$npx skillfedfor your agent

defusedcsv

Drop-in replacement for Python's CSV library that tries to mitigate CSV injection attacks

With conditionsPyPI SecurityReleased Sep 20251.5M downloads / moApache License 2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — defusedcsv-3.0.0-py3-none-any.whl
v3.0.0 · released 2025-09-02

Yes, if you export CSV files containing any user-generated data. The library is lightweight, has no dependencies, and solves a real attack surface with minimal code changes. The aging maintenance status (346 days since last release) is not a blocker for a stable, narrow-scope utility, but monitor the repository for any security disclosures. No known vulnerabilities are recorded.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Low friction: pure Python wheel with no runtime dependencies.
  • Maintenance is aging—last release was 346 days ago, though the repository remains active with a recent commit on 2025-09-03.

License · maintenance · safety

Apache License 2.0 (permissive) — Apache License 2.0 (permissive) places no restrictions on use or distribution; you may use this in commercial or proprietary projects without obligation to share modifications.

last release 2025-09-02 (346 days) · last repo commit 2025-09-03 · 27 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,473,625 downloads/mo, #3,864 on PyPI

Verify before relying

from defusedcsv import csv
import io

output = io.StringIO()
writer = csv.writer(output)
writer.writerow(['@formula', 'normal_data', '=SUM()'])
print(output.getvalue())
  • Whether the escaping strategy (prepending apostrophe, replacing pipe characters) is sufficient against all known CSV injection vectors or if newer attack patterns exist.
  • Real-world compatibility with spreadsheet software versions beyond the implicit testing mentioned in the description.
  • Whether the library's defense remains effective across all supported Python versions (3.9 to 3.13).
Same gist for agents: .md · .json

What it is and what it does

Defusedcsv wraps Python's standard csv module to defend against CSV injection attacks—a vulnerability where malicious formulas in user-generated data can execute when a spreadsheet application opens the exported file. The library intercepts cells that begin with formula-triggering characters (@, +, -, =, |, %) and prepends an apostrophe to neutralize them; it also replaces pipe characters in those cells with escaped equivalents. The apostrophe remains invisible to end users in most spreadsheet software, making the defense transparent.

It is designed as a drop-in replacement: you swap `import csv` for `from defusedcsv import csv` and use the API identically. The library supports Python 3.9 to 3.13 and carries no external dependencies, making installation and integration straightforward. The trade-off is that the resulting CSV files are slightly altered—cells that would have triggered formulas are now safe but visually different in raw form.

Use it for

  • Exporting user-submitted survey or form data to CSV without risk of formula injection in recipient spreadsheets.
  • Building a web application that generates downloadable CSV reports from untrusted user input.
  • Protecting against accidental or deliberate CSV injection when aggregating data from multiple sources into a single export file.
  • Ensuring compliance with security best practices when handling CSV export in multi-tenant SaaS platforms.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you export CSV files containing any user-generated data.

The library is lightweight, has no dependencies, and solves a real attack surface with minimal code changes. The aging maintenance status (346 days since last release) is not a blocker for a stable, narrow-scope utility, but monitor the repository for any security disclosures. No known vulnerabilities are recorded.

Install

defusedcsv on PyPI

Before you install

Low friction: pure Python wheel with no runtime dependencies. Maintenance is aging—last release was 346 days ago, though the repository remains active with a recent commit on 2025-09-03.

License in practice

Apache License 2.0 (permissive) places no restrictions on use or distribution; you may use this in commercial or proprietary projects without obligation to share modifications.

Quickstart

from defusedcsv import csv
import io

output = io.StringIO()
writer = csv.writer(output)
writer.writerow(['@formula', 'normal_data', '=SUM()'])
print(output.getvalue())

Verify before relying

  • Whether the escaping strategy (prepending apostrophe, replacing pipe characters) is sufficient against all known CSV injection vectors or if newer attack patterns exist.
  • Real-world compatibility with spreadsheet software versions beyond the implicit testing mentioned in the description.
  • Whether the library's defense remains effective across all supported Python versions (3.9 to 3.13).

Package facts

LicenseApache License 2.0 permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceAging 346 days since the last release
Last repo commit
First released
Downloads1,473,625 / month, #3,864 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Intended Audience :: DevelopersIntended Audience :: Other AudienceLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9

Evidence: defusedcsv-3.0.0-py3-none-any.whl

Tags

Capabilities
csv injection preventionsafe csv exportdefuse csv attackscsv formula injectionsecure csv writerexcel injection protectioncsv cell escaping
Topics
csv-injectiondata-exportsecurity-hardening
PyPI keywords
csvinjectiondefusesave

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “csv injection prevention”

  • defusedcsvDefusedcsv is a drop-in replacement for Python's standard csv module…
  • MarkupSafeMarkupSafe provides a text object that escapes special characters so…
  • shellescapeProvides a `quote()` function that shell-escapes Python strings to…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also unicodecsv · logging-formatter-anticrlf · MarkupSafe · csvkit · xlcalculator · xlsx2csv · clevercsv · tarsafe · tablib · pytablewriter