Package category
Security
Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.
514 packages2 comparisons
Packages compared
514 packages
| Package | Weekly downloads | 12-month change | 52 weeks | Gzip | Last release | Module | Types | Categories |
|---|---|---|---|---|---|---|---|---|
| @mondaydotcomorg/atp-provenance CAMEL-inspired provenance security for LLM applications - track data origin and enforce security policies | 9.2k | - | - | - | 4 months ago 0.22.3 | ESM + CommonJS | Bundled | AI and machine learning, Security |
| @hint/utils-connector-tools hint tools for connectors | 9.1k | - | - | - | 2 years ago 4.0.42 | CommonJS | Bundled | Accessibility, Security |
| hint The linting tool for the web | 9.1k | -36% | - | 2 years ago 7.1.13 | CommonJS | Bundled | Accessibility, Security | |
| vue-safe-html A Vue directive which renders sanitised HTML dynamically | 9k | +152% | - | 2 years ago 3.0.1 | ESM + CommonJS | None | Security, Vue | |
| react-native-screenguard A React Native library for preventing your app from screenshots and screen recordings, with powerful event detection capabilities. | 9k | +61% | - | 5 months ago 2.0.2 | ESM + CommonJS | Bundled | Security, React | |
| @xarf/xarf XARF v4 (eXtended Abuse Reporting Format) parser and generator for JavaScript/TypeScript - supports XARF spec v4.2.0 with backward compatibility for v3 | 8.9k | - | - | - | 3 months ago 1.1.0 | ESM + CommonJS | Bundled | Parsers and serialisers, Security |
| @hint/configuration-development webhint's recommended hints configuration for development | 8.9k | - | - | - | 2 years ago 8.3.20 | CommonJS | None | Bundlers, TypeScript tooling |
| popostmate A powerful, simple, promise-based postMessage library | 8.8k | +50% | - | 3 years ago 2.0.0 | ESM + CommonJS | Bundled | Security | |
| nono-ts Node.js/TypeScript bindings for nono capability-based sandboxing | 8.7k | - | - | 7 months ago 0.3.0 | CommonJS | Bundled | Security | |
| @interlace/eslint-devkit Toolkit for building ESLint plugins in TypeScript — AST helpers, type utilities, rule-creation scaffolding, security benchmarks, and SARIF output. | 8.7k | - | - | - | 2 days ago 1.19.8 | ESM + CommonJS | Bundled | Linting and formatting, TypeScript tooling |
| ldap-authentication A simple async nodejs library for LDAP user authentication | 8.7k | -6% | - | 18 days ago 4.4.1 | ESM + CommonJS | Bundled | Authentication and authorisation, Security | |
| @vierofernando/decancer-linux-arm64-gnu A library that removes common unicode confusables/homoglyphs from strings. (Binary port for linux-arm64-gnu) | 8.7k | - | - | - | 9 days ago 4.0.0 | CommonJS | None | Security, Strings and text |
| ecc-agentshield Security auditor for AI agent configurations. Scans Claude Code setups for vulnerabilities, misconfigs, and injection risks. | 8.6k | - | - | 15 days ago 1.6.0 | ESM only | Bundled | Security | |
| dumb-passwords Guard your users from security problems that start by having dumb passwords | 8.6k | +51% | - | 10 years ago 0.2.1 | CommonJS | None | Security | |
| @sanity-labs/secret-scan Secret detection library for chat and paste contexts. 1,100+ rules from TruffleHog detectors. | 8.4k | - | - | - | 7 months ago 1.1.0 | ESM + CommonJS | Bundled | Security |
| ecc-universal Harness-native agent operating system for Codex, OpenCode, Cursor, Gemini, Claude Code, and terminal workflows - skills, hooks, rules, MCP conventions, and operator control-plane patterns | 8.2k | - | - | 16 days ago 2.2.1 | - | None | Security, Testing | |
| yub Yubico Yubikey API Client for Node.js | 8.2k | -48% | - | 10 years ago 0.11.1 | CommonJS | None | Authentication and authorisation, Security | |
| @socketsecurity/registry Socket Registry - Core utilities and infrastructure for Socket.dev security tools | 8.1k | - | - | - | 1 month ago 2.0.5 | CommonJS | Bundled | Security |
| node-red-contrib-credentials Provides a credentials node to store one or more private values; preventing export to flows or version control. | 8.1k | -66% | - | 2 years ago 0.2.3 | - | None | Security | |
| @uploadcare/signed-uploads @uploadcare/signed-uploads secures uploads to Uploadcare. On the server it mints the credentials the Upload API expects: JWTs for the `Authorization: Bearer` scheme, with optional endpoint scope and operation limits, and the legacy {secureSignature, secur | 8k | - | - | - | 2 days ago 6.22.0 | ESM + CommonJS | Bundled | Cryptography and hashing, TypeScript tooling |
| @snyk/fix Snyk fix library and utility | 8k | - | - | - | 2 days ago 1.1307.4 | CommonJS | Bundled | Security |
| fleetctl Installer for the fleetctl CLI tool | 7.9k | +372% | - | 4 days ago 4.92.0 | - | None | Security | |
| @vantasdk/vanta-mcp-server Model Context Protocol server for Vanta's security compliance platform | 7.8k | - | - | - | 6 months ago 1.2.0 | ESM only | None | Security |
| astro-remote Render remote HTML or Markdown content in Astro with full control over the output. | 7.7k | +51% | - | 1 year ago 0.3.4 | ESM only | Bundled | Security, Static site generators and meta-frameworks | |
| @hint/configuration-web-recommended webhint's recommended hints configuration for live websites | 7.4k | - | - | - | 2 years ago 8.2.24 | CommonJS | None | Accessibility, Security |
| @remix-run/html-template HTML template tag with auto-escaping for JavaScript | 7.4k | - | - | - | 4 months ago 0.3.1 | ESM only | Bundled | Security |
| content-filter A simple but powerful content-filter. Also provides protection against NoSQL (like MongoDB) injection attacks on Node.js | 7.4k | +570% | - | 8 years ago 1.1.2 | CommonJS | None | Database clients and drivers, Security | |
| @arcjet/skills Versioned Agent Skills for the Arcjet JavaScript SDK, shipped with TanStack Intent | 7.3k | - | - | - | 8 days ago 1.13.0 | ESM only | Bundled | Security |
| @hint/utils-types Common types package | 7.2k | - | - | - | 3 years ago 1.2.1 | CommonJS | Bundled | Accessibility, Security |
| @hint/utils-fs utils for filesystem | 7.2k | - | - | - | 3 years ago 1.0.16 | CommonJS | Bundled | Files and file systems, Security |
| html-escape Escape string for use in html | 7.1k | +59% | - | 10 years ago 2.0.0 | CommonJS | None | Security | |
| fix-react2shell-next Fix the React 2 Shell vulnerability (CVE-2025-66478) in Next.js apps with one command | 7.1k | - | - | 9 months ago 1.1.4 | CommonJS | None | React, Security | |
| owasp-dependency-check A Node.js wrapper for the OWASP dependency-check-cli. | 6.9k | -18% | - | 8 months ago 1.0.1 | ESM only | None | Security | |
| @remix-run/cors-middleware Middleware for handling CORS in Fetch API servers | 6.9k | - | - | - | 6 days ago 0.2.0 | ESM only | Bundled | Security |
| skillcap-lock Review what an Agent Skill can newly do, not just what bytes changed. | 6.9k | - | - | 1 month ago 0.3.0 | ESM only | None | CLI tools and terminal utilities, Security | |
| cve-lite-cli Developer-friendly CLI for scanning JS/TS projects for dependency vulnerabilities using local lockfiles and OSV | 6.9k | - | - | 2 days ago 1.37.0 | ESM only | None | Security, CLI tools and terminal utilities | |
| @remix-run/csrf-middleware Middleware for CSRF protection in Fetch API servers | 6.8k | - | - | - | 6 days ago 0.1.10 | ESM only | Bundled | Security |
| @remix-run/cop-middleware Middleware for tokenless cross-origin protection in Fetch API servers | 6.7k | - | - | - | 6 days ago 0.1.10 | ESM only | Bundled | Security |
| @tinkoff/ng-dompurify Inclusive Angular API for DOMPurify | 6.6k | - | - | - | 3 years ago 4.0.0 | ESM + CommonJS | Bundled | Security, Angular |
| local-cors-proxy Simple proxy to bypass CORS issues. This was built as a local dev only solution to enable prototyping against existing APIs without having to worry about CORS. | 6.6k | -61% | - | 6 years ago 1.1.0 | CommonJS | None | Security | |
| cc-safety-net A coding agent CLI hook - block destructive commands and secret file access | 6.6k | - | - | 2 days ago 2.4.6 | ESM only | Bundled | Security, CLI tools and terminal utilities | |
| redefine A lightweight utility for ES6 like classes and an easier ES5 aware object properties definition introducing new, performance oriented, patterns. | 6.5k | +28% | - | 11 years ago 0.2.1 | CommonJS | None | Security | |
| @mondaydotcomorg/agent-toolkit-frozen Security placeholder — claimed to prevent dependency confusion. This package name was found as an unregistered npm alias in a production codebase. | 6.3k | - | - | - | 3 months ago 0.0.1 | CommonJS | None | Security |
| nestjs-rate-limiter Highly configurable and extensible rate limiter library | 6.1k | +32% | - | 4 years ago 3.1.0 | CommonJS | None | Security | |
| @endo/stream Foundation for async iterators as streams | 6k | - | - | - | 5 months ago 1.3.1 | ESM only | Bundled | Promises and async control flow, Security |
| cap-widget The self-hosted CAPTCHA for the modern web. | 6k | - | - | 1 day ago 0.1.58 | CommonJS | Bundled | Cryptography and hashing, Security | |
| @hpke/hybridkem-x-wing A Hybrid Public Key Encryption (HPKE) module extension for X-Wing: general-purpose hybrid post-quantum KEM. | 5.9k | - | - | - | 6 months ago 0.7.0 | ESM + CommonJS | Bundled | Cryptography and hashing, Security |
| vue-coerce-props Coerce props to custom values | 5.7k | -64% | - | 7 years ago 1.0.0 | ESM + CommonJS | None | Vue, Security | |
| @doyensec/csp-evaluator npm porting of the Google CSP evaluator library | 5.7k | - | - | - | 7 years ago 1.0.3 | CommonJS | None | Security |
| @doyensec/electronegativity Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications | 5.7k | - | - | - | 3 years ago 1.10.3 | CommonJS | None | Security |
12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.
- @mondaydotcomorg/atp-provenanceCAMEL-inspired provenance security for LLM applications - track data origin and enforce security policies
- @hint/utils-connector-toolshint tools for connectors
- hintThe linting tool for the web
- vue-safe-htmlA Vue directive which renders sanitised HTML dynamically
- react-native-screenguardA React Native library for preventing your app from screenshots and screen recordings, with powerful event detection capabilities.
- @xarf/xarfXARF v4 (eXtended Abuse Reporting Format) parser and generator for JavaScript/TypeScript - supports XARF spec v4.2.0 with backward compatibility for v3
- @hint/configuration-developmentwebhint's recommended hints configuration for development
- popostmateA powerful, simple, promise-based postMessage library
- nono-tsNode.js/TypeScript bindings for nono capability-based sandboxing
- @interlace/eslint-devkitToolkit for building ESLint plugins in TypeScript — AST helpers, type utilities, rule-creation scaffolding, security benchmarks, and SARIF output.
- ldap-authenticationA simple async nodejs library for LDAP user authentication
- @vierofernando/decancer-linux-arm64-gnuA library that removes common unicode confusables/homoglyphs from strings. (Binary port for linux-arm64-gnu)
- ecc-agentshieldSecurity auditor for AI agent configurations. Scans Claude Code setups for vulnerabilities, misconfigs, and injection risks.
- dumb-passwordsGuard your users from security problems that start by having dumb passwords
- @sanity-labs/secret-scanSecret detection library for chat and paste contexts. 1,100+ rules from TruffleHog detectors.
- ecc-universalHarness-native agent operating system for Codex, OpenCode, Cursor, Gemini, Claude Code, and terminal workflows - skills, hooks, rules, MCP conventions, and operator control-plane patterns
- yubYubico Yubikey API Client for Node.js
- @socketsecurity/registrySocket Registry - Core utilities and infrastructure for Socket.dev security tools
- node-red-contrib-credentialsProvides a credentials node to store one or more private values; preventing export to flows or version control.
- @uploadcare/signed-uploads@uploadcare/signed-uploads secures uploads to Uploadcare. On the server it mints the credentials the Upload API expects: JWTs for the `Authorization: Bearer` scheme, with optional endpoint scope and operation limits, and the legacy {secureSignature, secur
- @snyk/fixSnyk fix library and utility
- fleetctlInstaller for the fleetctl CLI tool
- @vantasdk/vanta-mcp-serverModel Context Protocol server for Vanta's security compliance platform
- astro-remoteRender remote HTML or Markdown content in Astro with full control over the output.
- @hint/configuration-web-recommendedwebhint's recommended hints configuration for live websites
- @remix-run/html-templateHTML template tag with auto-escaping for JavaScript
- content-filterA simple but powerful content-filter. Also provides protection against NoSQL (like MongoDB) injection attacks on Node.js
- @arcjet/skillsVersioned Agent Skills for the Arcjet JavaScript SDK, shipped with TanStack Intent
- @hint/utils-typesCommon types package
- @hint/utils-fsutils for filesystem
- html-escapeEscape string for use in html
- fix-react2shell-nextFix the React 2 Shell vulnerability (CVE-2025-66478) in Next.js apps with one command
- owasp-dependency-checkA Node.js wrapper for the OWASP dependency-check-cli.
- @remix-run/cors-middlewareMiddleware for handling CORS in Fetch API servers
- skillcap-lockReview what an Agent Skill can newly do, not just what bytes changed.
- cve-lite-cliDeveloper-friendly CLI for scanning JS/TS projects for dependency vulnerabilities using local lockfiles and OSV
- @remix-run/csrf-middlewareMiddleware for CSRF protection in Fetch API servers
- @remix-run/cop-middlewareMiddleware for tokenless cross-origin protection in Fetch API servers
- @tinkoff/ng-dompurifyInclusive Angular API for DOMPurify
- local-cors-proxySimple proxy to bypass CORS issues. This was built as a local dev only solution to enable prototyping against existing APIs without having to worry about CORS.
- cc-safety-netA coding agent CLI hook - block destructive commands and secret file access
- redefineA lightweight utility for ES6 like classes and an easier ES5 aware object properties definition introducing new, performance oriented, patterns.
- @mondaydotcomorg/agent-toolkit-frozenSecurity placeholder — claimed to prevent dependency confusion. This package name was found as an unregistered npm alias in a production codebase.
- nestjs-rate-limiterHighly configurable and extensible rate limiter library
- @endo/streamFoundation for async iterators as streams
- cap-widgetThe self-hosted CAPTCHA for the modern web.
- @hpke/hybridkem-x-wingA Hybrid Public Key Encryption (HPKE) module extension for X-Wing: general-purpose hybrid post-quantum KEM.
- vue-coerce-propsCoerce props to custom values
- @doyensec/csp-evaluatornpm porting of the Google CSP evaluator library
- @doyensec/electronegativityElectronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications