103,522 packages matching “cross-site-scripting”
csp_evaluator
v1.1.8 · 4 months ago
Evaluate Content Security Policies for a wide range of bypasses and weaknesses
No known vulnerabilities
csrf-csrf
v4.0.3 · 1 year ago
A utility package to help implement stateless CSRF protection using the Double Submit Cookie Pattern in express.
No known vulnerabilities
nuxt-security
v2.6.0 · 4 months ago
🛡️ Security Module for Nuxt based on HTTP Headers and Middleware
No known vulnerabilities
@security-alert/sarif-to-markdown
v1.11.1 · 8 months ago
Convert Sarif format to body text
No known vulnerabilities
@yarnpkg/shell
v4.1.3 · 1 year ago
No description provided.
No known vulnerabilities
@zohodesk/eslint-plugin-select2-restricted-options
v1.0.0 · 1 year ago
An ESLint plugin that restricts the use of formatSelection and formatResult to prevent potential issues when passed into select2() as initialization options. This proactive measure helps avoid Cross-Site Scripting (XSS) vulnerabilities and other unintende
No known vulnerabilities
html_sanitize
v1.1.3 · 10 years ago
This module Sanitizes HTML input, stripping all tags and attributes that aren't whitelisted.HTML sanitization can be used to protect against cross-site scripting (XSS) attacks by sanitizing any HTML code submitted by a user.
No known vulnerabilities
helmet-csp
v4.1.0 · 2 months ago
Content Security Policy middleware
No known vulnerabilities
cross-spawn
v7.0.6 · 1 year ago
Cross platform child_process#spawn and child_process#spawnSync
No known vulnerabilities
secure-request-encoder
v1.0.8 · 3 years ago
Secure Request Encoder is a middleware package for Node.js and Express.js that enhances the security of your web application by encoding potentially unsafe characters in HTTP request bodies. It helps prevent cross-site scripting (XSS) attacks by sanitizin
No known vulnerabilities
@netlify/plugin-csp-nonce
v1.6.2 · 7 months ago
Use a nonce for the script-src and style-src directives of your Content Security Policy.
No known vulnerabilities
vega-interpreter
v2.3.2 · 1 month ago
CSP-compliant interpreter for Vega expressions.
No known vulnerabilities
@hint/hint-strict-transport-security
v3.0.23 · 2 years ago
hint for best practices related to the usage of the Strict-Transport-Security response header
No known vulnerabilities
fas-hub-express-xss-sanitizer
v1.2.0 · 1 year ago
Express 4.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack.
No known vulnerabilities
helmet-crossdomain
v0.5.0 · 7 years ago
Set the X-Permitted-Cross-Domain-Policies header in Express apps
No known vulnerabilities
winchan
v0.2.2 · 7 years ago
Here's the scenario: You want to build a secure means of some untrusted site opening a window, which loads content at a trusted site. Then you want the untrusted dude to be able to pass in parameters. Then you want the trusted code to do any amount of
No known vulnerabilities
@react-jvectormap/lib
v1.0.3 · 3 years ago
jVectorMap is a vector-based, cross-browser and cross-platform component for interactive geography-related data visualization on the web. It provides numerious features like smooth zooming and panning, fully-customizable styling, markers, labels and toolt
No known vulnerabilities
immunio
v1.5.3 · 6 years ago
IMMUNIO protects your web app from security vulnerabilities by monitoring requests in realtime. After a two minute installation, your application will be protected from many of the top classes of attacks, including Cross-Site Scripting (XSS), SQL Injectio
No known vulnerabilities
cross-fetch
v4.1.0 · 1 year ago
Universal WHATWG Fetch API for Node, Browsers and React Native
No known vulnerabilities
@hint/hint-no-vulnerable-javascript-libraries
v2.12.22 · 2 years ago
hint that that checks using Snyk for vulnerable JavaScript libraries
No known vulnerabilities