$npx skillfedfor your agent

bandit

Security oriented static analyser for python code.

Worth itPyPI SecurityReleased Feb 202629.0M downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — bandit-1.9.4-py3-none-any.whl
v1.9.4 · released 2026-02-25 · Python >=3.10 · 4 runtime deps: PyYAML, stevedore, rich, colorama

Yes. Bandit is a production-stable, actively maintained security tool with no known vulnerabilities, low install friction, and permissive licensing. It fills a clear need for Python security scanning and is widely used in professional environments.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Low install friction with four lightweight runtime dependencies.
  • Active maintenance with a recent release and ongoing repository activity.

License · maintenance · safety

Apache-2.0 (permissive) — Apache-2.0 is permissive, allowing commercial and private use with minimal restrictions beyond attribution and liability disclaimers.

last release 2026-02-25 (170 days) · last repo commit 2026-08-04 · 8,212 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 29,001,887 downloads/mo, #826 on PyPI

Verify before relying

pip install bandit

bandit -r /path/to/code
  • Whether the tool catches all common Python security patterns or has known blind spots in specific vulnerability categories.
  • Performance characteristics when scanning very large codebases or projects with thousands of files.
Same gist for agents: .md · .json

What it is and what it does

Bandit is a static security analyzer for Python code that builds an abstract syntax tree from each file and runs security-focused plugins against it to detect common vulnerabilities. It processes entire codebases and generates a report of findings, making it useful for developers and security teams who want to catch security issues before code reaches production.

The tool depends on PyYAML for configuration, stevedore for plugin management, and rich and colorama for formatted console output. It supports modern Python versions and is actively maintained by the PyCQA community.

Use it for

  • Scan a codebase before committing to identify hardcoded credentials, insecure function calls, or weak cryptography usage.
  • Integrate into a CI/CD pipeline to block merges when security issues are detected.
  • Audit third-party or legacy Python code for common security anti-patterns.
  • Generate security reports for compliance or code review processes.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Bandit is a production-stable, actively maintained security tool with no known vulnerabilities, low install friction, and permissive licensing. It fills a clear need for Python security scanning and is widely used in professional environments.

Install

bandit on PyPI

Before you install

Low install friction with four lightweight runtime dependencies. Active maintenance with a recent release and ongoing repository activity.

Requires Python 3.10 or later.

License in practice

Apache-2.0 is permissive, allowing commercial and private use with minimal restrictions beyond attribution and liability disclaimers.

Quickstart

pip install bandit

bandit -r /path/to/code

Verify before relying

  • Whether the tool catches all common Python security patterns or has known blind spots in specific vulnerability categories.
  • Performance characteristics when scanning very large codebases or projects with thousands of files.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
4 packages
PyYAMLstevedorerichcolorama
MaintenanceActively maintained 170 days since the last release
Last repo commit
First released
Downloads29,001,887 / month, #826 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Information TechnologyIntended Audience :: System AdministratorsOperating System :: MacOS :: MacOS XOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Security

Evidence: bandit-1.9.4-py3-none-any.whl

Tags

Capabilities
python security linterstatic security analysisfind security vulnerabilities in codepython ast security scannercode security auditing tool
Topics
security-scanningstatic-analysisast-based

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “find security vulnerabilities in code”

  • banditBandit scans Python code to identify common security issues by…
  • njsscannjsscan is a static application security testing (SAST) tool that…
  • mythrilMythril analyzes EVM bytecode for security vulnerabilities in smart…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also flake8-bandit · bandit-sarif-formatter · prospector · semgrep · flawfinder · pure-eval · truffleHog · pylint · pysentry-rs · mabwiser

Further reading