$npx skillfedfor your agent

django-xff

Django X-Forwarded-For Properly

With conditionsPyPI WWW/HTTPReleased Feb 202593.7K downloads / moMIT LicensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — django_xff-1.5.0-py2.py3-none-any.whl
v1.5.0 · released 2025-02-13 · 1 runtime deps: Django

Yes, if you run Django behind one or more reverse proxies and need reliable client IP extraction. The middleware is straightforward to configure and has no external dependencies beyond Django. However, maintenance is dormant (last release 547 days ago); verify that it works with your specific Django and Python versions before relying on it in production, and monitor the repository for any security issues or compatibility breaks.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Django must be installed and configured; the middleware must be placed early in MIDDLEWARE_CLASSES to prevent malicious requests from reaching authentication layers.
  • Low friction: pure Python wheel with only Django as a runtime dependency.
  • Dormant maintenance (last release 547 days ago, last commit 2025-02-13) but repository is not archived and supports Django 4.2, 5.0, and 5.1.

License · maintenance · safety

MIT License (permissive) — MIT License (permissive) — you can use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.

last release 2025-02-13 (547 days) · last repo commit 2025-02-13 · 17 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 93,650 downloads/mo, #13,374 on PyPI

Verify before relying

# settings.py
MIDDLEWARE_CLASSES = [
    'xff.middleware.XForwardedForMiddleware',
]
XFF_TRUSTED_PROXY_DEPTH = 2

# request.META['REMOTE_ADDR'] will now contain the real client IP
  • Whether the package works correctly with Django versions beyond 5.1 or with modern Python versions (requires_python is unspecified).
  • Real-world effectiveness of spoofing detection modes (XFF_NO_SPOOFING, XFF_STRICT) against current attack patterns.
  • Whether the 17 GitHub stars and dormant status indicate sufficient community adoption or testing for production use.
Same gist for agents: .md · .json

What it is and what it does

django-xff is middleware that solves a common problem in reverse-proxy deployments: extracting the real client IP address from the X-Forwarded-For header. When requests pass through one or more reverse proxies (load balancers, CDNs, etc.), the original client IP gets buried in a comma-separated list of addresses. A malicious client can prepend fake IPs to this header to spoof their origin, potentially bypassing IP-based security checks or rate limiting.

The middleware works by trusting a fixed depth of proxies—you tell it how many proxies sit between the client and your Django app, and it extracts the IP at the correct position in the chain. It can optionally sanitize the header, validate that the expected number of proxies are present, and reject requests that fail validation. Configuration is entirely through Django settings, with modes ranging from permissive (do nothing if the header is missing) to strict (reject any request that doesn't match the expected proxy depth).

Use it for

  • Running Django behind an AWS Elastic Load Balancer or similar managed proxy where you need accurate client IPs for logging and analytics.
  • Implementing IP-based rate limiting or geographic restrictions when requests arrive through a CDN or reverse proxy.
  • Rejecting spoofed X-Forwarded-For headers in strict security configurations to prevent attackers from bypassing IP-based access controls.
  • Exempting specific URLs (health checks, admin endpoints) from X-Forwarded-For validation while enforcing it elsewhere.
  • Debugging request chains by cleaning up the X-Forwarded-For header to remove extraneous entries added by misconfigured proxies.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you run Django behind one or more reverse proxies and need reliable client IP extraction.

The middleware is straightforward to configure and has no external dependencies beyond Django. However, maintenance is dormant (last release 547 days ago); verify that it works with your specific Django and Python versions before relying on it in production, and monitor the repository for any security issues or compatibility breaks.

Install

django-xff on PyPI

Before you install

Low friction: pure Python wheel with only Django as a runtime dependency. Dormant maintenance (last release 547 days ago, last commit 2025-02-13) but repository is not archived and supports Django 4.2, 5.0, and 5.1.

Django must be installed and configured; the middleware must be placed early in MIDDLEWARE_CLASSES to prevent malicious requests from reaching authentication layers.

License in practice

MIT License (permissive) — you can use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.

Quickstart

# settings.py
MIDDLEWARE_CLASSES = [
    'xff.middleware.XForwardedForMiddleware',
]
XFF_TRUSTED_PROXY_DEPTH = 2

# request.META['REMOTE_ADDR'] will now contain the real client IP

Verify before relying

  • Whether the package works correctly with Django versions beyond 5.1 or with modern Python versions (requires_python is unspecified).
  • Real-world effectiveness of spoofing detection modes (XFF_NO_SPOOFING, XFF_STRICT) against current attack patterns.
  • Whether the 17 GitHub stars and dormant status indicate sufficient community adoption or testing for production use.

Package facts

LicenseMIT License permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
Django
MaintenanceDormant 547 days since the last release
Last repo commit
First released
Downloads93,650 / month, #13,374 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Environment :: Web EnvironmentFramework :: DjangoFramework :: Django :: 4.2Framework :: Django :: 5.0Framework :: Django :: 5.1Intended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: PythonTopic :: Internet :: WWW/HTTPTopic :: Internet :: WWW/HTTP :: Dynamic Content

Evidence: django_xff-1.5.0-py2.py3-none-any.whl

Tags

Capabilities
django x-forwarded-for headerclient ip behind proxyreverse proxy middleware djangoextract real client ipx-forwarded-for sanitizationtrusted proxy depthdjango remote addr rewrite
Topics
reverse-proxysecurity-headersdjango-middleware

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “django x-forwarded-for header”

  • django-xffDjango middleware that extracts the real client IP address from the…
  • django-ipwareRetrieves the client's IP address from a Django request object,…
  • python-ipwareExtracts a client's IP address from web request headers, handling…

Give your agent the search over MCP, or paste the wish link into any chat.

More WWW/HTTP packages

urllib3 Worth it
PyPI · Libraries · released May 2026

urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.

MITpure Python · 3.10+
1.8Bdownloads / mo
requests Worth it
PyPI · Libraries · released May 2026

Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.

Apache-2.0pure Python · 3.10+
1.8Bdownloads / mo
h11 With conditions
PyPI · WWW/HTTP · released Apr 2025

h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.

MITpure Python · 3.8+aging
894.9Mdownloads / mo
httpx Worth it
PyPI · WWW/HTTP · released Dec 2024

HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.

Install it if you are building new projects or modernizing existing ones that rely on HTTP.

BSD-3-Clausepure Python · 3.8+
797.0Mdownloads / mo
httpcore With conditions
PyPI · WWW/HTTP · released Apr 2025

A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.

BSD-3-Clausepure Python · 3.8+aging
783.6Mdownloads / mo
aiohttp Worth it
PyPI · WWW/HTTP · released Jul 2026

aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.

Install it if you need async HTTP client or server capabilities in asyncio-based applications.

permissive licensecompiled wheel · 3.10+
643.6Mdownloads / mo

See also django-ipware · django-revproxy · python-ipware · django-ebhealthcheck · django-allow-cidr · proxy-protocol · vercel-headers · requests-hardened · django-defender · xclienttransaction