$npx skillfedfor your agent

confusable-homoglyphs

Detect confusable usage of unicode homoglyphs, prevent homograph attacks.

With conditionsPyPI UtilitiesReleased Jan 20241.5M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — confusable_homoglyphs-3.3.1-py2.py3-none-any.whl
v3.3.1 · released 2024-01-30

Yes, if you need to detect homograph attacks in usernames, domains, or user-generated text. The package is stable, has no dependencies, and installs easily. However, be aware the repository is archived and unmaintained—unicode data is current as of 2024-01-30, but you should monitor whether future Unicode standards require updates. Suitable for production use in security-sensitive contexts where the risk of homograph attacks justifies the maintenance trade-off.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Low friction: pure Python wheel with no runtime dependencies.
  • Repository is archived and maintenance is abandoned as of 927 days ago, though the latest release (2024-01-30) includes unicode data updates and the package is marked Production/Stable.

License · maintenance · safety

MIT (permissive) — MIT license (permissive) places no restrictions on use, modification, or distribution in proprietary or open-source projects.

last release 2024-01-30 (927 days) · last repo commit 2024-01-02 · 166 stars · archived

0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,490,797 downloads/mo, #3,844 on PyPI

Verify before relying

pip install confusable-homoglyphs

from confusable_homoglyphs import confusables

# Check if a string contains confusable characters
is_dangerous = confusables.is_dangerous('ΑlaskaJazz')
print(is_dangerous)  # True: mixed-script with confusable Greek alpha
  • Whether the unicode data (categories.json, confusables.json) remains current after 2024-01-30 without active maintenance.
  • Performance characteristics when checking large batches of usernames or domains.
  • Whether the CONFUSABLE_DATA environment variable feature is documented and stable.
Same gist for agents: .md · .json

What it is and what it does

confusable_homoglyphs detects when Unicode characters that look identical or nearly identical to each other are mixed in a single string—a technique attackers use to impersonate legitimate usernames or domains. For example, a Greek letter alpha (Α) looks almost identical to a Latin A, so 'ΑlaskaJazz' could fool users into thinking they're interacting with 'AlaskaJazz'. The library checks strings against Unicode Consortium data to identify these dangerous combinations and can be configured to allow only specific scripts (like Latin-only usernames) or to flag only confusable characters from particular Unicode blocks.

The package ships with pre-built JSON data files derived from official Unicode security data, so it works out of the box with no external dependencies. It supports Python 3.7 through 3.12 and exposes a simple API for checking whether a string is dangerous, whether it contains confusable characters, and what script blocks are present. The repository is archived and no longer maintained, but the last release included unicode data updates.

Use it for

  • Validate usernames during account creation to prevent attackers from registering lookalike accounts like 'ΑlaskaJazz' or 'Gооgle'.
  • Check domain names before allowing them in a whitelist or before displaying them to users to prevent phishing via homograph attacks.
  • Filter user-generated content or comments to flag mixed-script strings that might be attempts to evade moderation or impersonate other users.
  • Validate email addresses or social media handles to ensure they don't use confusable characters that could mislead recipients.
  • Build security tooling that alerts administrators when suspicious homoglyphs appear in logs or authentication attempts.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need to detect homograph attacks in usernames, domains, or user-generated text.

The package is stable, has no dependencies, and installs easily. However, be aware the repository is archived and unmaintained—unicode data is current as of 2024-01-30, but you should monitor whether future Unicode standards require updates. Suitable for production use in security-sensitive contexts where the risk of homograph attacks justifies the maintenance trade-off.

Install

confusable-homoglyphs on PyPI

Before you install

Low friction: pure Python wheel with no runtime dependencies. Repository is archived and maintenance is abandoned as of 927 days ago, though the latest release (2024-01-30) includes unicode data updates and the package is marked Production/Stable.

License in practice

MIT license (permissive) places no restrictions on use, modification, or distribution in proprietary or open-source projects.

Quickstart

pip install confusable-homoglyphs

from confusable_homoglyphs import confusables

# Check if a string contains confusable characters
is_dangerous = confusables.is_dangerous('ΑlaskaJazz')
print(is_dangerous)  # True: mixed-script with confusable Greek alpha

Verify before relying

  • Whether the unicode data (categories.json, confusables.json) remains current after 2024-01-30 without active maintenance.
  • Performance characteristics when checking large batches of usernames or domains.
  • Whether the CONFUSABLE_DATA environment variable feature is documented and stable.

Package facts

LicenseMIT permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceAbandoned 927 days since the last release
Last repo commit repository archived
First released
Downloads1,490,797 / month, #3,844 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Text ProcessingTopic :: Text Processing :: FiltersTopic :: Utilities

Evidence: confusable_homoglyphs-3.3.1-py2.py3-none-any.whl

Tags

Capabilities
homoglyph detectionunicode spoofing preventionhomograph attack detectionconfusable charactersmixed-script validationunicode securitycharacter confusion detection
Topics
securityunicodehomograph-attack
PyPI keywords
confusablehomoglyphattackhomographunicodespoofing

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “homoglyph detection”

  • confusable-homoglyphsDetects Unicode homoglyphs and mixed-script strings that could be…
  • confusablesDetects and matches words that appear identical but use different…
  • pyjarowinklerComputes Jaro and Jaro-Winkler similarity and distance scores between…

Give your agent the search over MCP, or paste the wish link into any chat.

More Utilities packages

idna Worth it
PyPI · Python Modules · released Jun 2026

Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.

Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.

BSD-3-Clausepure Python · 3.9+
1.8Bdownloads / mo
charset-normalizer Worth it
PyPI · Utilities · released Aug 2026

Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.

permissive licensepure Python · 3.7+
1.7Bdownloads / mo
setuptools Worth it
PyPI · Python Modules · released Aug 2026

Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.

MITpure Python · 3.10+
1.6Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
Pygments Worth it
PyPI · Utilities · released Mar 2026

Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.

Install it if you need to display or transform source code.

BSD-2-Clausepure Python · 3.9+
1.3Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo

See also confusables · dnstwist · Unidecode · graphemeu · ftfy · uniseg · grapheme · anyascii · tangled-up-in-unicode · emoji