All tags
Catalogue tag

#xss

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

25 records
Tagged “xss”Ranked by health index
npm
97Exceptionalhealth index
cure53/DOMPurify
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
JavaScript · TypeScript★ 17.3K↓ 226M/moAug 4, 2026
Apache-2.0Aug 4, 2026 · metrics 2.10.0
npm
88Excellenthealth index
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5,893/moSep 6, 2026
MITSep 6, 2026 · metrics 2.10.0
Packagist
87Excellenthealth index
nette/latte
☕ Latte: the safest & truly intuitive templates for PHP. Engine for those who want the most secure PHP sites.
PHP★ 1,291↓ 169.1K/moSep 5, 2026
Custom licenseSep 5, 2026 · metrics 2.10.0
npm
86Excellenthealth index
humanspeak/svelte-markdown
📝 Markdown and HTML renderer for Svelte 5 — built for streaming AI agent output from Claude Code, ChatGPT, and agentic workflows. XSS-safe defaults, token caching, TypeScript types.
TypeScript · Svelte★ 123↓ 83.4K/moJul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
npm
86Excellenthealth index
kkomelin/isomorphic-dompurify
Use DOMPurify on server and client in the same way
TypeScript★ 595↓ 23.1M/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
crates.io
81Excellenthealth index
rust-ammonia/ammonia
Repair and secure untrusted HTML
Rust★ 668↓ 788.2K/moJul 22, 2026
Apache-2.0Jul 22, 2026 · metrics 2.10.0
Packagist
78Goodhealth index
voku/anti-xss
㊙️ AntiXSS | Protection against Cross-site scripting (XSS) via PHP
PHP★ 713↓ 304.2K/moJul 30, 2026
MITJul 30, 2026 · metrics 2.10.0
crates.io
71Goodhealth index
cloudflare/svg-hush
Make it safe to serve untrusted SVG files
Rust★ 425↓ 24.9K/moAug 9, 2026
MITAug 9, 2026 · metrics 2.10.0
crates.io
71Goodhealth index
kerberosmansour/SunLitSecurityLibraries
SunLit Security Libraries: Rust security crates for OWASP-aligned services
Rust★ 1↓ 27.9K/moJul 30, 2026
Custom licenseJul 30, 2026 · metrics 2.10.0
69Goodhealth index
mganss/HtmlSanitizer
Cleans HTML to avoid XSS attacks
C#★ 1,701Jul 18, 2026
MITJul 18, 2026 · metrics 2.10.0
Packagist
69Goodhealth index
paragonie/csp-builder
Build Content-Security-Policy headers from a JSON file (or build them programmatically)
PHP★ 540↓ 69.2K/moAug 18, 2026
MITAug 18, 2026 · metrics 2.10.0
Packagist
62Moderatehealth index
interactivetools-com/SmartString
PHP strings that HTML-encode themselves on echo, interpolation, and concatenation. XSS-safe by default and at least 3x faster than calling htmlspecialchars() yourself.
PHP★ 0↓ 24.7K/moSep 5, 2026
MITSep 5, 2026 · metrics 2.10.0
Packagist
62Moderatehealth index
interactivetools-com/ZenDB
PHP/MySQL database layer where values only enter SQL through placeholders and every result HTML-encodes itself on output. Faster than prepared statements plus htmlspecialchars() on every measured page, within microseconds of raw SQL.
PHP★ 3↓ 3,388/moAug 12, 2026
MITAug 12, 2026 · metrics 2.10.0
Packagist
60Moderatehealth index
TYPO3/html-sanitizer
HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values.
PHP★ 29↓ 328.4K/moJul 22, 2026
MITJul 22, 2026 · metrics 2.10.0
npm
59Moderatehealth index
leizongmin/js-xss
Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist
HTML · JavaScript★ 5,315↓ 22.1M/moAug 12, 2026
Custom licenseAug 12, 2026 · metrics 2.10.0
npm
51Moderatehealth index
3516634930/Payloader
渗透测试Payload速查平台 | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript
TypeScript · JavaScript★ 463Jul 19, 2026
AGPL-3.0Jul 19, 2026 · metrics 2.10.0
npm
51Moderatehealth index
NaturalIntelligence/is-unsafe
Zero-dependency, DOM-free, pure predicate for detecting unsafe strings across HTML, XML, SVG, SQL, SHELL, NOSQL, and REGEX contexts
JavaScript★ 1↓ 66.7M/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm
50Moderatehealth index
yuda-lyu/wsemi
A support package for web developer.
JavaScript★ 3↓ 41.2K/moJul 19, 2026
MITJul 19, 2026 · metrics 2.10.0
Packagist
48Weakhealth index
interactivetools-com/SmartArray
Enhanced Arrays with Chainable Methods and Automatic HTML Encoding
PHP★ 0↓ 4,903/moJul 16, 2026
MITJul 16, 2026 · metrics 2.10.0
NuGet
47Weakhealth index
Vereyon/HtmlRuleSanitizer
A rule based HTML sanitizer built on top of the HTML Agility pack
C#★ 69Aug 2, 2026
MITAug 2, 2026 · metrics 2.10.0
Go
39Weakhealth index
taq25/templ-lint
Security linter for a-h/templ: detects XSS-prone htmx / Alpine.js usage by parsing .templ files directly with parser/v2
Go★ 0Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
Go
34At Riskhealth index
microcosm-cc/bluemonday
bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
Go★ 3,704Jul 30, 2026
BSD-3-ClauseJul 30, 2026 · metrics 2.10.0
PyPI
33At Riskhealth index
wntrblm/flask-talisman
HTTP security headers for Flask
Python★ 87↓ 2.5M/moAug 27, 2026
Apache-2.0Aug 27, 2026 · metrics 2.10.0