Skip to content
JS
Package category

Security

Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.

514 packages2 comparisons

Packages compared

514 packages
PackageWeekly downloads12-month change52 weeksGzipLast releaseModuleTypesCategories
password-policy
A module to check if a password lives up to a policy.
2.6k+3%-9 years ago
0.0.3
CommonJSNoneSecurity
@mondoohq/xgrep
A fast, Semgrep-compatible code scanner written in Go.
2.5k---3 days ago
0.73.0
-NoneCLI tools and terminal utilities, Security
@depup/js-yaml
YAML 1.2 parser and serializer (with updated dependencies)
2.5k---today
5.4.2-depup.36
ESM + CommonJSBundledSecurity
@agimon-ai/doompi-web-security
Shared security primitives for the DoomPi web cockpit: sealed channels and signed bundle manifests for independently trusted verifiers.
2.5k---1 day ago
0.0.1-alpha.44
ESM + CommonJSBundledSecurity
npm-audit-ci-wrapper
A wrapper for 'npm audit' which can be configurable for use in a CI/CD tool like Jenkins
2.5k-22%-5 years ago
3.0.2
CommonJSNoneSecurity
eslint-plugin-secure-coding
ESLint plugin for secure coding — detects LDAP, XPath, XXE, GraphQL and template injection, unsafe deserialization, ReDoS, missing authentication, and PII in logs.
2.5k--1 day ago
5.4.13
CommonJSBundledLinting and formatting, Security
pulumi-infisical
A Pulumi provider for managing Infisical secrets management platform, dynamically bridged from the Terraform Infisical provider with support for projects, secrets, identity management, integrations, and access controls.
2.5k+1019%-26 days ago
0.20.1
ESM + CommonJSBundledAuthentication and authorisation, Security
@depup/express-validator
Express middleware for the validator module. (with updated dependencies)
2.4k---today
7.3.2-depup.218
CommonJSBundledSchema validation, HTTP servers and web frameworks
eslint-plugin-node-security
ESLint plugin for Node.js security — detects command injection, path traversal, SSRF, zip slip, and weak crypto (MD5/SHA-1, ECB, static IV) in fs, child_process, vm, and crypto.
2.4k--today
5.6.8
CommonJSBundledLinting and formatting, Node.js utilities
@depup/d3-dsv
A parser and formatter for delimiter-separated values, such as CSV and TSV (with updated dependencies)
2.4k---today
3.0.1-depup.251
ESM onlyNoneCharts and data visualisation, Security
@woocommerce/sanitize
WooCommerce HTML sanitization utilities.
2.4k---10 months ago
1.0.0
ESM + CommonJSBundledSecurity
@bun-security-scanner/osv
OSV vulnerability scanner for Bun projects
2.4k---10 months ago
1.0.0
ESM onlyBundledSecurity
@chax-at/better-npm-audit
Reshape into a better npm audit for the community and encourage more people to include security audit into their process.
2.4k---1 year ago
3.6.11
CommonJSNoneSecurity
@cypress/parse-domain
Splits an url into sub-domain, domain and effective top-level-domain
2.4k---6 years ago
2.4.0
CommonJSBundledURLs and query strings, Security
@tines/apps
Runtime SDK for Tines apps which includes typed hooks and helpers for interacting with Tines primitives, downloading files, and in-app routing.
2.3k---29 days ago
1.3.0
ESM onlyBundledSecurity
@phc/pbkdf2
Node.JS PBKDF2 password hashing algorithm following the PHC string format
2.3k---8 years ago
1.1.14
CommonJSNoneCryptography and hashing, Security
connect-roles
Provides dynamic roles based authorization for node.js connect and express servers.
2.3k+109%-10 years ago
3.1.2
CommonJSNoneHTTP servers and web frameworks, Security
targaryen
Test Firebase security rules without connecting to Firebase.
2.3k-6%-8 years ago
3.1.0
CommonJSNoneCloud SDKs, Security
@twin.org/vault-models
Shared models and factory utilities for consistent vault connector integration
2.3k---9 days ago
0.10.0
ESM onlyBundledBlockchain and Web3, Security
@endo/check-bundle
Checks the integrity of an Endo bundle.
2.3k---5 months ago
1.1.1
ESM onlyNoneBundlers, Security
tslint-config-security
TSLint security rules
2.3k-24%-7 years ago
1.16.0
CommonJSNoneSecurity
strict-csp-html-webpack-plugin
A webpack plugin that adds a hash-based strict CSP to help protect your site against XSS attacks.
2.3k-16%-4 years ago
1.0.2
CommonJSNoneSecurity
@acpr/rate-limit-postgresql
A PostgreSQL store for the `express-rate-limit` middleware
2.3k---2 years ago
1.4.1
ESM + CommonJSBundledDatabase clients and drivers, Security
social-links
Validate & sanitize social links
2.3k+8%-1 year ago
1.15.1
CommonJSBundledSecurity, Schema validation
@juspay/yama
Prompts-driven pull-request review agent on NeuroLink: config-driven skills, MCP tools, memory and fallback chains
2.2k---23 days ago
6.1.1
ESM onlyNoneSecurity
sysend
Communication and Synchronization between browser tabs/windows. Works cross-domain.
2.2k-53%--
1.17.5
CommonJSBundledSecurity
eslint-plugin-browser-security
ESLint plugin for browser security — detects DOM XSS, postMessage abuse, tokens in localStorage, insecure cookies, clickjacking, mixed content, and CSP gaps.
2.2k--2 days ago
2.1.9
CommonJSBundledLinting and formatting, Security
unifi-protect
A complete implementation of the UniFi Protect API.
2.1k+161%-1 month ago
5.3.1
ESM onlyBundledSecurity, TypeScript tooling
nopp
NoPP (No Prototype Pollution) – tiny helper to protect against Prototype Pollution vulnerabilities in your application
2.1k+6%-4 years ago
1.0.2
CommonJSNoneSecurity
skyflow-node
Skyflow SDK for Node.js
2.1k-28%-3 months ago
2.1.2
ESM + CommonJSBundledSecurity
koas-security
Koas security checks if a request matches the security requirement of an operation. For example, given the following partial OpenAPI document:
2.1k+79%-4 years ago
0.7.0
CommonJSNoneDocumentation tooling, Security
@rbac/rbac
Blazing Fast, Zero dependency, Hierarchical Role-Based Access Control for Node.js
2.1k---27 days ago
2.2.2
ESM + CommonJSBundledSecurity
grunt-retire
Grunt plugin for retire.
2.1k+16%-6 years ago
1.0.9
CommonJSNoneSecurity
protect-mcp
Cedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.
2k--4 days ago
0.30.0
ESM + CommonJSBundledSecurity
blowfish-js
Pure Javascript implementation of Blowfish block cipher.
2k+333%-4 years ago
1.0.0
CommonJSNoneSecurity
@nanocollective/prompt-scrub
`prompt-scrub` is a small open-source, local-first utility designed to strip identifying content out of prompts and messages before they hit any cloud LLM. It maps your sensitive data (emails, secrets, paths) to stable placeholders, allowing you to rehydr
2k---11 days ago
1.4.0
ESM onlyBundledSecurity
webext-base-css
Extremely minimal stylesheet/setup for Web Extensions’ options pages (also dark mode)
2k+94%-1 year ago
2.1.0
CommonJSNoneSecurity
vue-sanitize-directive
Vue directive for HTML sanitization.
2k-3%-4 years ago
0.2.1
ESM + CommonJSNoneSecurity, Vue
@raolin2025/claude-code-node
Node.js AI Code Agent CLI - Zero dependencies, pure JavaScript, security hardened, multi-channel notifications, Telegram & QQ Bot remote programming, rich media upload, multi-account management
2k---3 days ago
3.3.0
ESM onlyNoneCLI tools and terminal utilities, Security
@remnux/mcp-server
MCP server for using the REMnux malware analysis toolkit via AI assistants
1.9k---14 days ago
0.1.75
ESM onlyBundledSecurity
fast-ratelimit
Fast and efficient in-memory rate-limit for Node, used to alleviate severe DOS attacks.
1.9k-9%-10 months ago
4.0.0
CommonJSBundledSecurity, Queues and background jobs
safegres
Postgres security and performance auditor: RLS, grants and effective-access analysis plus index and policy-cost checks, scored on two independent axes. One connection, no framework.
1.9k--today
1.28.3
ESM + CommonJSBundledSecurity
@arcjet/guard
Arcjet Guards SDK — AI guardrails for rate limiting, prompt injection detection, and sensitive info detection
1.9k---8 days ago
1.13.0
ESM onlyBundledSecurity
ubiq-security-fpe
Ubiq Security, Inc. Format Preserving Encryption functions
1.8k+3018%-3 years ago
2.0.0
CommonJSNoneSecurity
phc-bcrypt
Node.JS bcrypt password hashing algorithm following the PHC string format
1.8k-0%-9 months ago
2.0.0
CommonJSNoneCryptography and hashing, Security
@varlock/astro-integration
Astro integration to use varlock for .env file loading - adds validation, type-safety, and extra security features
1.8k---13 days ago
1.4.2
ESM onlyBundledConfiguration, Schema validation
react-native-themis
Themis React Native is a convenient cryptographic library for data protection
1.8k-26%-5 months ago
0.15.7
-BundledCryptography and hashing, Security
upash
Unified API for password hashing algorithms
1.8k+13%-8 years ago
1.0.2
CommonJSNoneCryptography and hashing, Security
@carderne/sandbox-runtime
Anthropic Sandbox Runtime (ASRT) - A general-purpose tool for wrapping security boundaries around arbitrary processes
1.8k---17 days ago
0.0.72
ESM onlyBundledAI and machine learning, Security
@neuralegion/class-sanitizer
Class-based sanitization in TypeScript using decorators
1.8k---7 months ago
0.3.8
CommonJSBundledSecurity

12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.

  • password-policyA module to check if a password lives up to a policy.
  • @mondoohq/xgrepA fast, Semgrep-compatible code scanner written in Go.
  • @depup/js-yamlYAML 1.2 parser and serializer (with updated dependencies)
  • @agimon-ai/doompi-web-securityShared security primitives for the DoomPi web cockpit: sealed channels and signed bundle manifests for independently trusted verifiers.
  • npm-audit-ci-wrapperA wrapper for 'npm audit' which can be configurable for use in a CI/CD tool like Jenkins
  • eslint-plugin-secure-codingESLint plugin for secure coding — detects LDAP, XPath, XXE, GraphQL and template injection, unsafe deserialization, ReDoS, missing authentication, and PII in logs.
  • pulumi-infisicalA Pulumi provider for managing Infisical secrets management platform, dynamically bridged from the Terraform Infisical provider with support for projects, secrets, identity management, integrations, and access controls.
  • @depup/express-validatorExpress middleware for the validator module. (with updated dependencies)
  • eslint-plugin-node-securityESLint plugin for Node.js security — detects command injection, path traversal, SSRF, zip slip, and weak crypto (MD5/SHA-1, ECB, static IV) in fs, child_process, vm, and crypto.
  • @depup/d3-dsvA parser and formatter for delimiter-separated values, such as CSV and TSV (with updated dependencies)
  • @woocommerce/sanitizeWooCommerce HTML sanitization utilities.
  • @bun-security-scanner/osvOSV vulnerability scanner for Bun projects
  • @chax-at/better-npm-auditReshape into a better npm audit for the community and encourage more people to include security audit into their process.
  • @cypress/parse-domainSplits an url into sub-domain, domain and effective top-level-domain
  • @tines/appsRuntime SDK for Tines apps which includes typed hooks and helpers for interacting with Tines primitives, downloading files, and in-app routing.
  • @phc/pbkdf2Node.JS PBKDF2 password hashing algorithm following the PHC string format
  • connect-rolesProvides dynamic roles based authorization for node.js connect and express servers.
  • targaryenTest Firebase security rules without connecting to Firebase.
  • @twin.org/vault-modelsShared models and factory utilities for consistent vault connector integration
  • @endo/check-bundleChecks the integrity of an Endo bundle.
  • tslint-config-securityTSLint security rules
  • strict-csp-html-webpack-pluginA webpack plugin that adds a hash-based strict CSP to help protect your site against XSS attacks.
  • @acpr/rate-limit-postgresqlA PostgreSQL store for the `express-rate-limit` middleware
  • social-linksValidate & sanitize social links
  • @juspay/yamaPrompts-driven pull-request review agent on NeuroLink: config-driven skills, MCP tools, memory and fallback chains
  • sysendCommunication and Synchronization between browser tabs/windows. Works cross-domain.
  • eslint-plugin-browser-securityESLint plugin for browser security — detects DOM XSS, postMessage abuse, tokens in localStorage, insecure cookies, clickjacking, mixed content, and CSP gaps.
  • unifi-protectA complete implementation of the UniFi Protect API.
  • noppNoPP (No Prototype Pollution) – tiny helper to protect against Prototype Pollution vulnerabilities in your application
  • skyflow-nodeSkyflow SDK for Node.js
  • koas-securityKoas security checks if a request matches the security requirement of an operation. For example, given the following partial OpenAPI document:
  • @rbac/rbacBlazing Fast, Zero dependency, Hierarchical Role-Based Access Control for Node.js
  • grunt-retireGrunt plugin for retire.
  • protect-mcpCedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.
  • blowfish-jsPure Javascript implementation of Blowfish block cipher.
  • @nanocollective/prompt-scrub`prompt-scrub` is a small open-source, local-first utility designed to strip identifying content out of prompts and messages before they hit any cloud LLM. It maps your sensitive data (emails, secrets, paths) to stable placeholders, allowing you to rehydr
  • webext-base-cssExtremely minimal stylesheet/setup for Web Extensions’ options pages (also dark mode)
  • vue-sanitize-directiveVue directive for HTML sanitization.
  • @raolin2025/claude-code-nodeNode.js AI Code Agent CLI - Zero dependencies, pure JavaScript, security hardened, multi-channel notifications, Telegram & QQ Bot remote programming, rich media upload, multi-account management
  • @remnux/mcp-serverMCP server for using the REMnux malware analysis toolkit via AI assistants
  • fast-ratelimitFast and efficient in-memory rate-limit for Node, used to alleviate severe DOS attacks.
  • safegresPostgres security and performance auditor: RLS, grants and effective-access analysis plus index and policy-cost checks, scored on two independent axes. One connection, no framework.
  • @arcjet/guardArcjet Guards SDK — AI guardrails for rate limiting, prompt injection detection, and sensitive info detection
  • ubiq-security-fpeUbiq Security, Inc. Format Preserving Encryption functions
  • phc-bcryptNode.JS bcrypt password hashing algorithm following the PHC string format
  • @varlock/astro-integrationAstro integration to use varlock for .env file loading - adds validation, type-safety, and extra security features
  • react-native-themisThemis React Native is a convenient cryptographic library for data protection
  • upashUnified API for password hashing algorithms
  • @carderne/sandbox-runtimeAnthropic Sandbox Runtime (ASRT) - A general-purpose tool for wrapping security boundaries around arbitrary processes
  • @neuralegion/class-sanitizerClass-based sanitization in TypeScript using decorators