checksumdir
Compute a single hash of the file contents of a directory.
Decision gist · record as of 2026-08-14
Yes. Checksumdir solves a specific, well-defined problem with zero dependencies, permissive licensing, and no known vulnerabilities. Install it if you need to hash directory contents for integrity checking or change detection. The aging maintenance is not a concern—the code is stable and the last commit was recent. Not worth installing if you need active feature development or extensive documentation.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low install friction with no runtime dependencies.
- Maintenance is aging—last release was 364 days ago, though the repository remains active with a recent commit on 2025-08-15 and modest community interest (102 stars).
License · maintenance · safety
MIT (permissive) — MIT license is permissive, allowing free use, modification, and distribution with minimal restrictions—suitable for most projects.
last release 2025-08-15 (364 days) · last repo commit 2025-08-15 · 102 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 769,406 downloads/mo, #5,107 on PyPI
Alternatives
Verify before relying
pip install checksumdir
from checksumdir import dirhash
md5hash = dirhash('/path/to/directory', 'md5')
sha256hash = dirhash('/path/to/directory', 'sha256', excluded_extensions=['pyc'])- Whether the package handles symlinks correctly by default or only with the --follow-links flag
- Performance characteristics on very large directories or deeply nested structures
- Whether excluded_files and excluded_extensions can be combined in a single call
What it is and what it does
Checksumdir is a lightweight utility that generates a single hash digest representing all file contents within a directory tree. It ignores file and directory metadata—only the actual file content matters—making it useful for detecting whether the substantive content of a directory has changed, independent of timestamps or file names. The package works as both a Python library (via the dirhash function) and a command-line tool, supporting multiple hash algorithms (md5, sha1, sha256) and offering fine-grained control over which files to include or exclude.
The module has no runtime dependencies and supports Python 3.9 through 3.13. It's straightforward to integrate into build pipelines, testing frameworks, or any workflow where you need to verify that directory contents haven't been altered. The aging maintenance status (last release 364 days ago) suggests stability rather than active development, and the absence of known vulnerabilities indicates it's safe to use.
Use it for
- Verify that cached build artifacts or downloaded packages haven't been corrupted or modified
- Detect changes in source code directories for incremental build systems or CI/CD pipelines
- Compare directory contents across machines or time periods without relying on file timestamps
- Exclude temporary or generated files (e.g., .pyc, node_modules) when computing integrity hashes
- Implement simple content-based deduplication or change detection in file synchronization tools
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Checksumdir solves a specific, well-defined problem with zero dependencies, permissive licensing, and no known vulnerabilities. Install it if you need to hash directory contents for integrity checking or change detection. The aging maintenance is not a concern—the code is stable and the last commit was recent. Not worth installing if you need active feature development or extensive documentation.
Install
checksumdir on PyPI
Before you install
Low install friction with no runtime dependencies. Maintenance is aging—last release was 364 days ago, though the repository remains active with a recent commit on 2025-08-15 and modest community interest (102 stars).
License in practice
MIT license is permissive, allowing free use, modification, and distribution with minimal restrictions—suitable for most projects.
Quickstart
pip install checksumdir
from checksumdir import dirhash
md5hash = dirhash('/path/to/directory', 'md5')
sha256hash = dirhash('/path/to/directory', 'sha256', excluded_extensions=['pyc'])
Verify before relying
- Whether the package handles symlinks correctly by default or only with the --follow-links flag
- Performance characteristics on very large directories or deeply nested structures
- Whether excluded_files and excluded_extensions can be combined in a single call
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release <4.0,>=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Aging 364 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 769,406 / month, #5,107 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Topic :: Utilities |
Evidence: checksumdir-1.3.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “directory hash checksum”
- checksumdirComputes a single hash digest of all file contents in a directory,…
- dirhashComputes a single hash value for an entire directory based on its…
- filehashCalculates and verifies file checksums and hashes using algorithms…
Give your agent the search over MCP, or paste the wish link into any chat.
More Utilities packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.
Install it if you need to display or transform source code.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
See also dirhash · pooch · setuptools-download · filehash · bagit · hashring · dict-hash · py-multihash · xxhash · siphash