired provenance security for LLM applications - track data origin and enforce security policies
  • @hint/utils-connector-toolshint tools for connectors
  • hintThe linting tool for the web
  • vue-safe-htmlA Vue directive which renders sanitised HTML dynamically
  • react-native-screenguardA React Native library for preventing your app from screenshots and screen recordings, with powerful event detection capabilities.
  • @xarf/xarfXARF v4 (eXtended Abuse Reporting Format) parser and generator for JavaScript/TypeScript - supports XARF spec v4.2.0 with backward compatibility for v3
  • @hint/configuration-developmentwebhint's recommended hints configuration for development
  • popostmateA powerful, simple, promise-based postMessage library
  • nono-tsNode.js/TypeScript bindings for nono capability-based sandboxing
  • @interlace/eslint-devkitToolkit for building ESLint plugins in TypeScript — AST helpers, type utilities, rule-creation scaffolding, security benchmarks, and SARIF output.
  • ldap-authenticationA simple async nodejs library for LDAP user authentication
  • @vierofernando/decancer-linux-arm64-gnuA library that removes common unicode confusables/homoglyphs from strings. (Binary port for linux-arm64-gnu)
  • ecc-agentshieldSecurity auditor for AI agent configurations. Scans Claude Code setups for vulnerabilities, misconfigs, and injection risks.
  • dumb-passwordsGuard your users from security problems that start by having dumb passwords
  • @sanity-labs/secret-scanSecret detection library for chat and paste contexts. 1,100+ rules from TruffleHog detectors.
  • ecc-universalHarness-native agent operating system for Codex, OpenCode, Cursor, Gemini, Claude Code, and terminal workflows - skills, hooks, rules, MCP conventions, and operator control-plane patterns
  • yubYubico Yubikey API Client for Node.js
  • @socketsecurity/registrySocket Registry - Core utilities and infrastructure for Socket.dev security tools
  • node-red-contrib-credentialsProvides a credentials node to store one or more private values; preventing export to flows or version control.
  • @uploadcare/signed-uploads@uploadcare/signed-uploads secures uploads to Uploadcare. On the server it mints the credentials the Upload API expects: JWTs for the `Authorization: Bearer` scheme, with optional endpoint scope and operation limits, and the legacy {secureSignature, secur
  • @snyk/fixSnyk fix library and utility
  • fleetctlInstaller for the fleetctl CLI tool
  • @vantasdk/vanta-mcp-serverModel Context Protocol server for Vanta's security compliance platform
  • astro-remoteRender remote HTML or Markdown content in Astro with full control over the output.
  • @hint/configuration-web-recommendedwebhint's recommended hints configuration for live websites
  • @remix-run/html-templateHTML template tag with auto-escaping for JavaScript
  • content-filterA simple but powerful content-filter. Also provides protection against NoSQL (like MongoDB) injection attacks on Node.js
  • @arcjet/skillsVersioned Agent Skills for the Arcjet JavaScript SDK, shipped with TanStack Intent
  • @hint/utils-typesCommon types package
  • @hint/utils-fsutils for filesystem
  • html-escapeEscape string for use in html
  • fix-react2shell-nextFix the React 2 Shell vulnerability (CVE-2025-66478) in Next.js apps with one command
  • owasp-dependency-checkA Node.js wrapper for the OWASP dependency-check-cli.
  • @remix-run/cors-middlewareMiddleware for handling CORS in Fetch API servers
  • skillcap-lockReview what an Agent Skill can newly do, not just what bytes changed.
  • cve-lite-cliDeveloper-friendly CLI for scanning JS/TS projects for dependency vulnerabilities using local lockfiles and OSV
  • @remix-run/csrf-middlewareMiddleware for CSRF protection in Fetch API servers
  • @remix-run/cop-middlewareMiddleware for tokenless cross-origin protection in Fetch API servers
  • @tinkoff/ng-dompurifyInclusive Angular API for DOMPurify
  • local-cors-proxySimple proxy to bypass CORS issues. This was built as a local dev only solution to enable prototyping against existing APIs without having to worry about CORS.
  • cc-safety-netA coding agent CLI hook - block destructive commands and secret file access
  • redefineA lightweight utility for ES6 like classes and an easier ES5 aware object properties definition introducing new, performance oriented, patterns.
  • @mondaydotcomorg/agent-toolkit-frozenSecurity placeholder — claimed to prevent dependency confusion. This package name was found as an unregistered npm alias in a production codebase.
  • nestjs-rate-limiterHighly configurable and extensible rate limiter library
  • @endo/streamFoundation for async iterators as streams
  • cap-widgetThe self-hosted CAPTCHA for the modern web.
  • @hpke/hybridkem-x-wingA Hybrid Public Key Encryption (HPKE) module extension for X-Wing: general-purpose hybrid post-quantum KEM.
  • vue-coerce-propsCoerce props to custom values
  • @doyensec/csp-evaluatornpm porting of the Google CSP evaluator library
  • @doyensec/electronegativityElectronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications