django-quill-editor
Integrate Quill editor with Django project.
Decision gist · record as of 2026-08-14
Yes, if you need a Quill editor in Django admin or internal forms and your users are all trusted. The setup is genuinely simple and the install friction is minimal. No if your application accepts user-generated content from the public, because the XSS warning in the documentation is explicit and unresolved—you would need to sanitize output separately, which defeats the convenience of the package.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python >3.8 and Django 3.1 or higher; the package's own documentation warns that content is marked_safe and can be exploited for XSS attacks—only authorized administrators should use it in important projects.
- Low install friction—a single pure-Python dependency on django.
- Maintenance is dormant: last release was 2024-09-20 and last commit 2025-01-14, so the package is not actively developed but remains functional on current Python and Django versions.
License · maintenance · safety
MIT (permissive) — MIT license is permissive and imposes no significant restrictions on use or redistribution.
last release 2024-09-20 (693 days) · last repo commit 2025-01-14 · 224 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 74,929 downloads/mo, #14,767 on PyPI
Alternatives
Verify before relying
pip install django-quill-editor
# In settings.py
INSTALLED_APPS = [
'django_quill',
]
# In models.py
from django_quill.fields import QuillField
class MyModel(models.Model):
content = QuillField()- Whether the package's XSS warning applies only when user input is untrusted or in all contexts where content is displayed.
- Current compatibility with Django versions beyond 4.2 (the latest classifier listed).
What it is and what it does
django-quill-editor wraps Quill.js, a popular JavaScript rich-text editor, as a Django form field and admin widget. It handles static file inclusion automatically and requires no configuration beyond adding the app to INSTALLED_APPS and using QuillField in your model. The editor works in both regular Django forms and ModelForms, and integrates seamlessly into the Django admin interface.
The package is straightforward to set up: add QuillField to a model, register it in admin, and the editor appears. However, the documentation includes a critical security warning: content stored by django-quill-editor is marked as safe HTML by Django and will not be escaped when rendered, creating an XSS vulnerability if untrusted users can edit the content. This makes it suitable only for internal or admin-only use cases where all editors are trusted.
Use it for
- Add a rich-text editor to Django admin for trusted staff to compose formatted content without writing HTML.
- Build internal content management tools where only authorized users edit formatted text fields.
- Create a simple blog or documentation platform with a WYSIWYG editor in ModelForms for authenticated users.
- Replace plain textarea fields in Django forms with a visual editor for better user experience in admin-only applications.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need a Quill editor in Django admin or internal forms and your users are all trusted.
The setup is genuinely simple and the install friction is minimal. No if your application accepts user-generated content from the public, because the XSS warning in the documentation is explicit and unresolved—you would need to sanitize output separately, which defeats the convenience of the package.
Install
django-quill-editor on PyPI
Before you install
Low install friction—a single pure-Python dependency on django. Maintenance is dormant: last release was 2024-09-20 and last commit 2025-01-14, so the package is not actively developed but remains functional on current Python and Django versions.
Requires Python >3.8 and Django 3.1 or higher; the package's own documentation warns that content is marked_safe and can be exploited for XSS attacks—only authorized administrators should use it in important projects.
License in practice
MIT license is permissive and imposes no significant restrictions on use or redistribution.
Quickstart
pip install django-quill-editor
# In settings.py
INSTALLED_APPS = [
'django_quill',
]
# In models.py
from django_quill.fields import QuillField
class MyModel(models.Model):
content = QuillField()
Verify before relying
- Whether the package's XSS warning applies only when user input is untrusted or in all contexts where content is displayed.
- Current compatibility with Django versions beyond 4.2 (the latest classifier listed).
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagedjango |
| Maintenance | Dormant 693 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 74,929 / month, #14,767 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaFramework :: DjangoFramework :: Django :: 4.2Programming Language :: PythonProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: django_quill_editor-0.1.42-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “django wysiwyg editor”
- django-quill-editorIntegrates Quill.js, a rich-text WYSIWYG editor, into Django forms…
- django-tinymcedjango-tinymce provides a Django form widget and model field that…
- django-summernoteEmbeds the Summernote WYSIWYG editor into Django admin and forms,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Dynamic Content packages
MarkupSafe provides a text object that escapes special characters so untrusted strings can be safely embedded in HTML and XML without injection attacks.
Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.
Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.
Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.
Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.
See also django-tinymce · quill-delta · streamlit-quill · django-ckeditor · django-json-widget · django-jsonform · django-summernote · django-ace · django-markdownx · draftjs_exporter