$npx skillfedfor your agent

django-axes

Keep track of failed login attempts in Django-powered sites.

Worth itPyPI SecurityReleased Feb 20264.2M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — django_axes-8.3.1-py3-none-any.whl
v8.3.1 · released 2026-02-11 · Python >=3.10 · 2 runtime deps: django, asgiref

Yes. django-axes is a mature, actively maintained security plugin (1699 GitHub stars, top 5000 PyPI packages) with no known vulnerabilities, permissive licensing, and low install friction. It directly addresses a common attack vector (brute-force login) and integrates cleanly into Django's authentication layer. Install it if you operate a Django site with user authentication and want straightforward, configurable login-attempt monitoring and blocking.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Django project setup; django-ipware is optional but recommended for robust IP detection behind proxies.
  • Low install friction with only django and asgiref as runtime dependencies.
  • Actively maintained with recent releases; last commit 2026-08-14 and version 8.3.1 released 2026-02-11.

License · maintenance · safety

MIT (permissive) — MIT license (permissive) allows commercial and private use with minimal restrictions—you may use, modify, and distribute the package freely provided you include the license notice.

last release 2026-02-11 (184 days) · last repo commit 2026-08-14 · 1,699 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 4,246,729 downloads/mo, #2,352 on PyPI

Verify before relying

pip install django-axes

# In Django settings.py, add to INSTALLED_APPS:
# 'axes'

# In urls.py, include axes URLs:
from django.urls import path, include
urlpatterns = [
    path('admin/login/', include('axes.urls')),
]

# Login attempts are now tracked and blocked after configured limit
  • Whether cache-based attempt tracking (mentioned as alternative to database) performs better for high-traffic sites.
  • Specific cooloff period defaults and whether they are configurable per-attempt type.
  • Performance impact of tracking by combination of IP, username, and user agent simultaneously.
Same gist for agents: .md · .json

What it is and what it does

django-axes is a Django plugin that monitors login attempts and implements brute-force attack prevention. It records each failed login attempt and can block further attempts from the same IP address, username, user agent, or combinations thereof once a threshold is exceeded. The package supports both database persistence and cache-based tracking, allowing operators to choose between durability and speed; it also provides cool-off periods, IP allow-listing and block-listing, and user account allow-listing.

The package integrates as middleware and authentication backend into Django's standard login flow. It can be configured to track attempts by various identifiers, mask sensitive parameters in logs for privacy compliance, and respond with HTTP 429 (Too Many Requests) by default when a lockout occurs. It supports async middleware and includes management commands for resetting lockouts.

Use it for

  • Protect a public-facing Django site from credential-stuffing and password-guessing attacks by blocking repeated failed attempts from a single IP.
  • Log and audit login failures for compliance audits (PCI, GDPR) while masking sensitive credentials.
  • Implement per-user lockout policies to prevent account enumeration and targeted attacks on known usernames.
  • Use cache-based tracking for high-traffic sites where database writes would become a bottleneck.
  • Allow-list trusted IPs or user accounts to bypass rate-limiting for internal or administrative access.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

django-axes is a mature, actively maintained security plugin (1699 GitHub stars, top 5000 PyPI packages) with no known vulnerabilities, permissive licensing, and low install friction. It directly addresses a common attack vector (brute-force login) and integrates cleanly into Django's authentication layer. Install it if you operate a Django site with user authentication and want straightforward, configurable login-attempt monitoring and blocking.

Install

django-axes on PyPI

Before you install

Low install friction with only django and asgiref as runtime dependencies. Actively maintained with recent releases; last commit 2026-08-14 and version 8.3.1 released 2026-02-11. Supports current Python versions (3.10–3.14) and recent Django releases (4.2, 5.2, 6.0).

Requires Django project setup; django-ipware is optional but recommended for robust IP detection behind proxies.

License in practice

MIT license (permissive) allows commercial and private use with minimal restrictions—you may use, modify, and distribute the package freely provided you include the license notice.

Quickstart

pip install django-axes

# In Django settings.py, add to INSTALLED_APPS:
# 'axes'

# In urls.py, include axes URLs:
from django.urls import path, include
urlpatterns = [
    path('admin/login/', include('axes.urls')),
]

# Login attempts are now tracked and blocked after configured limit

Verify before relying

  • Whether cache-based attempt tracking (mentioned as alternative to database) performs better for high-traffic sites.
  • Specific cooloff period defaults and whether they are configurable per-attempt type.
  • Performance impact of tracking by combination of IP, username, and user agent simultaneously.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
djangoasgiref
MaintenanceActively maintained 184 days since the last release
Last repo commit
First released
Downloads4,246,729 / month, #2,352 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: PluginsEnvironment :: Web EnvironmentFramework :: DjangoFramework :: Django :: 4.2Framework :: Django :: 5.2Framework :: Django :: 6.0Intended Audience :: DevelopersIntended Audience :: System AdministratorsLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonTopic :: Internet :: Log AnalysisTopic :: SecurityTopic :: System :: Logging

Evidence: django_axes-8.3.1-py3-none-any.whl

Tags

Capabilities
django login attempt trackingbrute force attack blockingdjango authentication securityfailed login monitoringdjango access controlip blocking djangologin rate limiting
Topics
authenticationbrute-force-protectiondjango-plugin
PyPI keywords
authenticationdjangopcisecurity

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “brute force attack blocking”

  • django-axesdjango-axes tracks failed login attempts to Django sites and blocks…
  • bbotBBOT is a multipurpose reconnaissance and vulnerability scanner that…
  • django-defenderBlocks brute-force login attempts in Django by tracking failed…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also django-defender · django-allauth · django-ipware · django-ratelimit · django-pgmigrate · django-allow-cidr · django-logentry-admin · django-dirtyfields · django-invitations · django-ical