bleach-allowlist
Curated lists of tags and attributes for sanitizing html
Decision gist · record as of 2026-08-14
Yes, if you are already using bleach and want to avoid manually curating allowlists. The permissive BSD license and zero runtime dependencies make it low-risk to add. However, the package is abandoned and has not been updated since 2020; verify that its allowlists align with your current HTML/CSS standards and consider monitoring bleach for breaking changes that this package will not address.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires bleach to be installed separately; bleach-allowlist is only a data package of allowlists, not a complete sanitization solution.
- Low install friction with no runtime dependencies.
- However, the package is abandoned—last commit was 2022-06-20 and no releases since 2020-08-13.
License · maintenance · safety
BSD License (permissive) — BSD License (permissive) allows commercial and private use with minimal restrictions, making it suitable for most projects from a licensing standpoint.
last release 2020-08-13 (2192 days) · last repo commit 2022-06-20 · 14 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 896,985 downloads/mo, #4,786 on PyPI
Alternatives
Verify before relying
pip install bleach-allowlist
import bleach
from bleach_allowlist import print_tags, print_attrs, all_styles
bleach.clean(raw_html, print_tags, print_attrs, all_styles)- Whether the curated allowlists remain adequate for current HTML/CSS standards given the package's abandonment since 2022.
- Compatibility with recent versions of bleach and Python versions beyond what the fact sheet specifies.
What it is and what it does
bleach-allowlist is a data package that bundles pre-curated allowlists of safe HTML tags, attributes, and CSS styles for use with the bleach HTML sanitization library. It eliminates the need to manually define which HTML elements and styles are permitted when filtering user-provided markup. The package includes task-specific presets: markdown_tags and markdown_attrs for rendering markdown-style HTML, print_tags and print_attrs for print/PDF output, and all_styles and standard_styles for CSS property whitelisting.
The package is designed to be used as a reference or directly passed to bleach.clean() to enforce consistent, vetted sanitization rules across applications. It has no runtime dependencies and installs with low friction, but it is no longer actively maintained—the last commit was in June 2022 and no releases have occurred since August 2020. Users should verify that the allowlists remain suitable for their current HTML and CSS requirements.
Use it for
- Sanitizing user-submitted HTML in comment systems or forums using bleach with pre-vetted markdown-safe tag allowlists.
- Filtering HTML for PDF or print rendering by applying print_tags and print_attrs to remove web-only markup.
- Whitelisting CSS properties in user-generated content by passing all_styles or standard_styles to bleach for style attribute sanitization.
- Establishing consistent HTML sanitization policies across multiple applications by reusing the same curated allowlists.
- Rendering markdown-converted HTML safely by applying the markdown_tags and markdown_attrs presets to bleach.clean().
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are already using bleach and want to avoid manually curating allowlists.
The permissive BSD license and zero runtime dependencies make it low-risk to add. However, the package is abandoned and has not been updated since 2020; verify that its allowlists align with your current HTML/CSS standards and consider monitoring bleach for breaking changes that this package will not address.
Install
bleach-allowlist on PyPI
Before you install
Low install friction with no runtime dependencies. However, the package is abandoned—last commit was 2022-06-20 and no releases since 2020-08-13. Security and compatibility fixes are unlikely.
Requires bleach to be installed separately; bleach-allowlist is only a data package of allowlists, not a complete sanitization solution.
License in practice
BSD License (permissive) allows commercial and private use with minimal restrictions, making it suitable for most projects from a licensing standpoint.
Quickstart
pip install bleach-allowlist
import bleach
from bleach_allowlist import print_tags, print_attrs, all_styles
bleach.clean(raw_html, print_tags, print_attrs, all_styles)
Verify before relying
- Whether the curated allowlists remain adequate for current HTML/CSS standards given the package's abandonment since 2022.
- Compatibility with recent versions of bleach and Python versions beyond what the fact sheet specifies.
Package facts
| License | BSD License permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Abandoned 2,192 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 896,985 / month, #4,786 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: Web EnvironmentIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: PythonTopic :: Internet :: WWW/HTTPTopic :: Internet :: WWW/HTTP :: Dynamic Content |
Evidence: bleach_allowlist-1.0.3-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “bleach html sanitization allowlist”
- bleach-allowlistProvides curated allowlists of HTML tags, attributes, and CSS styles…
- types-bleachProvides type stubs for the bleach HTML sanitization library,…
- django-bleachIntegrates bleach HTML sanitization into Django models, forms, and…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also bleach · html-sanitizer · django-bleach · nh3 · lxml-html-clean · types-bleach · django-markdownify · css-inline · html-tag-names · sanitize-filename