{"enrichment":{"capability":"Provides hardened XML parsing wrappers around Python's standard library modules to defend against XML bomb attacks, entity expansion exploits, and external entity injection.","verdict":"defusedxml is a mature, stable library (Production/Stable status since 2013) that addresses well-known XML parsing vulnerabilities with zero security issues reported. Its dormant maintenance posture and three-year release gap are offset by its narrow, focused scope\u2014XML hardening rarely requires active development. Suitable for projects that parse untrusted XML and need defense against billion-laughs, quadratic blowup, and external entity attacks without external dependencies."},"id":"defusedxml","links":{"html":"https://skillfed.io/packages/defusedxml","md":"https://skillfed.io/packages/defusedxml.md","pypi":"https://pypi.org/project/defusedxml/"},"maintenance":{"status":"dormant"},"meta":{"latest_release":"2021-03-08","license_spdx":null,"license_treatment":"permissive","name":"defusedxml","python_support":"supports_current","summary":"XML bomb protection for Python stdlib modules"},"popularity":{"tier":"top_1000"},"security":{"n_vulnerabilities":0},"version":"0.7.1"}
