express-xss-sanitizer
Express 4.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack.
jsrender
Best-of-breed templating in browser or on Node.js (with Express 4, Hapi and Browserify integration)