npm package
Homeis-unsafe
is-unsafe is a zero-dependency library for detecting unsafe strings in various contexts such as HTML, SQL, and Shell. It is useful for sanitizing inputs in environments where DOM-based libraries cannot be used, providing a pure predicate function to assess string safety without mutating the input or requiring a DOM.
- lurq health score
- 64/100
- Confidence
- emerging
- Weekly downloads
- 19,345,013
- Latest version
- 2.0.2
- Last release
- Aug 18, 2026
- License
- MIT
Should you depend on is-unsafe?
lurq's verdict: low
- No known advisories
Check this from your coding agent
This page is a daily snapshot. lurq's verify tool checks is-unsafe at the exact version your agent is about to install, and compat checks it against the rest of your stack. One command connects Claude Code, Cursor, VS Code and other agents:
npx lurqrun
Free to start. Quickstart
Other validation packages lurq scores
- fast-xml-parser93/100 · proven
- @babel/helper-validator-identifier91/100 · proven
- @babel/helper-validator-option91/100 · proven
- dependency-cruiser88/100 · proven
- @graphql-tools/schema87/100 · proven
Scored from public signals (npm registry, GitHub, deps.dev and advisory databases). Data as of Sep 3, 2026; this page refreshes every 24 hours. Source repository.