Flask-WTF
Form rendering, validation, and CSRF protection for Flask with WTForms.
Decision gist · record as of 2026-08-14
Yes. Flask-WTF is production-stable, actively maintained, has low install friction, carries no known vulnerabilities, and is the standard form-handling solution for Flask applications. Install it if you are building forms in Flask.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later and a Flask application context to function.
- Low friction install with three straightforward runtime dependencies.
- Active maintenance with a recent release (113 days ago) and ongoing repository activity.
License · maintenance · safety
permissive license (permissive) — BSD license permits commercial and private use with minimal restrictions—retain the license notice and disclaimer in distributions.
last release 2026-04-23 (113 days) · last repo commit 2026-08-01 · 1,508 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 20,213,009 downloads/mo, #1,043 on PyPI
Alternatives
Verify before relying
pip install Flask-WTF
from flask import Flask
from flask_wtf import FlaskForm
from wtforms import StringField
from wtforms.validators import DataRequired
app = Flask(__name__)
app.config['SECRET_KEY'] = 'your-secret-key'
class MyForm(FlaskForm):
name = StringField('Name', validators=[DataRequired()])
@app.route('/', methods=['GET', 'POST'])
def index():
form = MyForm()
if form.validate_on_submit():
return f"Hello {form.name.data}"
return form.render()- Whether reCAPTCHA integration requires additional API keys or configuration beyond what Flask-WTF provides.
- File upload size limits and supported storage backends for uploaded files.
What it is and what it does
Flask-WTF is a Flask extension that bridges Flask and WTForms to simplify form handling in web applications. It provides built-in CSRF protection, form rendering, validation, and support for file uploads and reCAPTCHA integration. The package wraps WTForms functionality with Flask-specific conveniences, letting developers define form classes declaratively and validate user input with minimal boilerplate.
It depends on Flask, WTForms, and itsdangerous (for secure token handling). The package is production-stable, actively maintained, and widely used across Flask projects. It requires Python 3.10 or later and is designed to work seamlessly within Flask's application context and request lifecycle.
Use it for
- Build login and registration forms with built-in CSRF tokens and field validation.
- Handle file uploads in forms with automatic validation and security checks.
- Protect web forms against cross-site request forgery attacks automatically.
- Integrate reCAPTCHA into forms to prevent automated abuse.
- Render and validate multi-field forms with custom validators and error messages.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Flask-WTF is production-stable, actively maintained, has low install friction, carries no known vulnerabilities, and is the standard form-handling solution for Flask applications. Install it if you are building forms in Flask.
Install
flask-wtf on PyPI
Before you install
Low friction install with three straightforward runtime dependencies. Active maintenance with a recent release (113 days ago) and ongoing repository activity.
Requires Python 3.10 or later and a Flask application context to function.
License in practice
BSD license permits commercial and private use with minimal restrictions—retain the license notice and disclaimer in distributions.
Quickstart
pip install Flask-WTF
from flask import Flask
from flask_wtf import FlaskForm
from wtforms import StringField
from wtforms.validators import DataRequired
app = Flask(__name__)
app.config['SECRET_KEY'] = 'your-secret-key'
class MyForm(FlaskForm):
name = StringField('Name', validators=[DataRequired()])
@app.route('/', methods=['GET', 'POST'])
def index():
form = MyForm()
if form.validate_on_submit():
return f"Hello {form.name.data}"
return form.render()
Verify before relying
- Whether reCAPTCHA integration requires additional API keys or configuration beyond what Flask-WTF provides.
- File upload size limits and supported storage backends for uploaded files.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesflaskitsdangerouswtforms |
| Maintenance | Actively maintained 113 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 20,213,009 / month, #1,043 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: PythonTopic :: Internet :: WWW/HTTP :: Dynamic ContentTopic :: Internet :: WWW/HTTP :: WSGITopic :: Internet :: WWW/HTTP :: WSGI :: ApplicationTopic :: Software Development :: Libraries :: Application Frameworks |
Evidence: flask_wtf-1.3.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “flask form validation”
- Flask-WTFFlask-WTF integrates WTForms with Flask to handle form rendering,…
- Flask-PydanticAdds Pydantic model validation to Flask route handlers, automatically…
- Bootstrap-FlaskBootstrap-Flask provides Jinja macros that render Flask and WTForms…
Give your agent the search over MCP, or paste the wish link into any chat.
More Application Frameworks packages
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Textual is a Python framework for building cross-platform user interfaces that run in the terminal or web browser using a modern, component-based API.
Install it if you're developing CLI tools, dashboards, or interactive terminal applications.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Build and connect to Model Context Protocol servers that expose tools, resources, and prompts to LLM applications over stdio, HTTP, or SSE transports.
Install it if you need to build or connect to servers.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
See also Flask-Paranoid · WTForms · Flask · WTForms-Components · Bootstrap-Flask · WTForms-JSON · Flask-AutoIndex · flask-mongoengine · django-recaptcha · Flask-Security