Package category
Security
Sanitisation, CSRF, CORS, helmet, secrets and vulnerability tooling.
514 packages2 comparisons
Packages compared
514 packages
| Package | Weekly downloads | 12-month change | 52 weeks | Gzip | Last release | Module | Types | Categories |
|---|---|---|---|---|---|---|---|---|
| password-policy A module to check if a password lives up to a policy. | 2.6k | +3% | - | 9 years ago 0.0.3 | CommonJS | None | Security | |
| @mondoohq/xgrep A fast, Semgrep-compatible code scanner written in Go. | 2.5k | - | - | - | 3 days ago 0.73.0 | - | None | CLI tools and terminal utilities, Security |
| @depup/js-yaml YAML 1.2 parser and serializer (with updated dependencies) | 2.5k | - | - | - | today 5.4.2-depup.36 | ESM + CommonJS | Bundled | Security |
| @agimon-ai/doompi-web-security Shared security primitives for the DoomPi web cockpit: sealed channels and signed bundle manifests for independently trusted verifiers. | 2.5k | - | - | - | 1 day ago 0.0.1-alpha.44 | ESM + CommonJS | Bundled | Security |
| npm-audit-ci-wrapper A wrapper for 'npm audit' which can be configurable for use in a CI/CD tool like Jenkins | 2.5k | -22% | - | 5 years ago 3.0.2 | CommonJS | None | Security | |
| eslint-plugin-secure-coding ESLint plugin for secure coding — detects LDAP, XPath, XXE, GraphQL and template injection, unsafe deserialization, ReDoS, missing authentication, and PII in logs. | 2.5k | - | - | 1 day ago 5.4.13 | CommonJS | Bundled | Linting and formatting, Security | |
| pulumi-infisical A Pulumi provider for managing Infisical secrets management platform, dynamically bridged from the Terraform Infisical provider with support for projects, secrets, identity management, integrations, and access controls. | 2.5k | +1019% | - | 26 days ago 0.20.1 | ESM + CommonJS | Bundled | Authentication and authorisation, Security | |
| @depup/express-validator Express middleware for the validator module. (with updated dependencies) | 2.4k | - | - | - | today 7.3.2-depup.218 | CommonJS | Bundled | Schema validation, HTTP servers and web frameworks |
| eslint-plugin-node-security ESLint plugin for Node.js security — detects command injection, path traversal, SSRF, zip slip, and weak crypto (MD5/SHA-1, ECB, static IV) in fs, child_process, vm, and crypto. | 2.4k | - | - | today 5.6.8 | CommonJS | Bundled | Linting and formatting, Node.js utilities | |
| @depup/d3-dsv A parser and formatter for delimiter-separated values, such as CSV and TSV (with updated dependencies) | 2.4k | - | - | - | today 3.0.1-depup.251 | ESM only | None | Charts and data visualisation, Security |
| @woocommerce/sanitize WooCommerce HTML sanitization utilities. | 2.4k | - | - | - | 10 months ago 1.0.0 | ESM + CommonJS | Bundled | Security |
| @bun-security-scanner/osv OSV vulnerability scanner for Bun projects | 2.4k | - | - | - | 10 months ago 1.0.0 | ESM only | Bundled | Security |
| @chax-at/better-npm-audit Reshape into a better npm audit for the community and encourage more people to include security audit into their process. | 2.4k | - | - | - | 1 year ago 3.6.11 | CommonJS | None | Security |
| @cypress/parse-domain Splits an url into sub-domain, domain and effective top-level-domain | 2.4k | - | - | - | 6 years ago 2.4.0 | CommonJS | Bundled | URLs and query strings, Security |
| @tines/apps Runtime SDK for Tines apps which includes typed hooks and helpers for interacting with Tines primitives, downloading files, and in-app routing. | 2.3k | - | - | - | 29 days ago 1.3.0 | ESM only | Bundled | Security |
| @phc/pbkdf2 Node.JS PBKDF2 password hashing algorithm following the PHC string format | 2.3k | - | - | - | 8 years ago 1.1.14 | CommonJS | None | Cryptography and hashing, Security |
| connect-roles Provides dynamic roles based authorization for node.js connect and express servers. | 2.3k | +109% | - | 10 years ago 3.1.2 | CommonJS | None | HTTP servers and web frameworks, Security | |
| targaryen Test Firebase security rules without connecting to Firebase. | 2.3k | -6% | - | 8 years ago 3.1.0 | CommonJS | None | Cloud SDKs, Security | |
| @twin.org/vault-models Shared models and factory utilities for consistent vault connector integration | 2.3k | - | - | - | 9 days ago 0.10.0 | ESM only | Bundled | Blockchain and Web3, Security |
| @endo/check-bundle Checks the integrity of an Endo bundle. | 2.3k | - | - | - | 5 months ago 1.1.1 | ESM only | None | Bundlers, Security |
| tslint-config-security TSLint security rules | 2.3k | -24% | - | 7 years ago 1.16.0 | CommonJS | None | Security | |
| strict-csp-html-webpack-plugin A webpack plugin that adds a hash-based strict CSP to help protect your site against XSS attacks. | 2.3k | -16% | - | 4 years ago 1.0.2 | CommonJS | None | Security | |
| @acpr/rate-limit-postgresql A PostgreSQL store for the `express-rate-limit` middleware | 2.3k | - | - | - | 2 years ago 1.4.1 | ESM + CommonJS | Bundled | Database clients and drivers, Security |
| social-links Validate & sanitize social links | 2.3k | +8% | - | 1 year ago 1.15.1 | CommonJS | Bundled | Security, Schema validation | |
| @juspay/yama Prompts-driven pull-request review agent on NeuroLink: config-driven skills, MCP tools, memory and fallback chains | 2.2k | - | - | - | 23 days ago 6.1.1 | ESM only | None | Security |
| sysend Communication and Synchronization between browser tabs/windows. Works cross-domain. | 2.2k | -53% | - | - 1.17.5 | CommonJS | Bundled | Security | |
| eslint-plugin-browser-security ESLint plugin for browser security — detects DOM XSS, postMessage abuse, tokens in localStorage, insecure cookies, clickjacking, mixed content, and CSP gaps. | 2.2k | - | - | 2 days ago 2.1.9 | CommonJS | Bundled | Linting and formatting, Security | |
| unifi-protect A complete implementation of the UniFi Protect API. | 2.1k | +161% | - | 1 month ago 5.3.1 | ESM only | Bundled | Security, TypeScript tooling | |
| nopp NoPP (No Prototype Pollution) – tiny helper to protect against Prototype Pollution vulnerabilities in your application | 2.1k | +6% | - | 4 years ago 1.0.2 | CommonJS | None | Security | |
| skyflow-node Skyflow SDK for Node.js | 2.1k | -28% | - | 3 months ago 2.1.2 | ESM + CommonJS | Bundled | Security | |
| koas-security Koas security checks if a request matches the security requirement of an operation. For example, given the following partial OpenAPI document: | 2.1k | +79% | - | 4 years ago 0.7.0 | CommonJS | None | Documentation tooling, Security | |
| @rbac/rbac Blazing Fast, Zero dependency, Hierarchical Role-Based Access Control for Node.js | 2.1k | - | - | - | 27 days ago 2.2.2 | ESM + CommonJS | Bundled | Security |
| grunt-retire Grunt plugin for retire. | 2.1k | +16% | - | 6 years ago 1.0.9 | CommonJS | None | Security | |
| protect-mcp Cedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind. | 2k | - | - | 4 days ago 0.30.0 | ESM + CommonJS | Bundled | Security | |
| blowfish-js Pure Javascript implementation of Blowfish block cipher. | 2k | +333% | - | 4 years ago 1.0.0 | CommonJS | None | Security | |
| @nanocollective/prompt-scrub `prompt-scrub` is a small open-source, local-first utility designed to strip identifying content out of prompts and messages before they hit any cloud LLM. It maps your sensitive data (emails, secrets, paths) to stable placeholders, allowing you to rehydr | 2k | - | - | - | 11 days ago 1.4.0 | ESM only | Bundled | Security |
| webext-base-css Extremely minimal stylesheet/setup for Web Extensions’ options pages (also dark mode) | 2k | +94% | - | 1 year ago 2.1.0 | CommonJS | None | Security | |
| vue-sanitize-directive Vue directive for HTML sanitization. | 2k | -3% | - | 4 years ago 0.2.1 | ESM + CommonJS | None | Security, Vue | |
| @raolin2025/claude-code-node Node.js AI Code Agent CLI - Zero dependencies, pure JavaScript, security hardened, multi-channel notifications, Telegram & QQ Bot remote programming, rich media upload, multi-account management | 2k | - | - | - | 3 days ago 3.3.0 | ESM only | None | CLI tools and terminal utilities, Security |
| @remnux/mcp-server MCP server for using the REMnux malware analysis toolkit via AI assistants | 1.9k | - | - | - | 14 days ago 0.1.75 | ESM only | Bundled | Security |
| fast-ratelimit Fast and efficient in-memory rate-limit for Node, used to alleviate severe DOS attacks. | 1.9k | -9% | - | 10 months ago 4.0.0 | CommonJS | Bundled | Security, Queues and background jobs | |
| safegres Postgres security and performance auditor: RLS, grants and effective-access analysis plus index and policy-cost checks, scored on two independent axes. One connection, no framework. | 1.9k | - | - | today 1.28.3 | ESM + CommonJS | Bundled | Security | |
| @arcjet/guard Arcjet Guards SDK — AI guardrails for rate limiting, prompt injection detection, and sensitive info detection | 1.9k | - | - | - | 8 days ago 1.13.0 | ESM only | Bundled | Security |
| ubiq-security-fpe Ubiq Security, Inc. Format Preserving Encryption functions | 1.8k | +3018% | - | 3 years ago 2.0.0 | CommonJS | None | Security | |
| phc-bcrypt Node.JS bcrypt password hashing algorithm following the PHC string format | 1.8k | -0% | - | 9 months ago 2.0.0 | CommonJS | None | Cryptography and hashing, Security | |
| @varlock/astro-integration Astro integration to use varlock for .env file loading - adds validation, type-safety, and extra security features | 1.8k | - | - | - | 13 days ago 1.4.2 | ESM only | Bundled | Configuration, Schema validation |
| react-native-themis Themis React Native is a convenient cryptographic library for data protection | 1.8k | -26% | - | 5 months ago 0.15.7 | - | Bundled | Cryptography and hashing, Security | |
| upash Unified API for password hashing algorithms | 1.8k | +13% | - | 8 years ago 1.0.2 | CommonJS | None | Cryptography and hashing, Security | |
| @carderne/sandbox-runtime Anthropic Sandbox Runtime (ASRT) - A general-purpose tool for wrapping security boundaries around arbitrary processes | 1.8k | - | - | - | 17 days ago 0.0.72 | ESM only | Bundled | AI and machine learning, Security |
| @neuralegion/class-sanitizer Class-based sanitization in TypeScript using decorators | 1.8k | - | - | - | 7 months ago 0.3.8 | CommonJS | Bundled | Security |
12-month change compares the average of the last 4 weeks of downloads with the first 4 weeks of the 52-week series. Gzip size is for the whole package, as measured by Bundlephobia. "-" means the value has not been fetched.
- password-policyA module to check if a password lives up to a policy.
- @mondoohq/xgrepA fast, Semgrep-compatible code scanner written in Go.
- @depup/js-yamlYAML 1.2 parser and serializer (with updated dependencies)
- @agimon-ai/doompi-web-securityShared security primitives for the DoomPi web cockpit: sealed channels and signed bundle manifests for independently trusted verifiers.
- npm-audit-ci-wrapperA wrapper for 'npm audit' which can be configurable for use in a CI/CD tool like Jenkins
- eslint-plugin-secure-codingESLint plugin for secure coding — detects LDAP, XPath, XXE, GraphQL and template injection, unsafe deserialization, ReDoS, missing authentication, and PII in logs.
- pulumi-infisicalA Pulumi provider for managing Infisical secrets management platform, dynamically bridged from the Terraform Infisical provider with support for projects, secrets, identity management, integrations, and access controls.
- @depup/express-validatorExpress middleware for the validator module. (with updated dependencies)
- eslint-plugin-node-securityESLint plugin for Node.js security — detects command injection, path traversal, SSRF, zip slip, and weak crypto (MD5/SHA-1, ECB, static IV) in fs, child_process, vm, and crypto.
- @depup/d3-dsvA parser and formatter for delimiter-separated values, such as CSV and TSV (with updated dependencies)
- @woocommerce/sanitizeWooCommerce HTML sanitization utilities.
- @bun-security-scanner/osvOSV vulnerability scanner for Bun projects
- @chax-at/better-npm-auditReshape into a better npm audit for the community and encourage more people to include security audit into their process.
- @cypress/parse-domainSplits an url into sub-domain, domain and effective top-level-domain
- @tines/appsRuntime SDK for Tines apps which includes typed hooks and helpers for interacting with Tines primitives, downloading files, and in-app routing.
- @phc/pbkdf2Node.JS PBKDF2 password hashing algorithm following the PHC string format
- connect-rolesProvides dynamic roles based authorization for node.js connect and express servers.
- targaryenTest Firebase security rules without connecting to Firebase.
- @twin.org/vault-modelsShared models and factory utilities for consistent vault connector integration
- @endo/check-bundleChecks the integrity of an Endo bundle.
- tslint-config-securityTSLint security rules
- strict-csp-html-webpack-pluginA webpack plugin that adds a hash-based strict CSP to help protect your site against XSS attacks.
- @acpr/rate-limit-postgresqlA PostgreSQL store for the `express-rate-limit` middleware
- social-linksValidate & sanitize social links
- @juspay/yamaPrompts-driven pull-request review agent on NeuroLink: config-driven skills, MCP tools, memory and fallback chains
- sysendCommunication and Synchronization between browser tabs/windows. Works cross-domain.
- eslint-plugin-browser-securityESLint plugin for browser security — detects DOM XSS, postMessage abuse, tokens in localStorage, insecure cookies, clickjacking, mixed content, and CSP gaps.
- unifi-protectA complete implementation of the UniFi Protect API.
- noppNoPP (No Prototype Pollution) – tiny helper to protect against Prototype Pollution vulnerabilities in your application
- skyflow-nodeSkyflow SDK for Node.js
- koas-securityKoas security checks if a request matches the security requirement of an operation. For example, given the following partial OpenAPI document:
- @rbac/rbacBlazing Fast, Zero dependency, Hierarchical Role-Based Access Control for Node.js
- grunt-retireGrunt plugin for retire.
- protect-mcpCedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.
- blowfish-jsPure Javascript implementation of Blowfish block cipher.
- @nanocollective/prompt-scrub`prompt-scrub` is a small open-source, local-first utility designed to strip identifying content out of prompts and messages before they hit any cloud LLM. It maps your sensitive data (emails, secrets, paths) to stable placeholders, allowing you to rehydr
- webext-base-cssExtremely minimal stylesheet/setup for Web Extensions’ options pages (also dark mode)
- vue-sanitize-directiveVue directive for HTML sanitization.
- @raolin2025/claude-code-nodeNode.js AI Code Agent CLI - Zero dependencies, pure JavaScript, security hardened, multi-channel notifications, Telegram & QQ Bot remote programming, rich media upload, multi-account management
- @remnux/mcp-serverMCP server for using the REMnux malware analysis toolkit via AI assistants
- fast-ratelimitFast and efficient in-memory rate-limit for Node, used to alleviate severe DOS attacks.
- safegresPostgres security and performance auditor: RLS, grants and effective-access analysis plus index and policy-cost checks, scored on two independent axes. One connection, no framework.
- @arcjet/guardArcjet Guards SDK — AI guardrails for rate limiting, prompt injection detection, and sensitive info detection
- ubiq-security-fpeUbiq Security, Inc. Format Preserving Encryption functions
- phc-bcryptNode.JS bcrypt password hashing algorithm following the PHC string format
- @varlock/astro-integrationAstro integration to use varlock for .env file loading - adds validation, type-safety, and extra security features
- react-native-themisThemis React Native is a convenient cryptographic library for data protection
- upashUnified API for password hashing algorithms
- @carderne/sandbox-runtimeAnthropic Sandbox Runtime (ASRT) - A general-purpose tool for wrapping security boundaries around arbitrary processes
- @neuralegion/class-sanitizerClass-based sanitization in TypeScript using decorators