NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2930 most downloaded on npm
A url sanitizer
Last release 8 months ago
29 Jan 2026
Release timing varies
gaps range from 2 weeks to 1.1 years
Nearly every release is documented
notes for 13 of 13 stable releases
14 versions withdrawn
withdrawn after publishing
9 years old
27 releases · first in 2017
eslint-plugin-prettier to 5.5.4
DevDependency Changes happy-dom to 15.11.6 Update (sub-)dependencies cross-spawn to 7.0.6 micromatch to 4.0.8 vite to 4.5.5
DevDependency Changes
Update (sub-)dependencies
One column per quarter.
Updated to handle back-slashes
Updates get-func-name to 2.0.2
Dependencies Update braces to 3.0.3
Improve sanitization of whitespace escapes
Improve sanitization of whitespace escapes
Improve sanitization of HTML entities
Move constant declarations from index file to constants.ts file
Move constant declarations from index file to constants.ts file
Update to node v18
Dev Dependency Updates
Add additional null byte sanitization prior to html decoding
Add null check to beginning of sanitizeUrl function
sanitizeUrl function (#54)Fix issue where urls in the form https://example.com /something were not properly sanitized
https://example.com

/something were not properly sanitizedFix issue where urls in the form javascript:alert('xss'); were not properly sanitized
javascript:alert('xss'); were not properly sanitizedjavasc	ript:alert('XSS'); were not properly sanitizedDecode HTML characters automatically that would result in an XSS vulnerability when rendering links via a server rendered HTML file
// decodes to javacript:alert('XSS')
const vulnerableUrl =
"javascript:alert('XSS')";
sanitizeUrl(vulnerableUrl); // 'about:blank'
const okUrl = "https://example.com/" + vulnerableUrl;
// since the javascript bit is in the path instead of the protocol
// this is successfully sanitized
sanitizeUrl(okUrl); // 'https://example.com/javascript:alert('XSS');
Fix issue where certain invisible white space characters were not being sanitized
Fix issue where certain safe characters were being filtered out (#31 thanks @akirchmyer)
Sanitize vbscript urls (thanks @vicnicius)
Fixup path to type declaration (closes #25)
- Add typescript types
Fix issue where urls with accented characters were incorrectly sanitized
Protocol-less urls (ie: www.example.com) will be sanitised and passed on instead of sending out about:blank (Thanks @chawes13 #18)
www.example.com) will be sanitised and passed on instead of sending out about:blank (Thanks @chawes13 #18)- Trim whitespace from urls
Replace blank strings with about:blank
Allow relative urls to be sanitized
Sanitize malicious URLs that begin with \s
\sSanitize malicious URLs that begin with %20
- sanitize data: urls
- sanitize javascript: urls
Your coding agent can read these notes before it upgrades. Set up the MCP server →