JSPM

Found 69 results for content-security-policy

helmet

help secure Express/Connect apps with various HTTP headers

  • v8.1.0
  • 108.66
  • Published

csp_evaluator

Evaluate Content Security Policies for a wide range of bypasses and weaknesses

  • v1.1.5
  • 91.95
  • Published

helmet-csp

Content Security Policy middleware

  • v4.0.0
  • 86.50
  • Published

nuxt-security

🛡️ Security Module for Nuxt based on HTTP Headers and Middleware

  • v2.4.0
  • 75.98
  • Published

csp-header

Content-Security-Policy header generator

  • v6.1.0
  • 71.61
  • Published

@nosecone/next

Protect your Next.js application with secure headers

  • v1.0.0-beta.10
  • 68.30
  • Published

express-csp-header

Content-Security-Policy middleware for Express

  • v6.1.0
  • 65.29
  • Published

@next-safe/middleware

Strict Content-Security-Policy (CSP) for Next.js with composable middleware

  • v0.10.0
  • 64.94
  • Published

csp-toolkit

A comprehensive toolkit for working with Content Security Policy (CSP) directives in TypeScript.

  • v1.4.0
  • 64.52
  • Published

nosecone

Protect your Response with secure headers

  • v1.0.0-beta.10
  • 63.92
  • Published

vite-plugin-csp-guard

A Vite plugin that lets SPA applications generate a Content Security Policy (CSP).

  • v3.0.0
  • 62.59
  • Published

csp-typed-directives

Provides type information for all CSP directives and related headers' directives; as well as a basic utility funtion that helps convert the typed properties to the header content's policy string.

  • v1.1.10
  • 61.83
  • Published

strict-csp

Enables a hash-based strict Content Security Policy for static HTML files and single page applications.

  • v1.0.4
  • 58.61
  • Published

strict-csp-html-webpack-plugin

A webpack plugin that adds a hash-based strict CSP to help protect your site against XSS attacks.

  • v1.0.2
  • 55.28
  • Published

gatsby-plugin-csp

Adds Content Security Policy to your Gatsby app.

  • v1.1.4
  • 53.73
  • Published

csp-dev

Spec compliant content security policy builder and parser. 🚨

  • v1.0.2
  • 51.86
  • Published

property-expr-csp

tiny util for getting and setting deep object props safely

  • v1.4.0
  • 51.71
  • Published

@kindspells/astro-shield

Astro integration to enhance your website's security with SubResource Integrity hashes, Content-Security-Policy headers, and other techniques.

  • v1.7.1
  • 45.08
  • Published

gatsby-plugin-csp-nonce

Generate fixed nonces for scripts in Gatsby and make them available for the headers.

  • v1.2.0
  • 39.86
  • Published

@nosecone/sveltekit

Protect your SvelteKit application with secure headers

  • v1.0.0-beta.10
  • 33.92
  • Published

csp-builder

A builder tool to help generate Content Security Policies in a type-safe way

  • v1.1.1
  • 32.64
  • Published

vite-plugin-bun-csp

A Vite plugin that generates and injects a Content Security Policy (CSP) for your SPA application.

  • v2.1.0
  • 31.85
  • Published

vite-plugin-sri-gen

A Vite plugin to auto-generate Subresource Integrity (SRI) hashes.

  • v1.2.2
  • 31.72
  • Published

@cto.af/http-headers

Parse HTTP headers from RFC 9110 (and a bunch of others) using the full ABNF.

  • v1.0.2
  • 28.55
  • Published

csp-helper

Helpers for managing Content Security Policy (CSP)

  • v0.11.0
  • 27.52
  • Published

reporting-api

Roll your own Reporting API collector. Supports CSP, COEP, COOP, Document-Policy, Crash reports, Deprecation reports, Intervention reports and Network Error Logging

  • v1.0.4
  • 25.48
  • Published

@jackdbd/content-security-policy

Write your Content-Security-Policy header in JavaScript, so you can have validation and automatic hashes.

  • v3.0.0
  • 24.93
  • Published

csp-by-api

Easily build a Content Security Policy (CSP) by specifying APIs by name

  • v2.3.0
  • 22.00
  • Published

@1j01/live-server

live-server fork that adds Content-Security-Policy (CSP) support (a simple development http server with live reload capability)

  • v1.3.1
  • 19.71
  • Published

@frat/csp-serdes

Content-Security-Policy Serializer and Deserializer (Parser)

  • v1.0.1
  • 19.20
  • Published

securestack

A comprehensive authentication and security solution

  • v0.1.0
  • 17.88
  • Published

busted

A node module that detects improper iframe busting code

  • v1.0.0
  • 17.63
  • Published

next-armored

Security middlewares for Next.js

  • v1.0.0
  • 17.04
  • Published

@csp-kit/generator

Generate Content Security Policy headers for popular web services and libraries

  • v0.5.0
  • 17.04
  • Published

@csp-kit/data

Service definitions and CSP mappings database for csp-kit

  • v0.3.0
  • 16.91
  • Published

@mdworld/ingress-headers

A TypeScript utility for extracting and managing Content Security Policy (CSP) headers from Kubernetes ingress YAML files

  • v1.0.5
  • 16.33
  • Published

guardly

Security helper methods for front-end development

  • v1.0.15
  • 14.45
  • Published

tome-server

Zero dependency web server.

  • v2.0.0
  • 13.93
  • Published

@moroz/middleware

Strict Content-Security-Policy (CSP) for Next.js with composable middleware

  • v0.10.2
  • 12.67
  • Published

headgear

Sets various security related headers

  • v1.0.0
  • 12.37
  • Published

csp-policy-gen

A package to generate Content Security Policy (CSP) headers.

  • v1.0.3
  • 11.58
  • Published

@csp-kit/cli

Command-line tool for managing CSP service definitions and data updates

  • v0.2.3
  • 11.26
  • Published

csprefabricate

Generate valid and secure Content Security Policies (CSP) with TypeScript.

  • v2.0.0
  • 10.84
  • Published

@komw/next-safe-middleware

Strict Content-Security-Policy (CSP) for Next.js with composable middleware

  • v0.11.0
  • 10.15
  • Published

csp-serdes

Content-Security-Policy Serializer and Deserializer (Parser)

  • v1.0.1
  • 10.12
  • Published

grunt-csp-express

Tool to extract urls of a project for use in the Content-Security-Policy. Also includes warnings for usage with AngularJS.

  • v0.1.7
  • 10.08
  • Published

@moroz/builder

Builder with fluent interface for Content-Security-Policy (CSP) with IntelliSense

  • v0.0.0
  • 9.72
  • Published

arc-spa-csp

Content Security Policy (CSP) injector for Applications - React, Angular, and VITE projects with comprehensive environment variable support

  • v1.0.1
  • 9.31
  • Published

api-security-gateway

A security gateway for APIs with rate limiting, IP whitelisting, and injection prevention.

  • v1.0.1
  • 8.52
  • Published

csp-bun-cli

A CLI that generates and injects a Content Security Policy (CSP) for your SPA application.

  • v2.0.1
  • 8.52
  • Published

express-csp-generator

Content-Security-Policy Generator, Running as an express middleware that integrates with RapidSec.

  • v1.0.3
  • 7.88
  • Published

@kawaz/create-worker

Create Web Workers from inline functions without requiring separate worker files.

  • v1.3.8
  • 7.70
  • Published

csp-gen

generates a csp from a JSON file

  • v1.2.0
  • 6.75
  • Published

@mexican-man/pages-csp-generator

The goal of this package is to provide a simple automated way to generate Content Security Policy compliant headers for your Cloudflare Pages site at runtime. The primary goal is to automate hashing and nonces, but it will also scan your page to include a

  • v0.1.5
  • 6.04
  • Published

js-to-js

ExpressJS template engine to render JavaScript from JavaScript to avoid inlined code and allow strict and safe Content-Security-Policy

  • v1.4.1
  • 5.67
  • Published

@komw/next-safe-builder

Builder with fluent interface for Content-Security-Policy (CSP) with IntelliSense

  • v0.3.0
  • 5.63
  • Published

@klnjs/headers

This module provides types and functionality for parsing and stringifying Permissions Policy.

  • v1.0.0-beta.13
  • 5.63
  • Published

fixed-csp-parse

Content-Security-Policy policy parser

  • v0.0.3
  • 4.41
  • Published

csp-header-middleware

Middleware for express app for adding Content-Security-Policy header

  • v1.0.0
  • 2.62
  • Published

csp-scanner

A package to scan a website for its Content Security Policy (CSP) headers and report any issues.

    • v1.1.0
    • 2.49
    • Published

    @vchernin/strict-csp

    Enables a hash-based strict Content Security Policy for static HTML files and single page applications.

    • v1.0.6
    • 0.00
    • Published

    csp3-parser

    A CSP3 Parser based on W3 specification

    • v1.0.11
    • 0.00
    • Published