django-bleach
Easily use bleach with Django models and templates
Decision gist · record as of 2026-08-14
No. The repository is archived and abandoned with no maintenance since 2023-08-05. While the code is stable and currently compatible with Django 3.2–4.2, there is no path forward for security patches, Django 5.0+ support, or bleach library updates. For new projects, use an actively maintained alternative or apply bleach directly in your views. For existing projects still on supported Django versions, it remains functional but carries increasing technical debt.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low install friction with a pure-Python wheel.
- However, the repository is archived and abandoned as of 1105 days since last release, with the latest version from 2023-08-05.
- No active maintenance means security updates are unlikely.
License · maintenance · safety
MIT (permissive) — MIT license is permissive and imposes no restrictions on use, modification, or distribution in commercial or private projects.
last release 2023-08-05 (1105 days) · last repo commit 2024-11-05 · 149 stars · archived
0 known vulnerabilities (OSV.dev, 2026-08-14) · 105,784 downloads/mo, #12,679 on PyPI
Alternatives
Verify before relying
pip install django-bleach
# In settings.py
INSTALLED_APPS = ['django_bleach']
BLEACH_ALLOWED_TAGS = ['p', 'b', 'i', 'u', 'em', 'strong', 'a']
# In models.py
from django_bleach.models import BleachField
class Post(models.Model):
content = BleachField()- Whether bleach itself receives active security updates and how that affects django-bleach's viability
- Compatibility with Django versions beyond 4.2 given the abandoned status
- Real-world performance impact of sanitization on high-volume user input
What it is and what it does
django-bleach wraps bleach to make HTML sanitization a first-class feature in Django applications. It provides a BleachField model field that automatically sanitizes HTML before saving to the database, a corresponding form field for user input, and template filters for rendering untrusted content safely. The package lets you define allowed HTML tags, attributes, and CSS styles through Django settings, then applies those rules consistently across your application.
The core problem it solves is preventing XSS attacks and malformed HTML when accepting user-generated content. Instead of storing raw HTML or stripping all markup, django-bleach preserves semantic tags while removing script tags, event handlers, and other dangerous constructs. It integrates directly into Django's ORM and form layer, so sanitization happens automatically without extra middleware or view-level logic.
Use it for
- Blog or CMS platforms where users write posts with basic formatting but you need to prevent script injection
- Comment systems that allow limited HTML markup while blocking malicious content
- User profile descriptions or bio fields that should support simple rich text
- Converting URL-like strings to links in user-submitted text using the bleach_linkify filter
- Rendering third-party or legacy HTML content in templates without exposing your application to embedded attacks
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
The repository is archived and abandoned with no maintenance since 2023-08-05. While the code is stable and currently compatible with Django 3.2–4.2, there is no path forward for security patches, Django 5.0+ support, or bleach library updates. For new projects, use an actively maintained alternative or apply bleach directly in your views. For existing projects still on supported Django versions, it remains functional but carries increasing technical debt.
Install
django-bleach on PyPI
Before you install
Low install friction with a pure-Python wheel. However, the repository is archived and abandoned as of 1105 days since last release, with the latest version from 2023-08-05. No active maintenance means security updates are unlikely.
License in practice
MIT license is permissive and imposes no restrictions on use, modification, or distribution in commercial or private projects.
Quickstart
pip install django-bleach
# In settings.py
INSTALLED_APPS = ['django_bleach']
BLEACH_ALLOWED_TAGS = ['p', 'b', 'i', 'u', 'em', 'strong', 'a']
# In models.py
from django_bleach.models import BleachField
class Post(models.Model):
content = BleachField()
Verify before relying
- Whether bleach itself receives active security updates and how that affects django-bleach's viability
- Compatibility with Django versions beyond 4.2 given the abandoned status
- Real-world performance impact of sanitization on high-volume user input
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesbleachDjango |
| Maintenance | Abandoned 1,105 days since the last release |
| Last repo commit | repository archived |
| First released | |
| Downloads | 105,784 / month, #12,679 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentFramework :: Django :: 3.2Framework :: Django :: 4.0Framework :: Django :: 4.1Framework :: Django :: 4.2Intended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: django_bleach-3.1.0-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “django html sanitization”
- django-bleachIntegrates bleach HTML sanitization into Django models, forms, and…
- django-post_officeDjango Post Office queues and sends emails asynchronously with…
- lxml-html-cleanCleans and sanitizes HTML by removing unwanted tags and attributes…
Give your agent the search over MCP, or paste the wish link into any chat.
More Dynamic Content packages
MarkupSafe provides a text object that escapes special characters so untrusted strings can be safely embedded in HTML and XML without injection attacks.
Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.
Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.
Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.
Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.
See also bleach · html-sanitizer · lxml-html-clean · django-markdownify · bleach-allowlist · nh3 · django-ckeditor · types-bleach · django-bootstrap3 · django-template-partials