Skip to content
JS
Package category

Security

Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.

514 packages2 comparisons

Packages compared

514 packages
PackageWeekly downloads12-month change52 weeksGzipLast releaseModuleTypesCategories
ts-rate-limiter
High-performance, flexible rate limiting for TypeScript and Bun
5.6k+118%-15 days ago
0.4.10
ESM onlyBundledTypeScript tooling, Queues and background jobs
pompelmi
ClamAV for humans — scan any file and get back Clean, Malicious, or ScanError. No daemons. No cloud. No native bindings.
5.5k+4861%-4 months ago
1.20.0
ESM + CommonJSBundledHTTP servers and web frameworks, Svelte
zxcvbn-typescript
realistic password strength estimation, updated and ported to Typescript from Dan Wheeler's zxcvbn
5.5k-32%-5 years ago
5.0.1
CommonJSBundledAuthentication and authorisation, Security
@twin.org/crypto
Helper methods and classes which implement cryptographic functions
5.4k---9 days ago
0.10.0
ESM onlyBundledBlockchain and Web3, Security
vite-plugin-sri-gen
A Vite plugin to auto-generate Subresource Integrity (SRI) hashes.
5.4k+1126%-22 days ago
1.7.4
ESM onlyBundledBundler plugins and loaders, Cryptography and hashing
firebase-bolt
Firebase Bolt Security and Modeling Language Compiler
5.4k+447%-8 years ago
0.8.4
CommonJSBundledCloud SDKs, Security
sectxt
A Node.js Security.txt implementation
5.4k+142%-5 years ago
0.7.0
CommonJSBundledHTTP servers and web frameworks, Static site generators and meta-frameworks
tiny-csrf
Tiny CSRF library for use with ExpressJS
5.3k+556%-1 year ago
1.1.6
CommonJSBundledSecurity
@vierofernando/decancer-linux-arm64-musl
A library that removes common unicode confusables/homoglyphs from strings. (Binary port for linux-arm64-musl)
5.2k---9 days ago
4.0.0
CommonJSNoneSecurity, Strings and text
zxcvbn-ts
TypeScript rewrite of zxcvbn — strict types, phone detection, AI feedback, cost-to-crack estimates, and 20+ bug fixes over the original
5.1k--22 days ago
2.4.0
ESM + CommonJSBundledTypeScript tooling, Security
@stacksjs/security
The Stacks framework security.
5.1k---today
0.74.68
ESM onlyBundledTypeScript tooling, Security
vue-password-strength-meter
Interactive password strength meter based on zxcvbn
5.1k-15%-8 months ago
2.0.0
ESM + CommonJSNoneVue, Security
ldap-escape
Escape functions for LDAP filters and distinguished names to prevent LDAP injection attacks.
5k+80%-4 years ago
2.0.6
CommonJSNoneSecurity
pouchdb-security
PouchDB database access restrictions using a security document.
5k+58%-6 years ago
4.2.0
CommonJSNoneSecurity
mcp-tenant-isolation
Static analysis scanner for MCP server code and multi-tenant SaaS applications. 57 deterministic rules covering tenant isolation, tool visibility, cache key scoping, RLS, IDOR, and credential vault isolation. MCP server for AI agent integration.
5k--1 month ago
2.0.0
CommonJSBundledSecurity
neo.mjs
Neo.mjs is a self-evolving software organism: a professional end-to-end AI engineering team whose cross-model swarm inhabits live apps via Neural Link, Active Hybrid GraphRAG, DreamService, and self-healing loops.
4.9k-73%-2 months ago
13.1.0
ESM onlyNoneParsers and serialisers, Security
@csrf-armor/core
Framework-agnostic CSRF protection core functionality
4.9k---1 month ago
1.2.4
ESM onlyBundledSecurity
@tufjs/repo-mock
HTTP mocking for TUF repository requests
4.9k---3 months ago
5.0.0
CommonJSBundledSecurity
@stacksjs/tlsx
A TLS/HTTPS library with automation.
4.9k---22 days ago
0.13.19
ESM onlyBundledCryptography and hashing, TypeScript tooling
@boxlite-ai/boxlite-linux-x64-gnu
BoxLite - Embeddable micro-VM runtime for secure, isolated code execution
4.9k---1 day ago
0.10.4
CommonJSNoneSecurity
bad-words-next
JavaScript/TypeScript filter and checker for bad words aka profanity
4.9k+35%-9 months ago
3.2.0
ESM + CommonJSBundledSecurity
@boxlite-ai/boxlite
BoxLite - Embeddable micro-VM runtime for secure, isolated code execution
4.8k---1 day ago
0.10.4
ESM onlyBundledSecurity
@mapbox/sanitize-caja
sanitize html using caja and reasonable assumptions
4.7k---9 years ago
0.1.4
CommonJSNoneSecurity
@arcjet/node
Arcjet runtime security SDK for Node.js — bot protection, rate limiting, prompt injection detection, PII blocking, and WAF
4.7k---8 days ago
1.13.0
ESM onlyBundledSecurity
@csrf-armor/nextjs
CSRF protection middleware for Next.js applications
4.7k---1 month ago
1.4.5
ESM onlyBundledSecurity, Static site generators and meta-frameworks
nette-forms
Client side script for Nette Forms Component
4.6k+24%-1 year ago
3.5.3
CommonJSBundledForms, Security
zaproxy
ZAP API Client for Node.js
4.6k+1%-9 months ago
2.0.0-rc.7
CommonJSNoneSecurity
careful-downloader
🕵️‍♀️ Downloads a file and its checksums, validates the hash, and optionally extracts it if safe.
4.5k-43%-3 years ago
3.0.0
ESM onlyBundledSecurity
@promptshield/core
The heart of the PromptShield ecosystem. A zero-dependency, isomorphic TypeScript engine for detecting invisible characters, BIDI overrides, and homoglyph attacks in AI prompts.
4.5k---6 months ago
1.0.0
ESM + CommonJSBundledSecurity, Node.js utilities
@dodgeball/trust-sdk-server
Dodgeball Server SDK
4.5k---3 years ago
0.0.24
ESM + CommonJSBundledSecurity
@dodgeball/trust-sdk-client
Dodgeball Client SDK
4.5k---1 year ago
0.0.40
ESM + CommonJSBundledSecurity
solium-plugin-security
Official Solium Plugin for Security-related lint rules
4.4k+24%-8 years ago
0.1.1
CommonJSNoneBlockchain and Web3, Security
@tanker/file-reader
A promisified FileReader for browsers
4.4k---1 year ago
4.3.0
ESM + CommonJSBundledCryptography and hashing, Polyfills and shims
@promptshield/sanitizer
PromptShield sanitizer that applies safe, deterministic fixes to text based on detected prompt-injection threats such as invisible characters, markdown smuggling, and BOM artifacts.
4.4k---6 months ago
1.0.0
ESM + CommonJSBundledSecurity
@posthog/warlock
Security scanner for PostHog's agentic flows
4.4k---2 months ago
0.2.4
ESM onlyBundledSecurity
solium
Linter to identify and fix Style & Security issues in Solidity
4.3k+49%-7 years ago
1.2.5
CommonJSNoneBlockchain and Web3, Security
livr
Lightweight validator supporting Language Independent Validation Rules Specification
4.2k-16%-8 months ago
2.10.2
ESM + CommonJSBundledSchema validation, Security
@hono-rate-limiter/cloudflare
Cloudflare stores and helper functions for hono-rate-limiter.
4.2k---1 year ago
0.2.2
ESM + CommonJSBundledCloud SDKs, Security
@stackone/defender
Prompt injection defense framework for AI tool-calling
4.2k---2 days ago
0.8.3
ESM + CommonJSBundledSecurity
@flow-scanner/lightning-flow-scanner-core
A lightweight engine for Flow metadata in Node.js, and browser environments. Assess and enhance Salesforce Flow automations for best practices, security, governor limits, and performance issues.
4.1k---26 days ago
6.19.4
ESM + CommonJSBundledLinting and formatting, Security
vue-sanitize
HTML sanitizer plugin for Vue 3, powered by sanitize-html.
4.1k-22%-4 months ago
0.3.0
ESM + CommonJSBundledSecurity, Vue
entropy-string
Efficiently generate cryptographically strong random strings of specified entropy from various character sets.
4k+82%-7 years ago
4.2.0
CommonJSNoneCryptography and hashing, Security
@transmitsecurity/platform-web-sdk
Transmit Security Web SDK - Browser-only authentication and identity verification
4k---17 days ago
2.6.4
ESM + CommonJSBundledAuthentication and authorisation, Security
ban-sensitive-files
Checks filenames to be committed against a library of filename rules to prevent sensitive files in Git
4k-35%-11 months ago
1.10.11
CommonJSBundledSecurity
@exodus/safe-string
Library for generating safe strings that redact sensitive information
3.9k---4 months ago
1.5.0
ESM onlyBundledLogging, Security
@microsoft/antissrf
A library to prevent SSRF vulnerabilities in Node.js applications
3.9k---3 months ago
1.0.0
CommonJSBundledSecurity
wasm-themis
Themis is a convenient cryptographic library for data protection.
3.9k+2020%-3 years ago
0.15.0
ESM + CommonJSBundledCryptography and hashing, Security
@philiprehberger/safe-regex
Validate and sanitize regular expressions to prevent ReDoS attacks
3.8k---5 months ago
0.1.2
ESM + CommonJSBundledSecurity
@maced/api-client
Typed TypeScript client for the Maced API (api.maced.ai).
3.8k---1 month ago
0.10.1
ESM onlyBundledSecurity
@vigolium/vigolium
Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
3.8k---1 day ago
0.5.1
ESM onlyNoneSecurity

12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.

  • ts-rate-limiterHigh-performance, flexible rate limiting for TypeScript and Bun
  • pompelmiClamAV for humans — scan any file and get back Clean, Malicious, or ScanError. No daemons. No cloud. No native bindings.
  • zxcvbn-typescriptrealistic password strength estimation, updated and ported to Typescript from Dan Wheeler's zxcvbn
  • @twin.org/cryptoHelper methods and classes which implement cryptographic functions
  • vite-plugin-sri-genA Vite plugin to auto-generate Subresource Integrity (SRI) hashes.
  • firebase-boltFirebase Bolt Security and Modeling Language Compiler
  • sectxtA Node.js Security.txt implementation
  • tiny-csrfTiny CSRF library for use with ExpressJS
  • @vierofernando/decancer-linux-arm64-muslA library that removes common unicode confusables/homoglyphs from strings. (Binary port for linux-arm64-musl)
  • zxcvbn-tsTypeScript rewrite of zxcvbn — strict types, phone detection, AI feedback, cost-to-crack estimates, and 20+ bug fixes over the original
  • @stacksjs/securityThe Stacks framework security.
  • vue-password-strength-meterInteractive password strength meter based on zxcvbn
  • ldap-escapeEscape functions for LDAP filters and distinguished names to prevent LDAP injection attacks.
  • pouchdb-securityPouchDB database access restrictions using a security document.
  • mcp-tenant-isolationStatic analysis scanner for MCP server code and multi-tenant SaaS applications. 57 deterministic rules covering tenant isolation, tool visibility, cache key scoping, RLS, IDOR, and credential vault isolation. MCP server for AI agent integration.
  • neo.mjsNeo.mjs is a self-evolving software organism: a professional end-to-end AI engineering team whose cross-model swarm inhabits live apps via Neural Link, Active Hybrid GraphRAG, DreamService, and self-healing loops.
  • @csrf-armor/coreFramework-agnostic CSRF protection core functionality
  • @tufjs/repo-mockHTTP mocking for TUF repository requests
  • @stacksjs/tlsxA TLS/HTTPS library with automation.
  • @boxlite-ai/boxlite-linux-x64-gnuBoxLite - Embeddable micro-VM runtime for secure, isolated code execution
  • bad-words-nextJavaScript/TypeScript filter and checker for bad words aka profanity
  • @boxlite-ai/boxliteBoxLite - Embeddable micro-VM runtime for secure, isolated code execution
  • @mapbox/sanitize-cajasanitize html using caja and reasonable assumptions
  • @arcjet/nodeArcjet runtime security SDK for Node.js — bot protection, rate limiting, prompt injection detection, PII blocking, and WAF
  • @csrf-armor/nextjsCSRF protection middleware for Next.js applications
  • nette-formsClient side script for Nette Forms Component
  • zaproxyZAP API Client for Node.js
  • careful-downloader🕵️‍♀️ Downloads a file and its checksums, validates the hash, and optionally extracts it if safe.
  • @promptshield/coreThe heart of the PromptShield ecosystem. A zero-dependency, isomorphic TypeScript engine for detecting invisible characters, BIDI overrides, and homoglyph attacks in AI prompts.
  • @dodgeball/trust-sdk-serverDodgeball Server SDK
  • @dodgeball/trust-sdk-clientDodgeball Client SDK
  • solium-plugin-securityOfficial Solium Plugin for Security-related lint rules
  • @tanker/file-readerA promisified FileReader for browsers
  • @promptshield/sanitizerPromptShield sanitizer that applies safe, deterministic fixes to text based on detected prompt-injection threats such as invisible characters, markdown smuggling, and BOM artifacts.
  • @posthog/warlockSecurity scanner for PostHog's agentic flows
  • soliumLinter to identify and fix Style & Security issues in Solidity
  • livrLightweight validator supporting Language Independent Validation Rules Specification
  • @hono-rate-limiter/cloudflareCloudflare stores and helper functions for hono-rate-limiter.
  • @stackone/defenderPrompt injection defense framework for AI tool-calling
  • @flow-scanner/lightning-flow-scanner-coreA lightweight engine for Flow metadata in Node.js, and browser environments. Assess and enhance Salesforce Flow automations for best practices, security, governor limits, and performance issues.
  • vue-sanitizeHTML sanitizer plugin for Vue 3, powered by sanitize-html.
  • entropy-stringEfficiently generate cryptographically strong random strings of specified entropy from various character sets.
  • @transmitsecurity/platform-web-sdkTransmit Security Web SDK - Browser-only authentication and identity verification
  • ban-sensitive-filesChecks filenames to be committed against a library of filename rules to prevent sensitive files in Git
  • @exodus/safe-stringLibrary for generating safe strings that redact sensitive information
  • @microsoft/antissrfA library to prevent SSRF vulnerabilities in Node.js applications
  • wasm-themisThemis is a convenient cryptographic library for data protection.
  • @philiprehberger/safe-regexValidate and sanitize regular expressions to prevent ReDoS attacks
  • @maced/api-clientTyped TypeScript client for the Maced API (api.maced.ai).
  • @vigolium/vigoliumVigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision