# express-xss-sanitizer

> Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack.

Latest version **2.0.2** (published 2026-03-25) · MIT license · 0 weekly downloads

## Install

```sh
npm install express-xss-sanitizer
pnpm add express-xss-sanitizer
yarn add express-xss-sanitizer
bun add express-xss-sanitizer
```

## Health

**Score 53/100 (C)** — status: stable.

Positive: has types package; no vulnerabilities; high quality score.

Warnings: low downloads; no esm support.

## Facts

| | |
|---|---|
| Version | 2.0.2 |
| Published | 2026-03-25 |
| First published | 2020-11-20 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | separate (@types/express-xss-sanitizer) |
| Module format | CommonJS |
| Dependencies | 1 |
| Unpacked size | 47.3 KB |
| Known vulnerabilities | 0 (+3 in 1 direct dependencies) |
| Install scripts | no |
| GitHub stars | 28 |
| Author | Ahmed Adel |
| Maintainers | ahmedadelfahim |
| Keywords | express, koa, middleware, sanitizer, xss, security |

## Links

- npm: https://www.npmjs.com/package/express-xss-sanitizer
- Repository: https://github.com/AhmedAdelFahim/express-xss-sanitizer
- Homepage: https://github.com/AhmedAdelFahim/express-xss-sanitizer#readme
- Issues: https://github.com/AhmedAdelFahim/express-xss-sanitizer/issues
- npm.io page: https://npm.io/package/express-xss-sanitizer

## Dependencies (1)

- [sanitize-html](https://npm.io/package/sanitize-html.md) ~2.13.0

## Alternatives

- [@sindresorhus/slugify](https://npm.io/package/@sindresorhus/slugify.md) — 3.7M weekly downloads
- [solid-js](https://npm.io/package/solid-js.md) — 2.7M weekly downloads
- [expo-glass-effect](https://npm.io/package/expo-glass-effect.md) — 2.5M weekly downloads
- [nanoassert](https://npm.io/package/nanoassert.md) — 780.8K weekly downloads
- [@ffmpeg/ffmpeg](https://npm.io/package/@ffmpeg/ffmpeg.md) — 529.5K weekly downloads

## Recent versions

- 2.0.2 (latest) — 2026-03-25
- 2.0.1 — 2025-09-26
- 2.0.0 — 2024-12-28
- 1.2.1 — 2024-11-15
- 1.2.0 — 2024-03-22
- 1.1.9 — 2024-02-03
- 1.1.8 — 2024-01-05
- 1.1.7 — 2024-01-05
- 1.1.6 — 2022-10-08
- 1.1.5 — 2022-10-08
- 1.1.4 — 2022-10-07
- 1.1.3 — 2022-09-20
- 1.1.2 — 2022-08-06
- 1.1.1 — 2021-07-02
- 1.1.0 — 2021-02-24
- … 3 more at https://npm.io/package/express-xss-sanitizer/versions

## README

# Express XSS Sanitizer
Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack.

[![Build Status](https://img.shields.io/github/forks/AhmedAdelFahim/express-xss-sanitizer.svg?style=for-the-badge)](https://github.com/AhmedAdelFahim/express-xss-sanitizer)
[![Build Status](https://img.shields.io/github/stars/AhmedAdelFahim/express-xss-sanitizer.svg?style=for-the-badge)](https://github.com/AhmedAdelFahim/express-xss-sanitizer)
[![Latest Stable Version](https://img.shields.io/npm/v/express-xss-sanitizer.svg?style=for-the-badge)](https://www.npmjs.com/package/express-xss-sanitizer)
[![License](https://img.shields.io/npm/l/express-xss-sanitizer.svg?style=for-the-badge)](https://www.npmjs.com/package/express-xss-sanitizer)
[![NPM Downloads](https://img.shields.io/npm/dt/express-xss-sanitizer.svg?style=for-the-badge)](https://www.npmjs.com/package/express-xss-sanitizer)
[![NPM Downloads](https://img.shields.io/npm/dm/express-xss-sanitizer.svg?style=for-the-badge)](https://www.npmjs.com/package/express-xss-sanitizer)
## Installation
```bash
$ npm install express-xss-sanitizer
```
## Usage
Add as a piece of express middleware, before defining your routes.
```javascript
const express = require('express');
const bodyParser = require('body-parser');
const { xss } = require('express-xss-sanitizer');

const app = express();

app.use(bodyParser.json({limit:'1kb'}));
app.use(bodyParser.urlencoded({extended: true, limit:'1kb'}));
app.use(xss());
```
You can add options to control max number of recursion at sanitization to prevent DOS attacks.
```javascript
const options = {
   maxDepth: 50, // default 100
}

app.use(xss(options));
```
You can add options to specify allowed keys or allowed attributes to be skipped at sanitization
```javascript
const options = {
   allowedKeys: ['name'],
   allowedAttributes: {
         input: ['value'],
   },
}

app.use(xss(options));
```
You can add options to specify allowed tags to sanitize it and remove other tags
```javascript
const options = {
   allowedTags: ['h1']
}

app.use(xss(options));
```
Add as a piece of express middleware, before single route.
```javascript
const express = require('express');
const bodyParser = require('body-parser');
const { xss } = require('express-xss-sanitizer');

const app = express();

app.use(bodyParser.json({limit:'1kb'}));
app.use(bodyParser.urlencoded({extended: true, limit:'1kb'}));
app.post("/body", xss(), function (req, res) {
      // your code
});

app.post("/test", function (req, res) {
      // your code
});
```
__Note:__ if you adding xxs() as application level middleware, the xxs() will sanitize req.body, req.headers and req.query only and for req.params you must add xxs() as route level middleware like below example.

```javascript
const express = require('express');
const bodyParser = require('body-parser');
const { xss } = require('express-xss-sanitizer');

const app = express();

app.use(bodyParser.json({limit:'1kb'}));
app.use(bodyParser.urlencoded({extended: true, limit:'1kb'}));
app.post("/params/:val", xss(), function (req, res) {
      // your code
});

```
You also can sanitize your data (object, array, string,etc) on the fly.
```javascript
const { sanitize } = require('express-xss-sanitizer');

// ...
      data = sanitize(data)
// or
      data = sanitize(data, {allowedKeys: ['name']})
// ...
```
## For other frameworks
 * [koa-xss-sanitizer](https://www.npmjs.com/package/koa-xss-sanitizer)

## Tests
To run the test suite, first install the dependencies, then run `npm test`:
```bash
$ npm install
$ npm test
```
## Security

### Reporting Vulnerabilities
Please report security issues to [ahmedadelfahim@gmail.com](mailto:ahmedadelfahim@gmail.com)

### Security Updates
- **v2.0.1**: Fixed unbounded recursion depth vulnerability (CVE-2025-59364)
## Support
Feel free to open issues on [github](https://github.com/AhmedAdelFahim/express-xss-sanitizer.git).

---
_Source: https://npm.io/package/express-xss-sanitizer · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
