
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@remix-run/html-template
Advanced tools
Safe HTML template tag with auto-escaping for JavaScript.
html-template provides a tagged template literal for safely constructing HTML strings with automatic escaping of interpolated values to prevent XSS vulnerabilities.
html.raw when you need unescaped HTML from trusted sourcesInstall from npm:
npm install @remix-run/html-template
import { html } from '@remix-run/html-template'
let userInput = '<script>alert("XSS")</script>'
let greeting = html`<h1>Hello ${userInput}!</h1>`
console.log(String(greeting))
// Output: <h1>Hello <script>alert("XSS")</script>!</h1>
By default, all interpolated values are automatically escaped to prevent XSS attacks.
If you have trusted HTML that should not be escaped, use html.raw:
import { html } from '@remix-run/html-template'
let trustedIcon = '<svg>...</svg>'
let button = html.raw`<button>${trustedIcon} Click me</button>`
console.log(String(button))
// => <button><svg>...</svg> Click me</button>
Warning: Only use html.raw with content you trust. Never use it with user input.
SafeHtml values can be nested without double-escaping:
import { html } from '@remix-run/html-template'
let title = html`<h1>My Title</h1>`
let content = html`<p>Some content with ${userInput}</p>`
let page = html`
<!doctype html>
<html>
<body>
${title} ${content}
</body>
</html>
`
You can interpolate arrays of values, which will be flattened and joined:
import { html } from '@remix-run/html-template'
let items = ['Apple', 'Banana', 'Cherry']
let list = html`
<ul>
${items.map((item) => html`<li>${item}</li>`)}
</ul>
`
Use null or undefined to render nothing:
import { html } from '@remix-run/html-template'
let showError = false
let errorMessage = 'Something went wrong'
let page = html`<div>${showError ? html`<div class="error">${errorMessage}</div>` : null}</div>`
@remix-run/fetch-router - HTTP router that works great with html-templateSee LICENSE
FAQs
HTML template tag with auto-escaping for JavaScript
The npm package @remix-run/html-template receives a total of 3,683 weekly downloads. As such, @remix-run/html-template popularity was classified as popular.
We found that @remix-run/html-template demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.