# xss-clean

> Middleware to sanitize user input

Latest version **0.1.4** (published 2023-06-02) · MIT license · 0 weekly downloads

> **Deprecated.** This package is deprecated.

## Install

```sh
npm install xss-clean
pnpm add xss-clean
yarn add xss-clean
bun add xss-clean
```

## Health

**Score 10/100 (F)** — status: deprecated.

Negative: deprecated.

## Facts

| | |
|---|---|
| Version | 0.1.4 |
| Published | 2023-06-02 |
| First published | 2016-02-26 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 1 |
| Unpacked size | 5.1 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Maintainers | jsonmaur |

## Links

- npm: https://www.npmjs.com/package/xss-clean
- npm.io page: https://npm.io/package/xss-clean

## Dependencies (1)

- [xss-filters](https://npm.io/package/xss-filters.md) 1.2.7

## Recent versions

- 0.1.4 (latest) — 2023-06-02
- 0.1.3 — 2023-06-01
- 0.1.2 — 2023-06-01
- 0.1.1 — 2016-02-26
- 0.1.0 — 2016-02-26

## README

# Announcement

**This library has been deprecated. The implementation is quite simple, and I would suggest you copy the source code directly into your application using the [xss-filters](https://github.com/YahooArchive/xss-filters) dependency, or look for alternative libraries with more features and attention. Thanks for your support.**

---

Node.js Connect middleware to sanitize user input coming from POST body, GET queries, and url params. Works with [Express](http://expressjs.com/), [Restify](http://restify.com/), or any other [Connect](https://github.com/senchalabs/connect) app.

- [How to Use](#use)
- [License](#license)

## How to Use
```bash
npm install xss-clean --save
```

```javascript
const restify = require('restify')
const xss = require('xss-clean')

const app = restify.createServer()

app.use(restify.bodyParser())

// make sure this comes before any routes
app.use(xss())

app.listen(8080)
```

This will sanitize any data in `req.body`, `req.query`, and `req.params`. You can also access the API directly if you don't want to use as middleware.

```javascript
const clean = require('xss-clean/lib/xss').clean

const cleaned = clean('<script></script>')
// will return "&lt;script>&lt;/script>"
```

---
_Source: https://npm.io/package/xss-clean · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
