# eslint-plugin-xss

> Validates XSS related issues of mixing HTML and non-HTML content in variables.

Latest version **0.1.12** (published 2022-06-27) · ISC license · 0 weekly downloads

## Install

```sh
npm install eslint-plugin-xss
pnpm add eslint-plugin-xss
yarn add eslint-plugin-xss
bun add eslint-plugin-xss
```

## Health

**Score 23/100 (F)** — status: abandoned.

Positive: has types package; no vulnerabilities; high quality score.

Warnings: low downloads; no esm support; pre 1.0.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 0.1.12 |
| Published | 2022-06-27 |
| First published | 2016-04-25 |
| Weekly downloads | 0 |
| License | ISC |
| TypeScript types | separate (@types/eslint-plugin-xss) |
| Module format | CommonJS |
| Node | >=0.10.0 |
| Dependencies | 1 |
| Unpacked size | 76.4 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 73 |
| Author | Mikko Rantanen |
| Maintainers | rantanen |
| Keywords | eslint, eslintplugin, eslint-plugin |

## Links

- npm: https://www.npmjs.com/package/eslint-plugin-xss
- Repository: https://github.com/Rantanen/eslint-plugin-xss
- Homepage: https://github.com/Rantanen/eslint-plugin-xss#readme
- Issues: https://github.com/Rantanen/eslint-plugin-xss/issues
- npm.io page: https://npm.io/package/eslint-plugin-xss

## Dependencies (1)

- [requireindex](https://npm.io/package/requireindex.md) ~1.1.0

## Alternatives

- [eslint-plugin-sonarjs](https://npm.io/package/eslint-plugin-sonarjs.md) — 2.9M weekly downloads
- [eslint-config-expo](https://npm.io/package/eslint-config-expo.md) — 1.5M weekly downloads
- [@matter/protocol](https://npm.io/package/@matter/protocol.md) — 63.5K weekly downloads
- [@eventcatalog/linter](https://npm.io/package/@eventcatalog/linter.md) — 24.8K weekly downloads
- [@inrupt/eslint-config-base](https://npm.io/package/@inrupt/eslint-config-base.md) — 4.5K weekly downloads

## Recent versions

- 0.1.12 (latest) — 2022-06-27
- 0.1.11 — 2021-09-17
- 0.1.10 — 2020-02-14
- 0.1.9 — 2017-12-07
- 0.1.8 — 2016-09-06
- 0.1.7 — 2016-09-06
- 0.1.6 — 2016-09-05
- 0.1.5 — 2016-07-31
- 0.1.4 — 2016-07-25
- 0.1.3 — 2016-04-28
- 0.1.2 — 2016-04-27
- 0.1.1 — 2016-04-27
- 0.1.0 — 2016-04-27
- 0.0.11 — 2016-04-27
- 0.0.10 — 2016-04-27
- … 10 more at https://npm.io/package/eslint-plugin-xss/versions

## README

# eslint-plugin-xss

[![NPM version](http://img.shields.io/npm/v/eslint-plugin-xss.svg)](https://www.npmjs.com/package/eslint-plugin-xss)
[![Build Status](https://travis-ci.org/Rantanen/eslint-plugin-xss.svg?branch=master)](https://travis-ci.org/Rantanen/eslint-plugin-xss)
[![Codecov](https://codecov.io/gh/Rantanen/eslint-plugin-xss/branch/master/graph/badge.svg)](https://codecov.io/gh/Rantanen/eslint-plugin-xss)
[![Codacy](https://api.codacy.com/project/badge/grade/13e5c7abeb4545359ca9b02c0e91bb72)](https://www.codacy.com/app/jubjub/eslint-plugin-xss)

Tries to detect XSS issues in codebase before they end up in production.

## Installation

You'll first need to install [ESLint](http://eslint.org):

```
$ npm install eslint --save-dev
```

Next, install `eslint-plugin-xss`:

```
$ npm install eslint-plugin-xss --save-dev
```

**Note:** If you installed ESLint globally (using the `-g` flag) then you must also install `eslint-plugin-xss` globally.

## Usage

Add `xss` to the plugins section of your `.eslintrc` configuration file. You can omit the `eslint-plugin-` prefix:

```json
{
    "plugins": [
        "xss"
    ]
}
```

Then configure the rules you want to use under the rules section.

```json
{
    "rules": {
        "xss/rule-name": 2
    }
}
```

Or:

Enable all rules by adding the following to your `.eslintrc` configuration file

```json
{
    "extends": [
        "plugin:xss/recommended"
    ]
}
```

## Supported Rules

* [xss/no-mixed-html](docs/rules/no-mixed-html.md): Warn about possible XSS issues.
* [xss/no-location-href-assign](docs/rules/no-location-href-assign.md): Warn when trying to modify location.href.

---
_Source: https://npm.io/package/eslint-plugin-xss · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
