django-csp
Django Content Security Policy support.
Decision gist · record as of 2026-08-14
Yes. Django-CSP is a stable, low-friction way to add a critical security layer to Django applications. It has no known vulnerabilities, permissive licensing, and broad Django version support. The aging maintenance status is not a blocker—the package is mature and the 499-day release gap may reflect stability rather than abandonment. Install it if you need CSP header management in Django.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low install friction with only two runtime dependencies (django and packaging).
- Maintenance status is aging—last commit was 2025-11-14 and no release in 499 days—but the package is marked Production/Stable and remains actively used.
License · maintenance · safety
BSD (permissive) — BSD license is permissive, allowing commercial and private use with minimal restrictions; you may use and modify the package freely as long as you include the license notice.
last release 2025-04-02 (499 days) · last repo commit 2025-11-14 · 626 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 3,988,500 downloads/mo, #2,408 on PyPI
Alternatives
Verify before relying
pip install django-csp
# In Django settings.py, add to MIDDLEWARE:
MIDDLEWARE = [
'csp.middleware.CSPMiddleware',
]
# Define CSP policy:
CSP_DEFAULT_SRC = ("'self'",)
CSP_SCRIPT_SRC = ("'self'", "'unsafe-inline'")- Whether the 499-day gap since last release indicates maintenance concerns or stable maturity for this use case.
- Compatibility with Django versions beyond 5.2 and Python versions beyond 3.13.
What it is and what it does
Django-CSP is a middleware package that automatically injects Content-Security-Policy headers into Django HTTP responses. It lets you define a security policy that tells browsers which origins are allowed to load scripts, stylesheets, images, and other resources, helping prevent cross-site scripting (XSS) and other injection attacks. The package wraps around Django and works with the packaging library to manage policy directives.
You configure policies in Django settings and the middleware applies them to all responses. It supports both report-only mode (for testing policies without enforcing them) and enforcement mode, and integrates cleanly into the Django request/response cycle without requiring changes to your views or templates.
Use it for
- Prevent XSS attacks by restricting script execution to trusted origins only.
- Enforce HTTPS for all resources to block mixed-content vulnerabilities.
- Report policy violations to a logging endpoint for security monitoring.
- Gradually roll out stricter policies using report-only mode before enforcement.
- Isolate third-party widget code by restricting its access to the page DOM.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Django-CSP is a stable, low-friction way to add a critical security layer to Django applications. It has no known vulnerabilities, permissive licensing, and broad Django version support. The aging maintenance status is not a blocker—the package is mature and the 499-day release gap may reflect stability rather than abandonment. Install it if you need CSP header management in Django.
Install
django-csp on PyPI
Before you install
Low install friction with only two runtime dependencies (django and packaging). Maintenance status is aging—last commit was 2025-11-14 and no release in 499 days—but the package is marked Production/Stable and remains actively used.
License in practice
BSD license is permissive, allowing commercial and private use with minimal restrictions; you may use and modify the package freely as long as you include the license notice.
Quickstart
pip install django-csp
# In Django settings.py, add to MIDDLEWARE:
MIDDLEWARE = [
'csp.middleware.CSPMiddleware',
]
# Define CSP policy:
CSP_DEFAULT_SRC = ("'self'",)
CSP_SCRIPT_SRC = ("'self'", "'unsafe-inline'")
Verify before relying
- Whether the 499-day gap since last release indicates maintenance concerns or stable maturity for this use case.
- Compatibility with Django versions beyond 5.2 and Python versions beyond 3.13.
Package facts
| License | BSD permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesdjangopackaging |
| Maintenance | Aging 499 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 3,988,500 / month, #2,408 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentEnvironment :: Web Environment :: MozillaFramework :: Django :: 4.2Framework :: Django :: 5.0Framework :: Django :: 5.1Framework :: Django :: 5.2Intended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Software Development :: Libraries :: Python Modules |
Evidence: django_csp-4.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “django content security policy”
- django-cspDjango-CSP adds Content-Security-Policy headers to Django…
- django-permissions-policySets the Permissions-Policy HTTP header on Django responses to…
- django-sriGenerates Subresource Integrity (SRI) hashes for Django static files…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also django-permissions-policy · secure · Secweb · flask-talisman · django-otp-webauthn · django-cors-headers · django-hosts · django-browser-reload · django-js-asset · zope.security