MarkupSafe
Safely add untrusted strings to HTML/XML markup.
Decision gist · record as of 2026-08-14
Yes. MarkupSafe is a foundational security library with zero vulnerabilities, no dependencies, and permissive licensing. It is essential for any web application handling untrusted input. The aging maintenance status (321 days since release) is not a concern for a stable, mature library; the codebase is well-established and the repository remains active.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later.
- Medium install friction due to platform-specific wheels, but the package is stable and actively maintained with a recent release (2025-09-27).
- No runtime dependencies.
License · maintenance · safety
BSD-3-Clause (permissive) — BSD-3-Clause is permissive; you can use this package freely in commercial and open-source projects with minimal restrictions.
last release 2025-09-27 (321 days) · last repo commit 2025-09-27 · 694 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 797,118,023 downloads/mo, #34 on PyPI
Alternatives
Verify before relying
from markupsafe import escape, Markup
# Escape untrusted input
escaped = escape("<script>alert('xss')</script>")
# Mark safe strings to prevent re-escaping
safe_html = Markup("<b>bold</b>")- Whether the package is actively maintained beyond the latest release date or if 321 days since release indicates reduced activity.
What it is and what it does
MarkupSafe is a foundational security library that prevents HTML and XML injection attacks by escaping untrusted user input. It provides an `escape()` function that converts dangerous characters (like `<`, `>`, `&`, quotes) into their HTML entity equivalents, and a `Markup` class that marks strings as safe to prevent double-escaping. When you use `Markup` in string operations like formatting or concatenation, it automatically escapes any untrusted arguments inserted into it.
The package is widely used in web frameworks and templating engines to safely render user-supplied content. It has no external dependencies and supports current Python versions (3.9+). With 694 repository stars and a production-stable status, it is a mature, battle-tested tool for anyone building web applications or processing markup.
Use it for
- Render user comments or forum posts safely in HTML without XSS vulnerabilities.
- Build templating systems that auto-escape dynamic content while preserving intentional markup.
- Sanitize API responses or database content before displaying in web pages.
- Prevent injection attacks when constructing HTML emails or reports from untrusted data.
- Safely embed user-generated strings in XML documents or configuration files.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
MarkupSafe is a foundational security library with zero vulnerabilities, no dependencies, and permissive licensing. It is essential for any web application handling untrusted input. The aging maintenance status (321 days since release) is not a concern for a stable, mature library; the codebase is well-established and the repository remains active.
Install
markupsafe on PyPI
Before you install
Medium install friction due to platform-specific wheels, but the package is stable and actively maintained with a recent release (2025-09-27). No runtime dependencies.
Requires Python 3.9 or later.
License in practice
BSD-3-Clause is permissive; you can use this package freely in commercial and open-source projects with minimal restrictions.
Quickstart
from markupsafe import escape, Markup
# Escape untrusted input
escaped = escape("<script>alert('xss')</script>")
# Mark safe strings to prevent re-escaping
safe_html = Markup("<b>bold</b>")
Verify before relying
- Whether the package is actively maintained beyond the latest release date or if 321 days since release indicates reduced activity.
Package facts
| License | BSD-3-Clause permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | None |
| Maintenance | Aging 321 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 797,118,023 / month, #34 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentIntended Audience :: DevelopersOperating System :: OS IndependentProgramming Language :: PythonTopic :: Internet :: WWW/HTTP :: Dynamic ContentTopic :: Text Processing :: Markup :: HTMLTyping :: Typed |
Evidence: markupsafe-3.0.3-cp310-cp310-macosx_10_9_x86_64.whl; markupsafe-3.0.3-cp310-cp310-macosx_11_0_arm64.whl; markupsafe-3.0.3-cp310-cp310-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl; markupsafe-3.0.3-cp310-cp310-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl; markupsafe-3.0.3-cp310-cp310-manylinux_2_31_riscv64.manylinux_2_39_riscv64.whl; markupsafe-3.0.3-cp310-cp310-musllinux_1_2_aarch64.whl; markupsafe-3.0.3-cp310-cp310-musllinux_1_2_riscv64.whl; markupsafe-3.0.3-cp310-cp310-musllinux_1_2_x86_64.whl; markupsafe-3.0.3-cp310-cp310-win32.whl; markupsafe-3.0.3-cp310-cp310-win_amd64.whl; markupsafe-3.0.3-cp310-cp310-win_arm64.whl; markupsafe-3.0.3-cp311-cp311-macosx_10_9_x86_64.whl; markupsafe-3.0.3-cp311-cp311-macosx_11_0_arm64.whl; markupsafe-3.0.3-cp311-cp311-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl; markupsafe-3.0.3-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl; markupsafe-3.0.3-cp311-cp311-manylinux_2_31_riscv64.manylinux_2_39_riscv64.whl; markupsafe-3.0.3-cp311-cp311-musllinux_1_2_aarch64.whl; markupsafe-3.0.3-cp311-cp311-musllinux_1_2_riscv64.whl; markupsafe-3.0.3-cp311-cp311-musllinux_1_2_x86_64.whl; markupsafe-3.0.3-cp311-cp311-win32.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “html escaping”
- MarkupSafeMarkupSafe provides a text object that escapes special characters so…
- tinyhtmlRenders HTML5 safely from Python expressions using a functional API…
- bleachBleach sanitizes untrusted HTML by escaping or stripping markup and…
Give your agent the search over MCP, or paste the wish link into any chat.
More Dynamic Content packages
Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.
Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.
Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.
Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
See also bleach · itsdangerous · escapism · textile · shellescape · defusedcsv · logging-formatter-anticrlf · MarkupPy · nestedtext · html-sanitizer