Skip to content

Security notes

The library reads and writes spreadsheet data. It does not execute macros, access the network, or resolve external entities. VBA content can be retained as data with bookVBA; preserving it does not execute it.

Malformed input can throw. Catch those errors, limit accepted file sizes, and apply your application’s resource limits. A compressed workbook may expand substantially in memory. Do not assume a small uploaded file will be cheap to parse.

For a web application, use a worker for large inputs. For a service, apply limits appropriate to the workload. sheetRows limits parsed rows, but is not a complete memory or security boundary.

Spreadsheet cells can contain formulas and hyperlinks. Preserving them is not the same as checking whether they are safe for your users to open or follow. Apply your own rules before exporting untrusted data. Text beginning with =, +, -, or @ may be interpreted as a formula by an application opening CSV; decide whether to neutralize it for your export.

When rendering HTML output in a web page, treat it as generated content and follow your application’s HTML safety policy. Do not substitute untrusted HTML for a plain cell value.

Worksheet protection controls spreadsheet editing permissions. It is not file encryption. The package does not provide file encryption or the utils.hash_password and utils.test_password runtime functions. Type declarations for those helpers are retained for compatibility, not evidence that the runtime implements them.

WebAssembly compilation needs 'wasm-unsafe-eval' in script-src. Prefer that narrower permission to 'unsafe-eval'. See Browsers and CSP.