$npx skillfedfor your agent

django-impersonate

Django app to allow superusers to impersonate other users.

With conditionsPyPI Dynamic ContentReleased Apr 2025268.8K downloads / moBSD LicenseSource build

Decision gist · record as of 2026-08-14

sdist only — django_impersonate-1.9.5.tar.gz · builds from source
v1.9.5 · released 2025-04-05

Yes, with conditions. The package is stable, permissively licensed, and widely used. However, install friction is high (source distribution only), and maintenance is aging (496 days since last release). Install it if you need user impersonation in a Django admin context and can accept slower update cycles; avoid it if you require frequent security patches or active upstream support.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Django's session framework (django.contrib.sessions) to be enabled.
  • ImpersonateMiddleware must be placed after django.contrib.auth middleware.
  • High install friction due to source distribution only.

License · maintenance · safety

BSD License (permissive) — BSD License (permissive). You may use, modify, and distribute this package freely in commercial and private projects, with minimal restrictions.

last release 2025-04-05 (496 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 268,816 downloads/mo, #8,267 on PyPI

Verify before relying

pip install django-impersonate

# In settings.py:
INSTALLED_APPS = [
    ...
    'impersonate',
]

MIDDLEWARE = [
    ...
    'impersonate.middleware.ImpersonateMiddleware',
]

# In urls.py:
urlpatterns = [
    path('impersonate/', include('impersonate.urls')),
]

# Then visit /impersonate/<user-id>/ to start impersonation
  • Whether the XSS vulnerability mentioned for versions 1.9.3 and below has been fully resolved in 1.9.5
  • Current maintenance status and whether the 496-day gap since last release indicates active or dormant development
Same gist for agents: .md · .json

What it is and what it does

django-impersonate is a Django application that enables superusers to temporarily log in as other non-superuser accounts without needing their passwords. This is useful for debugging user-specific issues, testing permission systems, and providing support. The package injects an `is_impersonate` flag and an `impersonator` reference into the request object so your code can detect and audit when impersonation is active. It provides URL endpoints to start impersonation, stop it, list available users, and search for users to impersonate.

The package has no runtime dependencies beyond Django itself and relies on Django's built-in session framework. It includes middleware that integrates with Django's authentication system and provides signals you can hook into for audit logging. Configuration is optional—you can restrict which users can impersonate others and which users can be impersonated by defining custom allow/queryset functions.

Use it for

  • Debug a specific user's issue by impersonating their account and reproducing the problem in their context
  • Test permission and access control logic by switching to accounts with different roles
  • Provide customer support by temporarily viewing the application as a customer sees it
  • Audit user actions by logging impersonation sessions via the provided signals
  • Verify that certain features are correctly restricted to specific user types

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, with conditions.

The package is stable, permissively licensed, and widely used. However, install friction is high (source distribution only), and maintenance is aging (496 days since last release). Install it if you need user impersonation in a Django admin context and can accept slower update cycles; avoid it if you require frequent security patches or active upstream support.

Install

django-impersonate on PyPI

Before you install

High install friction due to source distribution only. Maintenance status is aging—last release was 496 days ago. The package is stable and widely used (top 15000 on PyPI), but slow update cadence may indicate limited active development.

Requires Django's session framework (django.contrib.sessions) to be enabled. ImpersonateMiddleware must be placed after django.contrib.auth middleware.

License in practice

BSD License (permissive). You may use, modify, and distribute this package freely in commercial and private projects, with minimal restrictions.

Quickstart

pip install django-impersonate

# In settings.py:
INSTALLED_APPS = [
    ...
    'impersonate',
]

MIDDLEWARE = [
    ...
    'impersonate.middleware.ImpersonateMiddleware',
]

# In urls.py:
urlpatterns = [
    path('impersonate/', include('impersonate.urls')),
]

# Then visit /impersonate/<user-id>/ to start impersonation

Verify before relying

  • Whether the XSS vulnerability mentioned for versions 1.9.3 and below has been fully resolved in 1.9.5
  • Current maintenance status and whether the 496-day gap since last release indicates active or dormant development

Package facts

LicenseBSD License permissive
Python supportNot specified
Install frictionHigh. Source build required
Runtime dependenciesNone
MaintenanceAging 496 days since the last release
First released
Downloads268,816 / month, #8,267 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentFramework :: DjangoFramework :: Django :: 3.2Framework :: Django :: 4.0Framework :: Django :: 4.1Framework :: Django :: 4.2Framework :: Django :: 5.0Intended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9

Evidence: django_impersonate-1.9.5.tar.gz

Tags

Capabilities
django user impersonationsuperuser testing other accountsdjango session hijacking adminuser identity switching djangoadmin user debuggingdjango support user testing
Topics
django-admintesting-supportsession-management

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “superuser testing other accounts”

Give your agent the search over MCP, or paste the wish link into any chat.

More Dynamic Content packages

MarkupSafe Worth it
PyPI · Dynamic Content · released Sep 2025

MarkupSafe provides a text object that escapes special characters so untrusted strings can be safely embedded in HTML and XML without injection attacks.

BSD-3-Clausecompiled wheel · 3.9+aging
797.1Mdownloads / mo
Jinja2 Worth it
PyPI · Dynamic Content · released Mar 2025

Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.

BSD-3-Clausepure Python · 3.7+aging
718.6Mdownloads / mo
soupsieve Worth it
PyPI · Python Modules · released Aug 2026

Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.

Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.

MITpure Python · 3.10+
428.6Mdownloads / mo
Werkzeug Worth it
PyPI · Application Frameworks · released Apr 2026

Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.

BSD-3-Clausepure Python · 3.9+
268.1Mdownloads / mo
Flask Worth it
PyPI · Application Frameworks · released Feb 2026

Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.

BSD-3-Clausepure Python · 3.9+
211.4Mdownloads / mo
Mako Worth it
PyPI · Dynamic Content · released Aug 2026

Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.

MITpure Python · 3.10+
201.7Mdownloads / mo

See also django-hijack · django-loginas · primp · scrapy-impersonate · django-magiclink · django-crum · django-logentry-admin · django-auth-adfs · django-permissionedforms · django-maintenance-mode