$npx skillfedfor your agent

passlib

comprehensive password hashing framework supporting over 30 schemes

With conditionsPyPI CryptographyReleased Oct 202039.7M downloads / moBSDPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — passlib-1.7.4-py2.py3-none-any.whl
v1.7.4 · released 2020-10-08

Yes, but with significant caveats. Passlib is widely used and has no known vulnerabilities, but it has been abandoned since October 2020. Install it only if you are maintaining legacy code that already depends on it, or if you have thoroughly verified that its algorithms meet your security requirements and you can patch it yourself if needed. For new projects, consider actively maintained alternatives.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Passlib is abandoned; verify algorithm compatibility with your target Python version and security requirements before use in new projects.
  • Installation is frictionless—a pure-Python wheel with no runtime dependencies.
  • However, the package has been abandoned since October 2020, which means no security patches, bug fixes, or compatibility updates are forthcoming.

License · maintenance · safety

BSD (permissive) — Passlib is licensed under BSD (permissive), so you can use, modify, and distribute it freely in commercial and open-source projects with minimal restrictions.

last release 2020-10-08 (2136 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 39,687,098 downloads/mo, #690 on PyPI

Verify before relying

pip install passlib

from passlib.context import CryptContext

ctx = CryptContext(schemes=['bcrypt'], deprecated='auto')
hashed = ctx.hash('mypassword')
ctx.verify('mypassword', hashed)
  • Whether passlib's algorithms remain cryptographically sound against current attack standards
  • Compatibility with Python versions released after October 2020
  • Whether any of the supported algorithms have been deprecated by the cryptographic community
Same gist for agents: .md · .json

What it is and what it does

Passlib is a password hashing library that abstracts away the complexity of choosing and implementing secure password schemes. It provides implementations of password hashing algorithms and a unified interface for hashing new passwords and verifying existing ones. The library is designed to handle both simple use cases (verifying hashes from system files like /etc/shadow) and complex scenarios (managing passwords across multi-user applications with algorithm migration).

The package has no runtime dependencies and installs as a pure-Python wheel, making it lightweight and portable. However, it has been abandoned since October 2020, meaning it receives no security updates, bug fixes, or maintenance. For new projects, you should carefully evaluate whether its algorithms meet current cryptographic standards and whether you need active maintenance and support.

Use it for

  • Verify password hashes stored in legacy system files or databases when migrating authentication systems.
  • Hash and verify user passwords in a web application or API using a single, algorithm-agnostic interface.
  • Support multiple password hashing schemes simultaneously to allow gradual migration from older to newer algorithms.
  • Authenticate against existing password stores without reimplementing individual hashing algorithms.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, but with significant caveats.

Passlib is widely used and has no known vulnerabilities, but it has been abandoned since October 2020. Install it only if you are maintaining legacy code that already depends on it, or if you have thoroughly verified that its algorithms meet your security requirements and you can patch it yourself if needed. For new projects, consider actively maintained alternatives.

Install

passlib on PyPI

Before you install

Installation is frictionless—a pure-Python wheel with no runtime dependencies. However, the package has been abandoned since October 2020, which means no security patches, bug fixes, or compatibility updates are forthcoming.

Passlib is abandoned; verify algorithm compatibility with your target Python version and security requirements before use in new projects.

License in practice

Passlib is licensed under BSD (permissive), so you can use, modify, and distribute it freely in commercial and open-source projects with minimal restrictions.

Quickstart

pip install passlib

from passlib.context import CryptContext

ctx = CryptContext(schemes=['bcrypt'], deprecated='auto')
hashed = ctx.hash('mypassword')
ctx.verify('mypassword', hashed)

Verify before relying

  • Whether passlib's algorithms remain cryptographically sound against current attack standards
  • Compatibility with Python versions released after October 2020
  • Whether any of the supported algorithms have been deprecated by the cryptographic community

Package facts

LicenseBSD permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceAbandoned 2,136 days since the last release
First released
Downloads39,687,098 / month, #690 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14

Evidence: passlib-1.7.4-py2.py3-none-any.whl

Tags

Capabilities
password hashing libraryverify password hashpassword security frameworkcross-platform password algorithmshash password pythonpassword scheme managementlegacy hash verification
Topics
password-hashinglegacy-maintenance
PyPI keywords
passwordsecrethashsecurity

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “verify password hash”

  • passlibPasslib provides a framework for hashing and verifying passwords…
  • pwdlibProvides a modern, easy-to-use wrapper for hashing and verifying…
  • libpassA password hashing library providing implementations of over 30…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also libpass · pwdlib · types-passlib · Flask-Bcrypt · argon2-cffi · bcrypt · securesystemslib · AuthEncoding · siphash · dict-hash