cure53/DOMPurify
63.6
Adequate · 1 October 2026
13.3k
lines of production code
JavaScript
with TypeScript
2
measurements over time
What this system is
This system is DOMPurify, a JavaScript library designed for sanitizing HTML and preventing cross-site scripting (XSS) attacks. It provides a robust API for configuring allowed tags and attributes, managing hooks for custom sanitization logic, and supporting complex scenarios like SVG handling and Trusted Types. The project includes comprehensive tooling for building, testing across multiple browsers and Node environments, and benchmarking performance to ensure security and reliability.
How it got here
2014–2015 — Build modernization and demo expansion
7 changes.
This period focused on modernizing the project's infrastructure by migrating the build system to Rolldown and the test suite to Playwright, while raising Node.js requirements. It also involved expanding the developer experience through a comprehensive new demo suite and a redesigned website with dark mode support.
2017–2025 — TypeScript migration and tooling
4 changes.
The core library was rewritten in TypeScript, introducing modular architecture, formal configuration interfaces, and dynamic hook management. Comprehensive tooling was added, including benchmarking scripts, type declaration fixes, and automated verification for multi-module TypeScript compatibility. Test coverage was expanded to validate new SVG attribute handling and security edge cases.
2026 — Testing infrastructure and build modernization
4 changes.
The project modernized its testing and build infrastructure by migrating browser tests from Karma to Playwright and adopting the Rolldown bundler. This period also introduced fuzz testing for DOMPurify sanitization and automated pre-commit hooks to enforce code quality and build integrity.
Features
Added Mental.js library to demos/lib
The Mental.js library file has been added to the demos/lib directory, providing a JavaScript parser implementation that includes token definitions and grammar rules for parsing JavaScript syntax.
demos/lib · high confidence
Added benchmarking script and build-time type declaration fixes
A new \scripts/benchmark.js\ harness is available for running deterministic performance comparisons of the built library across different scenarios (e.g., deep trees, wide attributes, dirty mixed input). Additionally, the build process now includes \scripts/fix-types.js\ to post-process generated type declarations, ensuring compatibility with older TypeScript versions by splitting inline \type\ exports and fixing CommonJS default export patterns.
scripts · high confidence
New demo suite for DOMPurify configuration and hooks
The demos directory now includes a comprehensive collection of interactive examples demonstrating how to use DOMPurify's configuration options and hook system. Users can explore basic sanitization, advanced configuration (such as allowing custom tags and attributes), and various hook implementations including text transformation, node removal, CSS sanitization, URI scheme allowlisting, link proxying, and sandboxing JavaScript via MentalJS. The suite also covers integration with Trusted Types and handling of SVG elements, providing practical reference code for common security and customization scenarios.
demos · high confidence
Project initialization with build, linting, and security configuration
The repository is initialized with essential configuration files to standardize development and enhance security. A \.babelrc\ file is added to configure Babel targets for modern browsers (Chrome 51+, Firefox 53+, etc.) and disable module transpilation. Prettier is configured via \.prettierrc\ to enforce consistent code formatting. Security and supply-chain hygiene are addressed through a \SECURITY.md\ detailing vulnerability reporting and release integrity, an \osv-scanner.toml\ to suppress known vulnerabilities in dev-only tooling, and a \CODEOWNERS\ file to require maintainer review for all changes. Additional files include \.editorconfig\, \.gitignore\, and \CONTRIBUTING.md\ to streamline contributor workflows.
(repo-wide) · high confidence
Behavioural changes
Automated linting and build checks on pre-commit
The pre-commit hook has been updated to automatically run linting, building, and commit-amend-build tasks before each commit. This ensures code quality and build integrity are verified locally before changes are recorded in the repository.
.husky · high confidence
DOMPurify source code refactored to TypeScript with new configuration and hook APIs
The core library in src has been rewritten in TypeScript, introducing a formal Config interface that allows ADD\_ATTR and ADD\_TAGS to accept functions for dynamic allow-listing, and adds a removeHook() method to the public API for managing hooks. The codebase is now split into modular files (purify, config, types, utils, tags, attrs, regexp) with immutable, frozen allow-lists for HTML and SVG elements and attributes, and includes a new license\_header file for build-time injection.
src · high confidence
Migration to Rolldown bundler and Playwright test runner
The build and test infrastructure has been updated to use the Rolldown bundler and Playwright for browser testing. The new rolldown configuration generates UMD, ESM, and CJS bundles along with TypeScript type declarations, ensuring strict mode is correctly applied in non-ESM formats. A dedicated coverage config instruments the code for accurate line and branch coverage mapping to original TypeScript sources. Additionally, Playwright is now used to run QUnit tests in Chromium, Firefox, and WebKit, with specific configurations for local development and CI environments.
config · high confidence
Redesigned DOMPurify demo website with modern UI and dark mode support
The website/index.html file has been completely rewritten to provide a modern, responsive demo interface for DOMPurify. The new design features a clean layout with CSS custom properties that automatically adapt to system light and dark color schemes (prefers-color-scheme). It includes a toolbar for configuring sanitization options, a text area for input, and a preview section, all styled with a contemporary aesthetic using system fonts and rounded corners. The page also loads jQuery 3.7.1 and the latest DOMPurify build from the CDN to power the interactive demo functionality.
website · high confidence
Test coverage
Added Playwright-based browser test infrastructure; Added TypeScript configuration verification script; Added fuzz testing for DOMPurify sanitization and configuration; Migrate test infrastructure from Karma to Playwright and add happy-dom Node runner; Updated test fixtures for SVG attributes and security edge cases.
Dependencies
DOMPurify 3.4.16 distribution files added
The distribution files for DOMPurify version 3.4.16 have been added to the \dist\ directory. This includes the CommonJS module (\purify.cjs.js\), its corresponding source map (\purify.cjs.js.map\), and the TypeScript type definitions (\purify.cjs.d.ts\).
dist · high confidence
Update to DOMPurify 3.4.16 with Rolldown build and Playwright test migration
DOMPurify is updated to version 3.4.16, introducing a significant build infrastructure change by replacing Rollup with Rolldown (v1.2.9) for bundling, alongside updated TypeScript (v5.6.3) and Babel (v7.29.7) tooling. The test suite has been migrated from Karma to Playwright (v1.61.0) for browser testing, with a new \test/legacy-playwright\ sub-package added to pin specific older Playwright versions (1.30.0 through 1.50.1) for legacy browser compatibility checks. The package exports are refined to explicitly target ESM and CommonJS entry points, and the Node.js engine requirement is raised to version 20 or higher.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 64 → 64 (-0.4)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 78 → 76 (-2.1)
- Architecture 99 → 99 (+0.4)
- Maturity 55 → 58 (+3.2)
- Readiness 59 → 58 (-0.6)
- Security 92 → 94 (+2.3)
- Performance 70 (new)
Resolved (5)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Hotspot: test/test-suite.js (test/test-suite.js)
- Off-boarding risk: anonymized user #1
- Orphaned files with no living knowledge
New (6)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (registry.npmjs.org published none of them)
- FileTooLong: src/purify.ts (src/purify.ts)
- FunctionTooLong: purify.createDOMPurify (src/purify.ts)
- Off-boarding risk: anonymized user #1
- purify.createDOMPurify (cognitive 390) (src/purify.ts)
- purify.createDOMPurify (cyclomatic 391) (src/purify.ts)
Changes since last survey
- 7 commits — 5 feature/other, 2 fixes
By area
- (root) — 4 commits
- .github/workflows — 2 commits
- typescript/commonjs-typescript-4.4 — 1 commit
Notable commits
- fix: fix: fixed a problem with IN_PLACE sanitization and removal hooks (#1633)
- fix: fix: keep the ESM default export out of the CommonJS declarations, verified against TypeScript 4.4 (#1634)
- change: build(deps): bump the actions group with 4 updates (#1627)
- change: build(deps): bump the actions group with 4 updates (#1648)
- change: build(deps-dev): bump the dev-dependencies group with 4 updates (#1620)
- change: chore: rolldown migration (#1632)
- change: release: 3.4.16 (#1635)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
cure53/DOMPurify was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 368ee78d528087ab192bcf06838013ec61c87ec8 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.