$npx skillfedfor your agent

MarkupSafe

Safely add untrusted strings to HTML/XML markup.

Worth itPyPI Dynamic ContentReleased Sep 2025797.1M downloads / moBSD-3-ClausePlatform wheel

Decision gist · record as of 2026-08-14

platform wheels — markupsafe-3.0.3-cp310-cp310-macosx_10_9_x86_64.whl · markupsafe-3.0.3-cp310-cp310-macosx_11_0_arm64.whl · markupsafe-3.0.3-cp310-cp310-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl
v3.0.3 · released 2025-09-27 · Python >=3.9

Yes. MarkupSafe is a foundational security library with zero vulnerabilities, no dependencies, and permissive licensing. It is essential for any web application handling untrusted input. The aging maintenance status (321 days since release) is not a concern for a stable, mature library; the codebase is well-established and the repository remains active.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or later.
  • Medium install friction due to platform-specific wheels, but the package is stable and actively maintained with a recent release (2025-09-27).
  • No runtime dependencies.

License · maintenance · safety

BSD-3-Clause (permissive) — BSD-3-Clause is permissive; you can use this package freely in commercial and open-source projects with minimal restrictions.

last release 2025-09-27 (321 days) · last repo commit 2025-09-27 · 694 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 797,118,023 downloads/mo, #34 on PyPI

Verify before relying

from markupsafe import escape, Markup

# Escape untrusted input
escaped = escape("<script>alert('xss')</script>")

# Mark safe strings to prevent re-escaping
safe_html = Markup("<b>bold</b>")
  • Whether the package is actively maintained beyond the latest release date or if 321 days since release indicates reduced activity.
Same gist for agents: .md · .json

What it is and what it does

MarkupSafe is a foundational security library that prevents HTML and XML injection attacks by escaping untrusted user input. It provides an `escape()` function that converts dangerous characters (like `<`, `>`, `&`, quotes) into their HTML entity equivalents, and a `Markup` class that marks strings as safe to prevent double-escaping. When you use `Markup` in string operations like formatting or concatenation, it automatically escapes any untrusted arguments inserted into it.

The package is widely used in web frameworks and templating engines to safely render user-supplied content. It has no external dependencies and supports current Python versions (3.9+). With 694 repository stars and a production-stable status, it is a mature, battle-tested tool for anyone building web applications or processing markup.

Use it for

  • Render user comments or forum posts safely in HTML without XSS vulnerabilities.
  • Build templating systems that auto-escape dynamic content while preserving intentional markup.
  • Sanitize API responses or database content before displaying in web pages.
  • Prevent injection attacks when constructing HTML emails or reports from untrusted data.
  • Safely embed user-generated strings in XML documents or configuration files.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

MarkupSafe is a foundational security library with zero vulnerabilities, no dependencies, and permissive licensing. It is essential for any web application handling untrusted input. The aging maintenance status (321 days since release) is not a concern for a stable, mature library; the codebase is well-established and the repository remains active.

Install

markupsafe on PyPI

Before you install

Medium install friction due to platform-specific wheels, but the package is stable and actively maintained with a recent release (2025-09-27). No runtime dependencies.

Requires Python 3.9 or later.

License in practice

BSD-3-Clause is permissive; you can use this package freely in commercial and open-source projects with minimal restrictions.

Quickstart

from markupsafe import escape, Markup

# Escape untrusted input
escaped = escape("<script>alert('xss')</script>")

# Mark safe strings to prevent re-escaping
safe_html = Markup("<b>bold</b>")

Verify before relying

  • Whether the package is actively maintained beyond the latest release date or if 321 days since release indicates reduced activity.

Package facts

LicenseBSD-3-Clause permissive
Python supportSupports the current Python release >=3.9
Install frictionMedium. Platform-specific wheel
Runtime dependenciesNone
MaintenanceAging 321 days since the last release
Last repo commit
First released
Downloads797,118,023 / month, #34 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentIntended Audience :: DevelopersOperating System :: OS IndependentProgramming Language :: PythonTopic :: Internet :: WWW/HTTP :: Dynamic ContentTopic :: Text Processing :: Markup :: HTMLTyping :: Typed

Evidence: markupsafe-3.0.3-cp310-cp310-macosx_10_9_x86_64.whl; markupsafe-3.0.3-cp310-cp310-macosx_11_0_arm64.whl; markupsafe-3.0.3-cp310-cp310-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl; markupsafe-3.0.3-cp310-cp310-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl; markupsafe-3.0.3-cp310-cp310-manylinux_2_31_riscv64.manylinux_2_39_riscv64.whl; markupsafe-3.0.3-cp310-cp310-musllinux_1_2_aarch64.whl; markupsafe-3.0.3-cp310-cp310-musllinux_1_2_riscv64.whl; markupsafe-3.0.3-cp310-cp310-musllinux_1_2_x86_64.whl; markupsafe-3.0.3-cp310-cp310-win32.whl; markupsafe-3.0.3-cp310-cp310-win_amd64.whl; markupsafe-3.0.3-cp310-cp310-win_arm64.whl; markupsafe-3.0.3-cp311-cp311-macosx_10_9_x86_64.whl; markupsafe-3.0.3-cp311-cp311-macosx_11_0_arm64.whl; markupsafe-3.0.3-cp311-cp311-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl; markupsafe-3.0.3-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl; markupsafe-3.0.3-cp311-cp311-manylinux_2_31_riscv64.manylinux_2_39_riscv64.whl; markupsafe-3.0.3-cp311-cp311-musllinux_1_2_aarch64.whl; markupsafe-3.0.3-cp311-cp311-musllinux_1_2_riscv64.whl; markupsafe-3.0.3-cp311-cp311-musllinux_1_2_x86_64.whl; markupsafe-3.0.3-cp311-cp311-win32.whl

Tags

Capabilities
html escapingxss preventionmarkup sanitizationsafe html renderinguntrusted string escapinginjection attack mitigationxml safe text
Topics
securityhtml-escapingweb-framework

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “html escaping”

  • MarkupSafeMarkupSafe provides a text object that escapes special characters so…
  • tinyhtmlRenders HTML5 safely from Python expressions using a functional API…
  • bleachBleach sanitizes untrusted HTML by escaping or stripping markup and…

Give your agent the search over MCP, or paste the wish link into any chat.

More Dynamic Content packages

Jinja2 Worth it
PyPI · Dynamic Content · released Mar 2025

Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.

BSD-3-Clausepure Python · 3.7+aging
718.6Mdownloads / mo
soupsieve Worth it
PyPI · Python Modules · released Aug 2026

Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.

Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.

MITpure Python · 3.10+
428.6Mdownloads / mo
Werkzeug Worth it
PyPI · Application Frameworks · released Apr 2026

Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.

BSD-3-Clausepure Python · 3.9+
268.1Mdownloads / mo
Flask Worth it
PyPI · Application Frameworks · released Feb 2026

Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.

BSD-3-Clausepure Python · 3.9+
211.4Mdownloads / mo
Mako Worth it
PyPI · Dynamic Content · released Aug 2026

Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.

MITpure Python · 3.10+
201.7Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo

See also bleach · itsdangerous · escapism · textile · shellescape · defusedcsv · logging-formatter-anticrlf · MarkupPy · nestedtext · html-sanitizer

Further reading