Skip to main content

Sanitize untrusted HTML fragments before rendering previews, comments, or CMS content with DOMPurify

Sanitizes untrusted HTML to ensure safe rendering in previews and CMS, protecting against XSS vulnerabilities.

Install this skill

or
97/100

Security score

The Sanitize untrusted HTML fragments before rendering previews, comments, or CMS content with DOMPurify skill was audited on Jun 6, 2026 and we found 3 security issues across 1 threat category. Review the findings below before installing.

Categories Tested

Security Issues

low line 35

External URL reference

SourceSKILL.md
35- Our automated tests cover 9 browser/OS combinations (Chromium, Firefox, and WebKit across Ubuntu, macOS, and Windows) on every push, plus Node.js v20, v22, v24, v25 and v26 running DOMPurify on [jsd
low line 36

External URL reference

SourceSKILL.md
36- DOMPurify technically also works server-side with Node.js. Our support strives to follow the [Node.js release cycle](https://nodejs.org/en/about/previous-releases).
low line 53

External URL reference

SourceSKILL.md
53- [Agent Skill Exchange](https://agentskillexchange.com/skills/sanitize-untrusted-html-fragments-before-rendering-previews-comments-or-cms-content-dompurify/)
Scanned on Jun 6, 2026
View Security Dashboard