dodgy
Dodgy: Searches for dodgy looking lines in Python code
Decision gist · record as of 2026-08-14
No—not for new projects. Dodgy is abandoned and unmaintained since 2021. For active codebases, use a modern alternative like detect-secrets, truffleHog, or a dedicated secrets scanner that receives updates. If you maintain legacy code already using dodgy and it still works on your Python version, keeping it is low-risk, but do not adopt it for new work.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Project is abandoned; compatibility with Python versions beyond 3.8 is untested and unsupported.
- Installation is frictionless with no runtime dependencies.
- However, the project is abandoned—last release was 2019-12-31 and last commit 2021-08-29—so it will not receive bug fixes, security updates, or compatibility patches for modern Python versions.
License · maintenance · safety
MIT (permissive) — MIT license is permissive and poses no restrictions on use, modification, or distribution in commercial or private projects.
last release 2019-12-31 (2418 days) · last repo commit 2021-08-29 · 130 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 672,077 downloads/mo, #5,402 on PyPI
Alternatives
Verify before relying
pip install dodgy==0.2.1
python -m dodgy /path/to/code- Whether the regex patterns remain effective at detecting modern secret formats and obfuscation techniques.
- Compatibility status with Python 3.9 and later versions despite classifiers only listing up to 3.8.
- Whether false-positive rate is acceptable for typical codebases.
What it is and what it does
Dodgy is a lightweight static analysis tool that searches Python codebases for suspicious code patterns using regular expressions. It targets common security oversights like accidental version control markers, hardcoded passwords, and embedded API keys—problems particularly dangerous in open-source projects where secrets become publicly visible. The tool is designed to run as a pre-commit hook to catch these issues before code is checked in.
The package has no runtime dependencies and installs cleanly, but it is no longer maintained. The last release was in late 2019 and the last repository commit in mid-2021. While it still functions on supported Python versions, it will not evolve to handle new secret patterns, modern Python syntax, or compatibility issues with newer language versions.
Use it for
- Run as a pre-commit hook in open-source projects to prevent accidental exposure of API keys or credentials.
- Scan legacy codebases for hardcoded secrets before migrating to a secrets-management system.
- Quick baseline check in CI/CD pipelines for obvious security oversights in Python files.
- Integrate into code review workflows to flag suspicious patterns before merge.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No—not for new projects.
Dodgy is abandoned and unmaintained since 2021. For active codebases, use a modern alternative like detect-secrets, truffleHog, or a dedicated secrets scanner that receives updates. If you maintain legacy code already using dodgy and it still works on your Python version, keeping it is low-risk, but do not adopt it for new work.
Install
dodgy on PyPI
Before you install
Installation is frictionless with no runtime dependencies. However, the project is abandoned—last release was 2019-12-31 and last commit 2021-08-29—so it will not receive bug fixes, security updates, or compatibility patches for modern Python versions.
Project is abandoned; compatibility with Python versions beyond 3.8 is untested and unsupported.
License in practice
MIT license is permissive and poses no restrictions on use, modification, or distribution in commercial or private projects.
Quickstart
pip install dodgy==0.2.1
python -m dodgy /path/to/code
Verify before relying
- Whether the regex patterns remain effective at detecting modern secret formats and obfuscation techniques.
- Compatibility status with Python 3.9 and later versions despite classifiers only listing up to 3.8.
- Whether false-positive rate is acceptable for typical codebases.
Package facts
| License | MIT permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Abandoned 2,418 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 672,077 / month, #5,402 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 7 - InactiveEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: UnixProgramming Language :: Python :: 3.4Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Topic :: Software Development :: Quality Assurance |
Evidence: dodgy-0.2.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “detect hardcoded secrets in code”
- dodgyDodgy scans Python source code for suspicious patterns—accidental…
- detect-secretsDetects secrets (API keys, tokens, credentials) in code repositories…
- bc-detect-secretsDetects secrets (API keys, tokens, credentials) in code repositories…
Give your agent the search over MCP, or paste the wish link into any chat.
More Quality Assurance packages
Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.
Install it if you want to measure test completeness or enforce coverage thresholds in your project.
Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.
Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.
Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.
pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.
Install it if your test suite takes long enough that parallelization would save meaningful time.
Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.
Install it if you work with CloudFormation templates.
See also detect-secrets · flawfinder · bc-detect-secrets · picklescan · vermin · truffleHog · cycode · zizmor · ggshield · pyre-check