Skip to content
JS
Package category

Security

Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.

514 packages2 comparisons

Packages compared

514 packages
PackageWeekly downloads12-month change52 weeksGzipLast releaseModuleTypesCategories
react-sanitized-html
A React component that will sanitize user-inputted HTML code, using the popular sanitize-html package
3.8k-54%-8 years ago
2.0.0
ESM + CommonJSNoneSecurity, React
@sp-uvb/vue
Official Vue.js composables for Universal Verification Broker (UVB)
3.7k---3 months ago
0.2.1
ESM + CommonJSBundledVue, Authentication and authorisation
@sp-uvb/client
Universal Verification Broker (UVB) TypeScript/JavaScript SDK
3.7k---3 months ago
0.2.1
ESM + CommonJSBundledAuthentication and authorisation, Security
@jongleberry/vurst-html
Rust + N-API: HTML sanitization, extraction, and boilerstrip.
3.7k---17 days ago
0.4.3
CommonJSBundledSecurity
@pexxi/fold-to-ascii-ts
A JavaScript port of the Apache Lucene ASCII Folding Filter that converts alphabetic, numeric, and symbolic Unicode characters which are not in the first 127 ASCII characters (the "Basic Latin" Unicode block) into a ASCII equivalents, if they exist.
3.7k---6 years ago
5.1.1
CommonJSNoneSecurity
@keep-lts/xlsx
Security-maintained drop-in fork of xlsx. Back-ports SheetJS's fixes for CVE-2023-30533 (prototype pollution) and CVE-2024-22363 (ReDoS) onto the frozen npm 0.18.5 baseline. Original API unchanged.
3.7k---3 months ago
0.18.6
ESM + CommonJSBundledPDF and documents, Security
krb5
Kerberos library bindings for Node.js
3.7k+363%-4 years ago
0.5.5
CommonJSNoneAuthentication and authorisation, Security
@devexpress/eslint-plugin-dx-security
An ESLint® plugin that detects and mitigates security-related issues for DevExpress projects.
3.6k---14 days ago
0.2.10
ESM onlyNoneLinting and formatting, Security
edge-core-js
Edge account & wallet management library
3.6k+270%-2 days ago
2.49.0
ESM + CommonJSBundledBlockchain and Web3, Security
strict-csp
Enables a hash-based strict Content Security Policy for static HTML files and single page applications.
3.6k+60%-1 year ago
1.1.2
CommonJSBundledSecurity
@jongleberry/vurst-prompt
Prompt-injection helper utilities for vurst.
3.6k---17 days ago
0.4.3
CommonJSBundledSecurity
security
Utility methods for escaping according to OWASP.
3.6k-27%-14 years ago
1.0.0
-NoneSecurity
phc-argon2
Node.JS Argon2 password hashing algorithm following the PHC string format
3.5k-5%-3 years ago
1.1.4
CommonJSNoneCryptography and hashing, Security
gitleaks-secret-scanner-fixed
A powerful, intelligent wrapper for the Gitleaks engine that provides accurate and safe secret scanning for local pre-commit hooks and CI/CD pipelines. Fork with fixed tar vulnerability.
3.5k--7 months ago
2.1.3
CommonJSNoneParsers and serialisers, Security
virgil-sdk
Virgil Security Services SDK
3.5k-20%-3 years ago
6.2.0
ESM + CommonJSBundledCryptography and hashing, Security
rnsec
Zero-config security scanner for React Native & Expo apps. Find vulnerabilities with 68 security rules covering Android, iOS, and React Native specific issues.
3.4k--5 months ago
1.3.0
ESM onlyNoneSecurity, React
@taiga-ui/dompurify
Inclusive Angular API for DOMPurify
3.4k---11 months ago
5.0.1
ESM + CommonJSBundledAngular, Security
openapi-generator-cli
🚫 Placeholder to prevent dependency confusion.
3.4k+281%-1 year ago
1.0.0
CommonJSNoneSecurity
audit-export
Pretty export your npm audit output as an offline accessible html page
3.4k+24%-4 months ago
5.1.5
CommonJSNoneSecurity
npm-audit-plus
A wrapper around NPM's built-in audit that adds extra features
3.3k+165%-4 years ago
0.2.0
CommonJSNoneSecurity
eslint-plugin-security-rules
ESLint security rules to help harden your project as early as possible.
3.3k+11%-4 years ago
0.8.0
CommonJSNoneLinting and formatting, Security
@callstack/react-native-sandbox
A component to run multiple React Native instances side-by-side.
3.3k---3 months ago
0.7.0
ESM + CommonJSBundledSecurity, React
actions-up
Interactive CLI tool to update GitHub Actions with SHA pinning or preserved refs
3.3k+373%-1 day ago
1.21.0
ESM onlyBundledCLI tools and terminal utilities, Security
@solongate/proxy
AI tool security proxy: protect any AI tool server with customizable policies, path/command constraints, rate limiting, and audit logging. No code changes required.
3.2k---13 days ago
0.91.25
ESM onlyBundledSecurity
@personnummer/generate
Generate Swedish Personal Identity Numbers
3.2k---3 years ago
1.0.3
ESM + CommonJSBundledSecurity
eslint-plugin-prototype-pollution-security-rules
Detect the use of vulnerable features within some libraries from https://github.com/HoLyVieR/prototype-pollution-nsec18/ that are not yet fixed
3.2k-54%-7 years ago
1.0.6
CommonJSNoneLinting and formatting, Security
organisationsnummer
Validate Swedish organization numbers
3.1k+80%-2 years ago
1.2.0
ESM + CommonJSBundledSecurity
vue-html-secure
Vue.js 2.x and 3.x plugin to add HTML secure directives v-html-remove, v-html-escape, v-html-safe
3.1k-58%-4 years ago
1.0.10
CommonJSNoneVue, Security
npm-audit-reporter-teamcity
generate TeamCity code inspections from the output of `npm audit`
3k-16%-3 years ago
0.4.0
CommonJSNoneSecurity
@visulima/redact
A library for redacting and masking sensitive data from objects and strings, with support for GDPR compliance, custom rules, and deep object traversal.
3k---22 days ago
5.0.0
ESM onlyBundledSecurity, React
reserved-email-addresses-list
List of 1250+ generic, admin, mailer-daemon, and no-reply usernames reserved for security concerns. Made for Forward Email <https//forwardemail.net>.
3k+780%-1 year ago
2.0.16
ESM + CommonJSNoneEmail, Security
bun-scan
Vulnerability scanner for Bun projects
3k--5 months ago
1.1.2
ESM onlyBundledSecurity
ring-client-api
Unofficial API for Ring doorbells, cameras, security alarm system and smart lighting
3k-20%-7 months ago
14.3.0
ESM onlyBundledSecurity
content-security-policy
Middleware to add Content-Security-Policy header.
2.9k+121%-2 days ago
0.4.0
CommonJSBundledSecurity
neosanitize
Zero-dependency, isomorphic HTML sanitizer: a fast browser-faithful WHATWG engine (deny-by-default) plus a drop-in sanitize-html-compatible legacy engine.
2.9k--3 months ago
0.3.0
ESM + CommonJSBundledSecurity
perfect-express-sanitizer
a complete package to control user input data to prevent Cross Site Scripting (XSS) ,Sql injection and no Sql injection attack
2.9k+27%-2 years ago
2.0.2
CommonJSNoneSecurity
cordova-plugin-secure-storage-echo
Secure storage plugin for iOS & Android
2.9k-2%-6 years ago
5.1.1
CommonJSNoneSecurity
dotenv-diff
Detects environment variable issues, usage, and potential security risks.
2.8k+970%-19 days ago
3.4.1
ESM onlyBundledConfiguration, CLI tools and terminal utilities
axios-error-redact
Library to redact sensitive information from Axios errors
2.8k+68%--
1.1.203
CommonJSBundledHTTP clients, TypeScript tooling
@turingpointde/cvss.js
A tiny library to work with cvss vectors
2.8k---8 months ago
2.1.0
ESM onlyBundledSecurity
sensitive-fields
List of sensitive fields that should be masked, obfuscated, or purged for security purposes
2.8k-0%-3 years ago
1.0.1
CommonJSNoneLogging, Security
node-guard
General purpose I/O module to add following http headers to keep your webpages securing them from malware attacks. This module can be used with any node http server.
2.8k+71%-10 years ago
1.0.0
CommonJSNoneSecurity, HTTP servers and web frameworks
is-my-node-vulnerable
package that checks if your Node.js installation is vulnerable to known security vulnerabilities
2.7k+4%-1 year ago
1.6.1
CommonJSNoneSecurity
nuxt-api-shield
Nuxt API Shield - Rate Limiting
2.7k+498%-3 months ago
1.0.0
ESM onlyBundledSecurity, Vue
sha1-hulud-scanner
Sha1-Hulud 2.0 npm supply chain attack scanner - Real-time detection using Koi.ai data
2.7k--9 months ago
1.0.1
CommonJSNoneSecurity
@presidio-dev/hai-guardrails
A set of guards for LLM Apps
2.7k---7 months ago
1.12.0
ESM + CommonJSBundledSecurity
@varlock/expo-integration
Expo/React Native Babel plugin to use varlock for .env file loading - adds validation, type-safety, and extra security features
2.6k---1 month ago
1.2.1
ESM + CommonJSBundledConfiguration, Schema validation
vite-plugin-content-security-policy
A Vite plugin for managing Content Security Policy (CSP) headers during development and generating Apache/Nginx configuration files
2.6k--5 months ago
1.0.3
ESM onlyBundledSecurity, Bundler plugins and loaders
@kindspells/astro-shield
Astro integration to enhance your website's security with SubResource Integrity hashes, Content-Security-Policy headers, and other techniques.
2.6k---1 year ago
1.7.1
ESM onlyBundledSecurity, Static site generators and meta-frameworks
@seontechnologies/seon-id-verification
An advanced SDK for natural person identification through document scanning, facial recognition, designed for secure and efficient user verification.
2.6k---10 months ago
2.1.0
ESM + CommonJSBundledSecurity

12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.

  • react-sanitized-htmlA React component that will sanitize user-inputted HTML code, using the popular sanitize-html package
  • @sp-uvb/vueOfficial Vue.js composables for Universal Verification Broker (UVB)
  • @sp-uvb/clientUniversal Verification Broker (UVB) TypeScript/JavaScript SDK
  • @jongleberry/vurst-htmlRust + N-API: HTML sanitization, extraction, and boilerstrip.
  • @pexxi/fold-to-ascii-tsA JavaScript port of the Apache Lucene ASCII Folding Filter that converts alphabetic, numeric, and symbolic Unicode characters which are not in the first 127 ASCII characters (the "Basic Latin" Unicode block) into a ASCII equivalents, if they exist.
  • @keep-lts/xlsxSecurity-maintained drop-in fork of xlsx. Back-ports SheetJS's fixes for CVE-2023-30533 (prototype pollution) and CVE-2024-22363 (ReDoS) onto the frozen npm 0.18.5 baseline. Original API unchanged.
  • krb5Kerberos library bindings for Node.js
  • @devexpress/eslint-plugin-dx-securityAn ESLint® plugin that detects and mitigates security-related issues for DevExpress projects.
  • edge-core-jsEdge account & wallet management library
  • strict-cspEnables a hash-based strict Content Security Policy for static HTML files and single page applications.
  • @jongleberry/vurst-promptPrompt-injection helper utilities for vurst.
  • securityUtility methods for escaping according to OWASP.
  • phc-argon2Node.JS Argon2 password hashing algorithm following the PHC string format
  • gitleaks-secret-scanner-fixedA powerful, intelligent wrapper for the Gitleaks engine that provides accurate and safe secret scanning for local pre-commit hooks and CI/CD pipelines. Fork with fixed tar vulnerability.
  • virgil-sdkVirgil Security Services SDK
  • rnsecZero-config security scanner for React Native & Expo apps. Find vulnerabilities with 68 security rules covering Android, iOS, and React Native specific issues.
  • @taiga-ui/dompurifyInclusive Angular API for DOMPurify
  • openapi-generator-cli🚫 Placeholder to prevent dependency confusion.
  • audit-exportPretty export your npm audit output as an offline accessible html page
  • npm-audit-plusA wrapper around NPM's built-in audit that adds extra features
  • eslint-plugin-security-rulesESLint security rules to help harden your project as early as possible.
  • @callstack/react-native-sandboxA component to run multiple React Native instances side-by-side.
  • actions-upInteractive CLI tool to update GitHub Actions with SHA pinning or preserved refs
  • @solongate/proxyAI tool security proxy: protect any AI tool server with customizable policies, path/command constraints, rate limiting, and audit logging. No code changes required.
  • @personnummer/generateGenerate Swedish Personal Identity Numbers
  • eslint-plugin-prototype-pollution-security-rulesDetect the use of vulnerable features within some libraries from https://github.com/HoLyVieR/prototype-pollution-nsec18/ that are not yet fixed
  • organisationsnummerValidate Swedish organization numbers
  • vue-html-secureVue.js 2.x and 3.x plugin to add HTML secure directives v-html-remove, v-html-escape, v-html-safe
  • npm-audit-reporter-teamcitygenerate TeamCity code inspections from the output of `npm audit`
  • @visulima/redactA library for redacting and masking sensitive data from objects and strings, with support for GDPR compliance, custom rules, and deep object traversal.
  • reserved-email-addresses-listList of 1250+ generic, admin, mailer-daemon, and no-reply usernames reserved for security concerns. Made for Forward Email <https//forwardemail.net>.
  • bun-scanVulnerability scanner for Bun projects
  • ring-client-apiUnofficial API for Ring doorbells, cameras, security alarm system and smart lighting
  • content-security-policyMiddleware to add Content-Security-Policy header.
  • neosanitizeZero-dependency, isomorphic HTML sanitizer: a fast browser-faithful WHATWG engine (deny-by-default) plus a drop-in sanitize-html-compatible legacy engine.
  • perfect-express-sanitizera complete package to control user input data to prevent Cross Site Scripting (XSS) ,Sql injection and no Sql injection attack
  • cordova-plugin-secure-storage-echoSecure storage plugin for iOS & Android
  • dotenv-diffDetects environment variable issues, usage, and potential security risks.
  • axios-error-redactLibrary to redact sensitive information from Axios errors
  • @turingpointde/cvss.jsA tiny library to work with cvss vectors
  • sensitive-fieldsList of sensitive fields that should be masked, obfuscated, or purged for security purposes
  • node-guardGeneral purpose I/O module to add following http headers to keep your webpages securing them from malware attacks. This module can be used with any node http server.
  • is-my-node-vulnerablepackage that checks if your Node.js installation is vulnerable to known security vulnerabilities
  • nuxt-api-shieldNuxt API Shield - Rate Limiting
  • sha1-hulud-scannerSha1-Hulud 2.0 npm supply chain attack scanner - Real-time detection using Koi.ai data
  • @presidio-dev/hai-guardrailsA set of guards for LLM Apps
  • @varlock/expo-integrationExpo/React Native Babel plugin to use varlock for .env file loading - adds validation, type-safety, and extra security features
  • vite-plugin-content-security-policyA Vite plugin for managing Content Security Policy (CSP) headers during development and generating Apache/Nginx configuration files
  • @kindspells/astro-shieldAstro integration to enhance your website's security with SubResource Integrity hashes, Content-Security-Policy headers, and other techniques.
  • @seontechnologies/seon-id-verificationAn advanced SDK for natural person identification through document scanning, facial recognition, designed for secure and efficient user verification.