helmetjs/helmet

Help secure Express apps with various HTTP headers

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 31 minutes ago
Added to GitGenius on September 5th, 2026
Created on February 1st, 2012
Open Issues & Pull Requests: 9 (+0)
GitHub issues: Enabled
Number of forks: 413
Total Stargazers: 10,732 (+0)
Total Subscribers: 97 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 6.5 hours
Mean response time: 29.3 hours
90th percentile: 42.2 hours
Tracked items: 25

How this project is maintained

Around half of the issues opened in the past year never receive a reply. Only 8% of issues opened in the past year have been closed. Three people close 95% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 4
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 682 days
Stale 30+ days: 4
Stale 90+ days: 2

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • needs more information (7)
  • feedback wanted (1)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

Helmet is middleware for Express applications that secures them by setting various HTTP headers.

HTTP headers provide a first line of defense against common web vulnerabilities, but developers often miss which headers to set or misconfigure them. Helmet automatically applies a suite of header-setting middleware functions to Express apps, each addressing specific security concerns. Rather than requiring developers to manually research and implement individual headers, Helmet bundles sensible defaults that follow security best practices and can be customized per application needs.

Helmet suits any Express-based web application where security is a concern, from small projects to large production systems. It is particularly valuable for teams without dedicated security expertise, as it reduces the cognitive load of security header configuration. The tool integrates as standard middleware and can be adopted incrementally, enabling or disabling specific header protections as needed.

The project maintains a steady stream of updates addressing new security considerations and compatibility with evolving Express versions. Maintenance activity shows consistent attention to reported issues and pull requests. The codebase is written in TypeScript, providing type safety for developers integrating the middleware into their applications.