Package category
Security
Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.
514 packages2 comparisons
Packages compared
514 packages
| Package | Weekly downloads | 12-month change | 52 weeks | Gzip | Last release | Module | Types | Categories |
|---|---|---|---|---|---|---|---|---|
| ts-rate-limiter High-performance, flexible rate limiting for TypeScript and Bun | 5.6k | +118% | - | 15 days ago 0.4.10 | ESM only | Bundled | TypeScript tooling, Queues and background jobs | |
| pompelmi ClamAV for humans — scan any file and get back Clean, Malicious, or ScanError. No daemons. No cloud. No native bindings. | 5.5k | +4861% | - | 4 months ago 1.20.0 | ESM + CommonJS | Bundled | HTTP servers and web frameworks, Svelte | |
| zxcvbn-typescript realistic password strength estimation, updated and ported to Typescript from Dan Wheeler's zxcvbn | 5.5k | -32% | - | 5 years ago 5.0.1 | CommonJS | Bundled | Authentication and authorisation, Security | |
| @twin.org/crypto Helper methods and classes which implement cryptographic functions | 5.4k | - | - | - | 9 days ago 0.10.0 | ESM only | Bundled | Blockchain and Web3, Security |
| vite-plugin-sri-gen A Vite plugin to auto-generate Subresource Integrity (SRI) hashes. | 5.4k | +1126% | - | 22 days ago 1.7.4 | ESM only | Bundled | Bundler plugins and loaders, Cryptography and hashing | |
| firebase-bolt Firebase Bolt Security and Modeling Language Compiler | 5.4k | +447% | - | 8 years ago 0.8.4 | CommonJS | Bundled | Cloud SDKs, Security | |
| sectxt A Node.js Security.txt implementation | 5.4k | +142% | - | 5 years ago 0.7.0 | CommonJS | Bundled | HTTP servers and web frameworks, Static site generators and meta-frameworks | |
| tiny-csrf Tiny CSRF library for use with ExpressJS | 5.3k | +556% | - | 1 year ago 1.1.6 | CommonJS | Bundled | Security | |
| @vierofernando/decancer-linux-arm64-musl A library that removes common unicode confusables/homoglyphs from strings. (Binary port for linux-arm64-musl) | 5.2k | - | - | - | 9 days ago 4.0.0 | CommonJS | None | Security, Strings and text |
| zxcvbn-ts TypeScript rewrite of zxcvbn — strict types, phone detection, AI feedback, cost-to-crack estimates, and 20+ bug fixes over the original | 5.1k | - | - | 22 days ago 2.4.0 | ESM + CommonJS | Bundled | TypeScript tooling, Security | |
| @stacksjs/security The Stacks framework security. | 5.1k | - | - | - | today 0.74.68 | ESM only | Bundled | TypeScript tooling, Security |
| vue-password-strength-meter Interactive password strength meter based on zxcvbn | 5.1k | -15% | - | 8 months ago 2.0.0 | ESM + CommonJS | None | Vue, Security | |
| ldap-escape Escape functions for LDAP filters and distinguished names to prevent LDAP injection attacks. | 5k | +80% | - | 4 years ago 2.0.6 | CommonJS | None | Security | |
| pouchdb-security PouchDB database access restrictions using a security document. | 5k | +58% | - | 6 years ago 4.2.0 | CommonJS | None | Security | |
| mcp-tenant-isolation Static analysis scanner for MCP server code and multi-tenant SaaS applications. 57 deterministic rules covering tenant isolation, tool visibility, cache key scoping, RLS, IDOR, and credential vault isolation. MCP server for AI agent integration. | 5k | - | - | 1 month ago 2.0.0 | CommonJS | Bundled | Security | |
| neo.mjs Neo.mjs is a self-evolving software organism: a professional end-to-end AI engineering team whose cross-model swarm inhabits live apps via Neural Link, Active Hybrid GraphRAG, DreamService, and self-healing loops. | 4.9k | -73% | - | 2 months ago 13.1.0 | ESM only | None | Parsers and serialisers, Security | |
| @csrf-armor/core Framework-agnostic CSRF protection core functionality | 4.9k | - | - | - | 1 month ago 1.2.4 | ESM only | Bundled | Security |
| @tufjs/repo-mock HTTP mocking for TUF repository requests | 4.9k | - | - | - | 3 months ago 5.0.0 | CommonJS | Bundled | Security |
| @stacksjs/tlsx A TLS/HTTPS library with automation. | 4.9k | - | - | - | 22 days ago 0.13.19 | ESM only | Bundled | Cryptography and hashing, TypeScript tooling |
| @boxlite-ai/boxlite-linux-x64-gnu BoxLite - Embeddable micro-VM runtime for secure, isolated code execution | 4.9k | - | - | - | 1 day ago 0.10.4 | CommonJS | None | Security |
| bad-words-next JavaScript/TypeScript filter and checker for bad words aka profanity | 4.9k | +35% | - | 9 months ago 3.2.0 | ESM + CommonJS | Bundled | Security | |
| @boxlite-ai/boxlite BoxLite - Embeddable micro-VM runtime for secure, isolated code execution | 4.8k | - | - | - | 1 day ago 0.10.4 | ESM only | Bundled | Security |
| @mapbox/sanitize-caja sanitize html using caja and reasonable assumptions | 4.7k | - | - | - | 9 years ago 0.1.4 | CommonJS | None | Security |
| @arcjet/node Arcjet runtime security SDK for Node.js — bot protection, rate limiting, prompt injection detection, PII blocking, and WAF | 4.7k | - | - | - | 8 days ago 1.13.0 | ESM only | Bundled | Security |
| @csrf-armor/nextjs CSRF protection middleware for Next.js applications | 4.7k | - | - | - | 1 month ago 1.4.5 | ESM only | Bundled | Security, Static site generators and meta-frameworks |
| nette-forms Client side script for Nette Forms Component | 4.6k | +24% | - | 1 year ago 3.5.3 | CommonJS | Bundled | Forms, Security | |
| zaproxy ZAP API Client for Node.js | 4.6k | +1% | - | 9 months ago 2.0.0-rc.7 | CommonJS | None | Security | |
| careful-downloader 🕵️♀️ Downloads a file and its checksums, validates the hash, and optionally extracts it if safe. | 4.5k | -43% | - | 3 years ago 3.0.0 | ESM only | Bundled | Security | |
| @promptshield/core The heart of the PromptShield ecosystem. A zero-dependency, isomorphic TypeScript engine for detecting invisible characters, BIDI overrides, and homoglyph attacks in AI prompts. | 4.5k | - | - | - | 6 months ago 1.0.0 | ESM + CommonJS | Bundled | Security, Node.js utilities |
| @dodgeball/trust-sdk-server Dodgeball Server SDK | 4.5k | - | - | - | 3 years ago 0.0.24 | ESM + CommonJS | Bundled | Security |
| @dodgeball/trust-sdk-client Dodgeball Client SDK | 4.5k | - | - | - | 1 year ago 0.0.40 | ESM + CommonJS | Bundled | Security |
| solium-plugin-security Official Solium Plugin for Security-related lint rules | 4.4k | +24% | - | 8 years ago 0.1.1 | CommonJS | None | Blockchain and Web3, Security | |
| @tanker/file-reader A promisified FileReader for browsers | 4.4k | - | - | - | 1 year ago 4.3.0 | ESM + CommonJS | Bundled | Cryptography and hashing, Polyfills and shims |
| @promptshield/sanitizer PromptShield sanitizer that applies safe, deterministic fixes to text based on detected prompt-injection threats such as invisible characters, markdown smuggling, and BOM artifacts. | 4.4k | - | - | - | 6 months ago 1.0.0 | ESM + CommonJS | Bundled | Security |
| @posthog/warlock Security scanner for PostHog's agentic flows | 4.4k | - | - | - | 2 months ago 0.2.4 | ESM only | Bundled | Security |
| solium Linter to identify and fix Style & Security issues in Solidity | 4.3k | +49% | - | 7 years ago 1.2.5 | CommonJS | None | Blockchain and Web3, Security | |
| livr Lightweight validator supporting Language Independent Validation Rules Specification | 4.2k | -16% | - | 8 months ago 2.10.2 | ESM + CommonJS | Bundled | Schema validation, Security | |
| @hono-rate-limiter/cloudflare Cloudflare stores and helper functions for hono-rate-limiter. | 4.2k | - | - | - | 1 year ago 0.2.2 | ESM + CommonJS | Bundled | Cloud SDKs, Security |
| @stackone/defender Prompt injection defense framework for AI tool-calling | 4.2k | - | - | - | 2 days ago 0.8.3 | ESM + CommonJS | Bundled | Security |
| @flow-scanner/lightning-flow-scanner-core A lightweight engine for Flow metadata in Node.js, and browser environments. Assess and enhance Salesforce Flow automations for best practices, security, governor limits, and performance issues. | 4.1k | - | - | - | 26 days ago 6.19.4 | ESM + CommonJS | Bundled | Linting and formatting, Security |
| vue-sanitize HTML sanitizer plugin for Vue 3, powered by sanitize-html. | 4.1k | -22% | - | 4 months ago 0.3.0 | ESM + CommonJS | Bundled | Security, Vue | |
| entropy-string Efficiently generate cryptographically strong random strings of specified entropy from various character sets. | 4k | +82% | - | 7 years ago 4.2.0 | CommonJS | None | Cryptography and hashing, Security | |
| @transmitsecurity/platform-web-sdk Transmit Security Web SDK - Browser-only authentication and identity verification | 4k | - | - | - | 17 days ago 2.6.4 | ESM + CommonJS | Bundled | Authentication and authorisation, Security |
| ban-sensitive-files Checks filenames to be committed against a library of filename rules to prevent sensitive files in Git | 4k | -35% | - | 11 months ago 1.10.11 | CommonJS | Bundled | Security | |
| @exodus/safe-string Library for generating safe strings that redact sensitive information | 3.9k | - | - | - | 4 months ago 1.5.0 | ESM only | Bundled | Logging, Security |
| @microsoft/antissrf A library to prevent SSRF vulnerabilities in Node.js applications | 3.9k | - | - | - | 3 months ago 1.0.0 | CommonJS | Bundled | Security |
| wasm-themis Themis is a convenient cryptographic library for data protection. | 3.9k | +2020% | - | 3 years ago 0.15.0 | ESM + CommonJS | Bundled | Cryptography and hashing, Security | |
| @philiprehberger/safe-regex Validate and sanitize regular expressions to prevent ReDoS attacks | 3.8k | - | - | - | 5 months ago 0.1.2 | ESM + CommonJS | Bundled | Security |
| @maced/api-client Typed TypeScript client for the Maced API (api.maced.ai). | 3.8k | - | - | - | 1 month ago 0.10.1 | ESM only | Bundled | Security |
| @vigolium/vigolium Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision | 3.8k | - | - | - | 1 day ago 0.5.1 | ESM only | None | Security |
12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.
- ts-rate-limiterHigh-performance, flexible rate limiting for TypeScript and Bun
- pompelmiClamAV for humans — scan any file and get back Clean, Malicious, or ScanError. No daemons. No cloud. No native bindings.
- zxcvbn-typescriptrealistic password strength estimation, updated and ported to Typescript from Dan Wheeler's zxcvbn
- @twin.org/cryptoHelper methods and classes which implement cryptographic functions
- vite-plugin-sri-genA Vite plugin to auto-generate Subresource Integrity (SRI) hashes.
- firebase-boltFirebase Bolt Security and Modeling Language Compiler
- sectxtA Node.js Security.txt implementation
- tiny-csrfTiny CSRF library for use with ExpressJS
- @vierofernando/decancer-linux-arm64-muslA library that removes common unicode confusables/homoglyphs from strings. (Binary port for linux-arm64-musl)
- zxcvbn-tsTypeScript rewrite of zxcvbn — strict types, phone detection, AI feedback, cost-to-crack estimates, and 20+ bug fixes over the original
- @stacksjs/securityThe Stacks framework security.
- vue-password-strength-meterInteractive password strength meter based on zxcvbn
- ldap-escapeEscape functions for LDAP filters and distinguished names to prevent LDAP injection attacks.
- pouchdb-securityPouchDB database access restrictions using a security document.
- mcp-tenant-isolationStatic analysis scanner for MCP server code and multi-tenant SaaS applications. 57 deterministic rules covering tenant isolation, tool visibility, cache key scoping, RLS, IDOR, and credential vault isolation. MCP server for AI agent integration.
- neo.mjsNeo.mjs is a self-evolving software organism: a professional end-to-end AI engineering team whose cross-model swarm inhabits live apps via Neural Link, Active Hybrid GraphRAG, DreamService, and self-healing loops.
- @csrf-armor/coreFramework-agnostic CSRF protection core functionality
- @tufjs/repo-mockHTTP mocking for TUF repository requests
- @stacksjs/tlsxA TLS/HTTPS library with automation.
- @boxlite-ai/boxlite-linux-x64-gnuBoxLite - Embeddable micro-VM runtime for secure, isolated code execution
- bad-words-nextJavaScript/TypeScript filter and checker for bad words aka profanity
- @boxlite-ai/boxliteBoxLite - Embeddable micro-VM runtime for secure, isolated code execution
- @mapbox/sanitize-cajasanitize html using caja and reasonable assumptions
- @arcjet/nodeArcjet runtime security SDK for Node.js — bot protection, rate limiting, prompt injection detection, PII blocking, and WAF
- @csrf-armor/nextjsCSRF protection middleware for Next.js applications
- nette-formsClient side script for Nette Forms Component
- zaproxyZAP API Client for Node.js
- careful-downloader🕵️♀️ Downloads a file and its checksums, validates the hash, and optionally extracts it if safe.
- @promptshield/coreThe heart of the PromptShield ecosystem. A zero-dependency, isomorphic TypeScript engine for detecting invisible characters, BIDI overrides, and homoglyph attacks in AI prompts.
- @dodgeball/trust-sdk-serverDodgeball Server SDK
- @dodgeball/trust-sdk-clientDodgeball Client SDK
- solium-plugin-securityOfficial Solium Plugin for Security-related lint rules
- @tanker/file-readerA promisified FileReader for browsers
- @promptshield/sanitizerPromptShield sanitizer that applies safe, deterministic fixes to text based on detected prompt-injection threats such as invisible characters, markdown smuggling, and BOM artifacts.
- @posthog/warlockSecurity scanner for PostHog's agentic flows
- soliumLinter to identify and fix Style & Security issues in Solidity
- livrLightweight validator supporting Language Independent Validation Rules Specification
- @hono-rate-limiter/cloudflareCloudflare stores and helper functions for hono-rate-limiter.
- @stackone/defenderPrompt injection defense framework for AI tool-calling
- @flow-scanner/lightning-flow-scanner-coreA lightweight engine for Flow metadata in Node.js, and browser environments. Assess and enhance Salesforce Flow automations for best practices, security, governor limits, and performance issues.
- vue-sanitizeHTML sanitizer plugin for Vue 3, powered by sanitize-html.
- entropy-stringEfficiently generate cryptographically strong random strings of specified entropy from various character sets.
- @transmitsecurity/platform-web-sdkTransmit Security Web SDK - Browser-only authentication and identity verification
- ban-sensitive-filesChecks filenames to be committed against a library of filename rules to prevent sensitive files in Git
- @exodus/safe-stringLibrary for generating safe strings that redact sensitive information
- @microsoft/antissrfA library to prevent SSRF vulnerabilities in Node.js applications
- wasm-themisThemis is a convenient cryptographic library for data protection.
- @philiprehberger/safe-regexValidate and sanitize regular expressions to prevent ReDoS attacks
- @maced/api-clientTyped TypeScript client for the Maced API (api.maced.ai).
- @vigolium/vigoliumVigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision