# koa-helmet

> Security header middleware collection for koa

Latest version **9.0.0** (published 2025-12-28) · MIT license · 0 weekly downloads

## Install

```sh
npm install koa-helmet
pnpm add koa-helmet
yarn add koa-helmet
bun add koa-helmet
```

## Health

**Score 60/100 (C)** — status: stable.

Positive: has types; esm support; no vulnerabilities; high quality score.

Warnings: low downloads.

## Facts

| | |
|---|---|
| Version | 9.0.0 |
| Published | 2025-12-28 |
| First published | 2014-03-30 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | ESM + CommonJS |
| Node | >= 18.0.0 |
| Dependencies | 0 |
| Unpacked size | 8.3 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 637 |
| Author | Matt Venables |
| Maintainers | venables |
| Keywords | csp, headers, helmet, hsts, koa, security, x-frame-options |

## Links

- npm: https://www.npmjs.com/package/koa-helmet
- Repository: https://github.com/venables/koa-helmet
- Homepage: https://github.com/venables/koa-helmet#readme
- Issues: https://github.com/venables/koa-helmet/issues
- npm.io page: https://npm.io/package/koa-helmet

## Recent versions

- 9.0.0 (latest) — 2025-12-28
- 1.1.0 (koa1) — 2017-01-20
- 2.0.0-alpha.1 (alpha) — 2015-12-24
- 0.2.0-beta2 (beta) — 2015-07-17
- 8.0.3 — 2025-12-16
- 8.0.2 — 2025-12-10
- 8.0.1 — 2024-11-28
- 8.0.0 — 2024-11-27
- 7.1.0 — 2024-11-12
- 7.0.2 — 2023-03-27
- 7.0.1 — 2023-03-17
- 7.0.0 — 2023-03-17
- 6.1.0 — 2021-03-14
- 6.0.0 — 2020-09-28
- 5.2.0 — 2019-10-07
- … 25 more at https://npm.io/package/koa-helmet/versions

## README

# koa-helmet

[![Version](https://img.shields.io/npm/v/koa-helmet.svg)](https://www.npmjs.com/package/koa-helmet)
[![Downloads](https://img.shields.io/npm/dm/koa-helmet.svg)](https://www.npmjs.com/package/koa-helmet)

koa-helmet is a wrapper for [helmet](https://github.com/helmetjs/helmet) to work with [koa](https://github.com/koajs/koa) (v2 and v3). It provides important security headers to make your app more secure by default.

This package has **zero** direct dependencies, with `peerDependencies` of koa and helmet.

## Installation

```sh
npm i koa-helmet helmet

# or:

bun add koa-helmet helmet
```

## Usage

Usage is the same as [helmet](https://github.com/helmetjs/helmet)

Helmet offers 11 security middleware functions:

```js
// This...
app.use(helmet());

// ...is equivalent to this:
app.use(helmet.contentSecurityPolicy());
app.use(helmet.dnsPrefetchControl());
app.use(helmet.expectCt());
app.use(helmet.frameguard());
app.use(helmet.hidePoweredBy());
app.use(helmet.hsts());
app.use(helmet.ieNoOpen());
app.use(helmet.noSniff());
app.use(helmet.permittedCrossDomainPolicies());
app.use(helmet.referrerPolicy());
app.use(helmet.xssFilter());
```

You can see more in [the documentation](https://helmetjs.github.io).

## Example

```js
import Koa from "koa";
import helmet from "koa-helmet";

const app = new Koa();

app.use(helmet());

app.use((ctx) => {
  ctx.body = "Hello World";
});

app.listen(4000);
```

## Testing

To run the test and lint suite, simply run

```
npm check
```

Alternatively, you can run:

```bash
npm run test
npm run lint
npm run format:check
```

## Contributing

Please see [CONTRIBUTING.md](CONTRIBUTING.md) for details.

## Versioning

- koa-helmet >=2.x (main branch) supports koa 2.x and 3.x
- koa-helmet 1.x ([koa-1](https://github.com/venables/koa-helmet/tree/koa-1) branch) supports koa 0.x and koa 1.x

---
_Source: https://npm.io/package/koa-helmet · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
