$npx skillfedfor your agent

pwned-passwords-django

A Pwned Passwords implementation for Django sites.

With conditionsPyPI UtilitiesReleased Apr 2025167.7K downloads / moBSD-3-ClausePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pwned_passwords_django-5.2.0-py3-none-any.whl
v5.2.0 · released 2025-04-06 · Python >=3.9 · 2 runtime deps: Django, httpx

Yes, if you run a Django site and want to reject compromised passwords. The package is production-stable (Development Status 5), has low install friction, carries a permissive license, and has no known vulnerabilities. The aging maintenance status (last release 495 days ago) is a minor concern—the code is stable and the underlying Pwned Passwords API is maintained externally—but verify that the package still works with your Django and Python versions before deploying.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Django 4.2 or later and Python 3.9 or later; the Pwned Passwords API is queried over the network, so internet connectivity is needed for password checks.
  • Low install friction with two straightforward runtime dependencies (Django and httpx).
  • Maintenance status is aging—last commit was 2025-04-06 and the package has not had a release in 495 days, though the repository remains active and not archived.

License · maintenance · safety

BSD-3-Clause (permissive) — BSD-3-Clause permissive license allows commercial and private use with minimal restrictions, requiring only preservation of copyright and license notices.

last release 2025-04-06 (495 days) · last repo commit 2025-04-06 · 131 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 167,675 downloads/mo, #10,465 on PyPI

Verify before relying

pip install pwned-passwords-django

# In Django settings.py:
AUTH_PASSWORD_VALIDATORS = [
    {"NAME": "pwned_passwords_django.validators.PwnedPasswordsValidator"},
]
MIDDLEWARE = [
    "pwned_passwords_django.middleware.pwned_passwords_middleware",
]
  • Whether the 495-day gap since last release indicates the package is stable or no longer actively maintained.
  • Performance impact of middleware on request handling when checking against the Pwned Passwords API.
  • Whether async support in middleware and API client is production-ready.
Same gist for agents: .md · .json

What it is and what it does

This package brings password breach detection to Django applications by querying the Have I Been Pwned Pwned Passwords database—a large, curated collection of passwords compromised in known data breaches. It offers three integration points: a password validator that plugs into Django's built-in password validation system, middleware that automatically checks certain request payloads, and a direct API client for custom use cases. All queries use an anonymized, k-anonymity protocol that never sends full passwords or complete hashes to third parties, protecting user privacy while checking against breach records.

The package supports both synchronous and asynchronous Django request handling, making it suitable for modern async-capable Django projects. It requires Django 4.2 or later and Python 3.9 or later, and depends only on httpx for HTTP communication. The recommended setup is to enable both the validator and middleware together, creating a defense-in-depth approach: the validator rejects weak passwords at account creation or password-change time, while the middleware catches attempts to use compromised credentials in login or other sensitive requests.

Use it for

  • Reject weak passwords during user registration or password reset by adding the validator to Django's AUTH_PASSWORD_VALIDATORS.
  • Automatically block login attempts using credentials known to be compromised, via the middleware layer.
  • Build custom password-strength workflows that query the Pwned Passwords database directly using the API client.
  • Implement multi-layer authentication security in Django admin or other sensitive areas by combining the validator and middleware.
  • Audit existing user passwords against breach records in background tasks using the async API client.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you run a Django site and want to reject compromised passwords.

The package is production-stable (Development Status 5), has low install friction, carries a permissive license, and has no known vulnerabilities. The aging maintenance status (last release 495 days ago) is a minor concern—the code is stable and the underlying Pwned Passwords API is maintained externally—but verify that the package still works with your Django and Python versions before deploying.

Install

pwned-passwords-django on PyPI

Before you install

Low install friction with two straightforward runtime dependencies (Django and httpx). Maintenance status is aging—last commit was 2025-04-06 and the package has not had a release in 495 days, though the repository remains active and not archived.

Requires Django 4.2 or later and Python 3.9 or later; the Pwned Passwords API is queried over the network, so internet connectivity is needed for password checks.

License in practice

BSD-3-Clause permissive license allows commercial and private use with minimal restrictions, requiring only preservation of copyright and license notices.

Quickstart

pip install pwned-passwords-django

# In Django settings.py:
AUTH_PASSWORD_VALIDATORS = [
    {"NAME": "pwned_passwords_django.validators.PwnedPasswordsValidator"},
]
MIDDLEWARE = [
    "pwned_passwords_django.middleware.pwned_passwords_middleware",
]

Verify before relying

  • Whether the 495-day gap since last release indicates the package is stable or no longer actively maintained.
  • Performance impact of middleware on request handling when checking against the Pwned Passwords API.
  • Whether async support in middleware and API client is production-ready.

Package facts

LicenseBSD-3-Clause permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
Djangohttpx
MaintenanceAging 495 days since the last release
Last repo commit
First released
Downloads167,675 / month, #10,465 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentFramework :: DjangoFramework :: Django :: 4.2Framework :: Django :: 5.1Framework :: Django :: 5.2Intended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Topic :: Utilities

Evidence: pwned_passwords_django-5.2.0-py3-none-any.whl

Tags

Capabilities
django password breach validationpwned passwords integrationdjango security password checkerhave i been pwned djangopassword compromise detectiondjango auth password validatorbreach database password check
Topics
django-securitypassword-validationbreach-detection
PyPI keywords
djangosecuritypasswordsauthauthentication

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “django password breach validation”

Give your agent the search over MCP, or paste the wish link into any chat.

More Utilities packages

idna Worth it
PyPI · Python Modules · released Jun 2026

Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.

Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.

BSD-3-Clausepure Python · 3.9+
1.8Bdownloads / mo
charset-normalizer Worth it
PyPI · Utilities · released Aug 2026

Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.

permissive licensepure Python · 3.7+
1.7Bdownloads / mo
setuptools Worth it
PyPI · Python Modules · released Aug 2026

Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.

MITpure Python · 3.10+
1.6Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
Pygments Worth it
PyPI · Utilities · released Mar 2026

Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.

Install it if you need to display or transform source code.

BSD-2-Clausepure Python · 3.9+
1.3Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo

See also django-password-validators · django-zxcvbn-password-validator · django-otp · pwdlib · django-dirtyfields · django-registration · django-localflavor · django-constance · django-sesame · streamlit-authenticator