# @locker/html-sanitizer

> Lightning Web Security HTML and SVG sanitization utilities

Latest version **0.28.11** (published 2026-09-23) · SEE LICENSE IN LICENSE.txt license · 0 weekly downloads

## Install

```sh
npm install @locker/html-sanitizer
pnpm add @locker/html-sanitizer
yarn add @locker/html-sanitizer
bun add @locker/html-sanitizer
```

## Health

**Score 60/100 (C)** — status: active.

Positive: esm support; no vulnerabilities; recently updated; high maintenance score.

Warnings: low downloads; no types; pre 1.0.

## Facts

| | |
|---|---|
| Version | 0.28.11 |
| Published | 2026-09-23 |
| First published | 2020-08-17 |
| Weekly downloads | 0 |
| License | SEE LICENSE IN LICENSE.txt |
| TypeScript types | none |
| Module format | ESM + CommonJS |
| Dependencies | 5 |
| Unpacked size | 51.7 KB |
| Known vulnerabilities | 0 (+2 in 1 direct dependencies) |
| Install scripts | no |
| Author | Salesforce UI Security Team |
| Maintainers | mjasso, caridy, jdalton, t.lau, dejang, rwaldron, garychangsf, achabot |

## Links

- npm: https://www.npmjs.com/package/@locker/html-sanitizer
- npm.io page: https://npm.io/package/@locker/html-sanitizer

## Dependencies (5)

- [dompurify](https://npm.io/package/dompurify.md) 3.4.11
- [@locker/shared](https://npm.io/package/@locker/shared.md) 0.28.11
- [@locker/shared-dom](https://npm.io/package/@locker/shared-dom.md) 0.28.11
- [@locker/shared-url](https://npm.io/package/@locker/shared-url.md) 0.28.11
- [@locker/trusted-types](https://npm.io/package/@locker/trusted-types.md) 0.28.11

## Recent versions

- 0.28.11 (latest) — 2026-09-23
- 0.29.2 — 2026-09-21
- 0.28.10 — 2026-09-04
- 0.27.10 — 2026-09-03
- 0.28.9 — 2026-09-01
- 0.27.9 — 2026-08-31
- 0.27.8 — 2026-08-31
- 0.28.8 — 2026-08-20
- 0.29.1 — 2026-08-20
- 0.29.0 — 2026-08-18
- 0.28.7 — 2026-08-12
- 0.28.6 — 2026-07-31
- 0.28.5 — 2026-07-23
- 0.28.4 — 2026-07-01
- 0.27.7 — 2026-06-23
- … 263 more at https://npm.io/package/@locker/html-sanitizer/versions

## README

# @locker/html-sanitizer powered by DOMPurify

> Lightning Web Security HTML and SVG sanitization utilities

This package provides a set of utilities to facilitate the sanitization of HTML
and SVG using [DOMPurify].

## Features

- Caching mechanism to store DOMPurify instances based on configuration objects.
  This avoids re-parsing the configuration object.
- Utility functions meant to facilitate working with predefined configuration
  objects required by Locker in various scenarios, i.e sanitization of SVG strings,
  sanitization of Blob HTML content strings, sanitization of strings that are to
  be usd with `innerHTML`, `outerHTML` etc.
- Hook for sanitizing SVG network resources (even if they are nested).

[DOMPurify]: https://www.npmjs.com/package/dompurify

## Upgrading DOMPurify

To upgrade DOMPurify, simply update the version number of the `"dompurify"` dependency in this [package.json](package.json) and the root [package.json](../../../package.json).

However, in production, Locker/LWS uses DOMPurify from Aura, and for this reason, the version of DOMPurify used by Locker/LWS in this repo must be kept in sync with the DOMPurify version in Aura.

Please see [Aura's DOMPurify](https://gitcore.soma.salesforce.com/core-2206/core-public/blob/p4/main/core/ui/aura/aura-resources/java/resources/aura/resources/DOMPurify/README.md) documentation for instructions on how to do that.

---
_Source: https://npm.io/package/@locker/html-sanitizer · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
