Socket
Socket
Sign inDemoInstall

xss-shield

Package Overview
Dependencies
Maintainers
1
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

xss-shield

A powerful middleware for securing your express.js applications against cross-site scripting (XSS) attacks


Version published
Maintainers
1
Created
Source

xss-shield

This package provides a middleware for Express.js that helps protect against cross-site scripting (XSS) attacks. It's built on top of the xss module and is written in TypeScript.

contributors last update forks stars open issues license

Installation

To use this middleware, first install it using npm or yarn:

npm install xss-shield

or

yarn add xss-shield

Usage

To use this middleware in your Express.js application, simply require or import it and add it to your middleware stack:

const express = require('express'); 
const xssShield = require('xss-shield');

const app = express();

// Add the middleware to the middleware stack
app.use(xssShield());

You can also pass options to the middleware to customize its behavior. See the xss documentation for available options.

const express = require('express'); 
const xssShield = require('xss-shield');

const app = express();

// Add the middleware to the middleware stack with options
app.use(xssShield({
  whiteList: {
    a: ['href', 'title', 'target'],
    img: ['src', 'alt'],
  }
}));

License

xss-shield is licensed under the MIT License. See LICENSE for more information.

Keywords

FAQs

Package last updated on 23 Mar 2023

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc