npm97Exceptionalhealth index

cure53/DOMPurifyDOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
JavaScript · TypeScript★ 17.3K↓ 226M/moAug 4, 2026
npm88Excellenthealth index

asamassekou10/ship-safeCLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5,893/moSep 6, 2026
Packagist87Excellenthealth index

nette/latte☕ Latte: the safest & truly intuitive templates for PHP. Engine for those who want the most secure PHP sites.
PHP★ 1,291↓ 169.1K/moSep 5, 2026
npm86Excellenthealth index
humanspeak/svelte-markdown📝 Markdown and HTML renderer for Svelte 5 — built for streaming AI agent output from Claude Code, ChatGPT, and agentic workflows. XSS-safe defaults, token caching, TypeScript types.
TypeScript · Svelte★ 123↓ 83.4K/moJul 17, 2026
npm86Excellenthealth index
TypeScript★ 595↓ 23.1M/moAug 27, 2026
crates.io81Excellenthealth index
Rust★ 668↓ 788.2K/moJul 22, 2026
Packagist78Goodhealth index
voku/anti-xss㊙️ AntiXSS | Protection against Cross-site scripting (XSS) via PHP
PHP★ 713↓ 304.2K/moJul 30, 2026
crates.io71Goodhealth index
Rust★ 425↓ 24.9K/moAug 9, 2026
crates.io71Goodhealth index
Rust★ 1↓ 27.9K/moJul 30, 2026
C#★ 1,701Jul 18, 2026
Packagist69Goodhealth index

paragonie/csp-builderBuild Content-Security-Policy headers from a JSON file (or build them programmatically)
PHP★ 540↓ 69.2K/moAug 18, 2026
Packagist62Moderatehealth index

interactivetools-com/SmartStringPHP strings that HTML-encode themselves on echo, interpolation, and concatenation. XSS-safe by default and at least 3x faster than calling htmlspecialchars() yourself.
PHP★ 0↓ 24.7K/moSep 5, 2026
Packagist62Moderatehealth index

interactivetools-com/ZenDBPHP/MySQL database layer where values only enter SQL through placeholders and every result HTML-encodes itself on output. Faster than prepared statements plus htmlspecialchars() on every measured page, within microseconds of raw SQL.
PHP★ 3↓ 3,388/moAug 12, 2026
Packagist60Moderatehealth index
TYPO3/html-sanitizerHTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values.
PHP★ 29↓ 328.4K/moJul 22, 2026
npm59Moderatehealth index

leizongmin/js-xssSanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist
HTML · JavaScript★ 5,315↓ 22.1M/moAug 12, 2026
npm53Moderatehealth index
JavaScript · HTML★ 3↓ 144M/moAug 22, 2026
npm51Moderatehealth index
3516634930/Payloader渗透测试Payload速查平台 | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript
TypeScript · JavaScript★ 463Jul 19, 2026
npm51Moderatehealth index

NaturalIntelligence/is-unsafeZero-dependency, DOM-free, pure predicate for detecting unsafe strings across HTML, XML, SVG, SQL, SHELL, NOSQL, and REGEX contexts
JavaScript★ 1↓ 66.7M/moAug 27, 2026
npm50Moderatehealth index
JavaScript★ 3↓ 41.2K/moJul 19, 2026
Packagist48Weakhealth index
PHP★ 0↓ 4,903/moJul 16, 2026
C#★ 69Aug 2, 2026
taq25/templ-lintSecurity linter for a-h/templ: detects XSS-prone htmx / Alpine.js usage by parsing .templ files directly with parser/v2
Go★ 0Jul 17, 2026
microcosm-cc/bluemondaybluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
Go★ 3,704Jul 30, 2026
Python★ 87↓ 2.5M/moAug 27, 2026
C#★ 975Aug 27, 2026