bandit
Security oriented static analyser for python code.
Decision gist · record as of 2026-08-14
Yes. Bandit is a production-stable, actively maintained security tool with no known vulnerabilities, low install friction, and permissive licensing. It fills a clear need for Python security scanning and is widely used in professional environments.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Low install friction with four lightweight runtime dependencies.
- Active maintenance with a recent release and ongoing repository activity.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 is permissive, allowing commercial and private use with minimal restrictions beyond attribution and liability disclaimers.
last release 2026-02-25 (170 days) · last repo commit 2026-08-04 · 8,212 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 29,001,887 downloads/mo, #826 on PyPI
Alternatives
Verify before relying
pip install bandit
bandit -r /path/to/code- Whether the tool catches all common Python security patterns or has known blind spots in specific vulnerability categories.
- Performance characteristics when scanning very large codebases or projects with thousands of files.
What it is and what it does
Bandit is a static security analyzer for Python code that builds an abstract syntax tree from each file and runs security-focused plugins against it to detect common vulnerabilities. It processes entire codebases and generates a report of findings, making it useful for developers and security teams who want to catch security issues before code reaches production.
The tool depends on PyYAML for configuration, stevedore for plugin management, and rich and colorama for formatted console output. It supports modern Python versions and is actively maintained by the PyCQA community.
Use it for
- Scan a codebase before committing to identify hardcoded credentials, insecure function calls, or weak cryptography usage.
- Integrate into a CI/CD pipeline to block merges when security issues are detected.
- Audit third-party or legacy Python code for common security anti-patterns.
- Generate security reports for compliance or code review processes.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Bandit is a production-stable, actively maintained security tool with no known vulnerabilities, low install friction, and permissive licensing. It fills a clear need for Python security scanning and is widely used in professional environments.
Install
bandit on PyPI
Before you install
Low install friction with four lightweight runtime dependencies. Active maintenance with a recent release and ongoing repository activity.
Requires Python 3.10 or later.
License in practice
Apache-2.0 is permissive, allowing commercial and private use with minimal restrictions beyond attribution and liability disclaimers.
Quickstart
pip install bandit
bandit -r /path/to/code
Verify before relying
- Whether the tool catches all common Python security patterns or has known blind spots in specific vulnerability categories.
- Performance characteristics when scanning very large codebases or projects with thousands of files.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 4 packagesPyYAMLstevedorerichcolorama |
| Maintenance | Actively maintained 170 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 29,001,887 / month, #826 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Information TechnologyIntended Audience :: System AdministratorsOperating System :: MacOS :: MacOS XOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Security |
Evidence: bandit-1.9.4-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “find security vulnerabilities in code”
- banditBandit scans Python code to identify common security issues by…
- njsscannjsscan is a static application security testing (SAST) tool that…
- mythrilMythril analyzes EVM bytecode for security vulnerabilities in smart…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also flake8-bandit · bandit-sarif-formatter · prospector · semgrep · flawfinder · pure-eval · truffleHog · pylint · pysentry-rs · mabwiser