escape-goat
Escape a string for use in HTML or the inverse
character-parser
Parse JavaScript one character at a time to look for snippets in Templates. This is not a validator, it's just designed to allow you to have sections of JavaScript delimited by brackets robustly.
puka
A cross-platform library for safely passing strings through shells
uri-tag
ES6 template literal tag to encode URI components
security
Utility methods for escaping according to OWASP.