Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist
Secure XSS Filters - Just sufficient output filtering to prevent XSS!
Middleware to disable the X-XSS-Protection header
XSS filter extension for showdown
TypeScript definitions for xss-filters
Validates XSS related issues of mixing HTML and non-HTML content in variables.
blocklet prevent xss attack
XSS Secure
Various XSS-hunter ESLint rules
⚙️ CLI/NPM | RAV XSS | 🎯 Basic Reflected XSS scanner for bug bounty programs.
TypeScript definitions for express-xss-sanitizer
Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack.
Anti-XSS filters for security
nanoid console xss
A plugin for Elysia.js that provides XSS (Cross-Site Scripting) protection by sanitizing request body data.
A fast, native Bun-powered HTML sanitizer with DOMPurify-like features. Protection against XSS and malicious content.
蓝鲸 XSS 过滤工具
Disallow jQuery functions with XSS potential.
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It's written in JavaScript and works in all modern browsers (Safari, Opera (15+), Internet Explorer (10+), Firefox and Chrome - as well as almost anything else usin
Escapes content for prevention of XSS (Cross Site Scripting) attacks.
joi xss
A powerful middleware for securing your express.js applications against cross-site scripting (XSS) attacks
A CSS sanitizer to prevent XSS attacks
Various XSS-hunter ESLint rules
Web scanner built for actual pentests. Fast, modular, Rust.
Lightweight headless browser for security testing. Fast, pure Rust, no Chrome.
Type-safe asynchronous wrapper for the Dalfox XSS scanner with streaming output, stored XSS support, and multi-format result formatting
Rust port of libinjection - SQL/XSS injection detection library
XSS vulnerability test for docs.rs
<img onload='alert('Injected 1234')' src='https://google.com'><img onload='alert('Injected 777')' src='https://google.com'>%3Cimg%20onload%3D'alert('Injected%20666')'%20src%3D'https%3A%2F%2Fgoogle.com'%3E
Probe for XSS vulnerability
<script>alert('ha, ha!')</script>
A fast, allowlist-based HTML sanitizer
Rust bindings for libinjection
Rust bindings for libinjection from libinjection/libinjection fork
contextual output encoding for xss defense and safe literal embedding, inspired by the owasp java encoder
A gem to control the world!
XssTerminate for Rails 3.2
This plugin replaces the default ERB template handlers with erubis, and switches the behaviour to escape by default rather than requiring you to escape. This is consistent with the behaviour in Rails 3.0.
Patches rails_xss and Haml so AngularJS interpolations are auto-escaped in unsafe strings.
Drop-in XSS support for remote applications.
This Rails plugin provides automatic cross site scripting (XSS) protection for your views. Once installed, you no longer have to manually and painstakingly sanitize all your views with HTML escaping.
Hax <script>alert('omg hax')</script>
Just an attempt to own a few things. <script>console.log</script>
This plugin provides XSS protection for views coded in HAML and RHTML. ERB templates are sometimes used for HTML, and sometimes for other kinds of languages (SQL, email templates, YAML etc.). XSS Shield protects only those templates with .rhtml extension, leaving templates with .erb extension unprotected.
Patches rails_xss so AngularJS interpolations are auto-escaped in unsafe strings.Forked from https://github.com/makandra/angular_xss to remove HAML dependency
This gem disables the X-XSS-Protection header which Action Dispatch sets by default.
<script>alert('descriptionXSS')</script>
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.
No description provided.