py_svg_hush
Decision gist · record as of 2026-08-14
Yes, if you need to sanitize untrusted SVG input and can accept the license uncertainty. The package is straightforward, has no runtime dependencies, and benefits from battle-tested Rust logic. However, verify the license terms before use in proprietary or commercial contexts, and confirm that svg-hush's threat model matches your security requirements. The aging maintenance status (182 days since last release) is not a blocker for a stable utility, but monitor the repository for security updates.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Medium install friction due to compiled Rust bindings; wheels are available for Python 3.10–3.14 across Linux, macOS, and Windows.
- Last commit was 182 days ago and the project is marked as aging, though the repository remains active and unarchived.
License · maintenance · safety
(unclear) — License status is unclear—no SPDX identifier or raw license text is recorded in the package metadata, so the legal terms for use and redistribution cannot be determined from the fact sheet.
last release 2026-02-13 (182 days) · last repo commit 2026-02-13 · 7 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 82,483 downloads/mo, #14,160 on PyPI
Alternatives
Verify before relying
pip install py-svg-hush
from py_svg_hush import filter_svg
svg_bytes = b'<svg>...</svg>'
keep_data_url_mime_types = {"image": ["jpeg", "png", "gif"]}
sanitized = filter_svg(svg_bytes, keep_data_url_mime_types)- Whether the underlying svg-hush Rust library's security model and threat coverage are documented or audited.
- What specific malicious elements and attributes are removed by filter_svg beyond data URL filtering.
- Whether the package is actively maintained or in maintenance-only mode given the 182-day gap since last release.
What it is and what it does
py-svg-hush is a Python wrapper around Cloudflare's svg-hush Rust library that removes potentially malicious content from SVG files. It provides a single function, filter_svg, which takes SVG bytes and an optional dictionary of allowed MIME types for data URLs, then returns sanitized SVG bytes. The package strips dangerous elements and attributes while enforcing a whitelist of permitted data URL MIME types—any data URL whose type is not in the whitelist is dropped entirely.
The package is built as a compiled extension using Rust bindings, which means installation requires downloading or building wheels for your platform and Python version. It supports Python 3.10 through 3.14 on CPython and PyPy, with prebuilt wheels available for common architectures. The API is minimal and straightforward: one function call with two parameters, raising ValueError or TypeError on invalid input.
Use it for
- Sanitize user-uploaded SVG files in a web application before storing or displaying them.
- Strip embedded scripts and event handlers from SVG graphics in a content management system.
- Enforce a whitelist of allowed image MIME types in SVG data URLs to prevent unexpected content injection.
- Batch-process a collection of SVG files to remove known attack vectors before distribution.
- Validate SVG safety in a document processing pipeline that accepts external graphics.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to sanitize untrusted SVG input and can accept the license uncertainty.
The package is straightforward, has no runtime dependencies, and benefits from battle-tested Rust logic. However, verify the license terms before use in proprietary or commercial contexts, and confirm that svg-hush's threat model matches your security requirements. The aging maintenance status (182 days since last release) is not a blocker for a stable utility, but monitor the repository for security updates.
Install
py-svg-hush on PyPI
Before you install
Medium install friction due to compiled Rust bindings; wheels are available for Python 3.10–3.14 across Linux, macOS, and Windows. Last commit was 182 days ago and the project is marked as aging, though the repository remains active and unarchived.
Requires Python 3.10 or later.
License in practice
License status is unclear—no SPDX identifier or raw license text is recorded in the package metadata, so the legal terms for use and redistribution cannot be determined from the fact sheet.
Quickstart
pip install py-svg-hush
from py_svg_hush import filter_svg
svg_bytes = b'<svg>...</svg>'
keep_data_url_mime_types = {"image": ["jpeg", "png", "gif"]}
sanitized = filter_svg(svg_bytes, keep_data_url_mime_types)
Verify before relying
- Whether the underlying svg-hush Rust library's security model and threat coverage are documented or audited.
- What specific malicious elements and attributes are removed by filter_svg beyond data URL filtering.
- Whether the package is actively maintained or in maintenance-only mode given the 182-day gap since last release.
Package facts
| License | Not declared unclear |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | None |
| Maintenance | Aging 182 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 82,483 / month, #14,160 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Programming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyProgramming Language :: Rust |
Evidence: py_svg_hush-0.3.0-cp310-cp310-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; py_svg_hush-0.3.0-cp310-cp310-manylinux_2_17_armv7l.manylinux2014_armv7l.whl; py_svg_hush-0.3.0-cp310-cp310-manylinux_2_17_ppc64le.manylinux2014_ppc64le.whl; py_svg_hush-0.3.0-cp310-cp310-manylinux_2_17_s390x.manylinux2014_s390x.whl; py_svg_hush-0.3.0-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; py_svg_hush-0.3.0-cp310-cp310-manylinux_2_5_i686.manylinux1_i686.whl; py_svg_hush-0.3.0-cp310-cp310-musllinux_1_2_aarch64.whl; py_svg_hush-0.3.0-cp310-cp310-musllinux_1_2_armv7l.whl; py_svg_hush-0.3.0-cp310-cp310-musllinux_1_2_i686.whl; py_svg_hush-0.3.0-cp310-cp310-musllinux_1_2_x86_64.whl; py_svg_hush-0.3.0-cp310-cp310-win_amd64.whl; py_svg_hush-0.3.0-cp311-cp311-macosx_10_12_x86_64.whl; py_svg_hush-0.3.0-cp311-cp311-macosx_11_0_arm64.whl; py_svg_hush-0.3.0-cp311-cp311-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; py_svg_hush-0.3.0-cp311-cp311-manylinux_2_17_armv7l.manylinux2014_armv7l.whl; py_svg_hush-0.3.0-cp311-cp311-manylinux_2_17_ppc64le.manylinux2014_ppc64le.whl; py_svg_hush-0.3.0-cp311-cp311-manylinux_2_17_s390x.manylinux2014_s390x.whl; py_svg_hush-0.3.0-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; py_svg_hush-0.3.0-cp311-cp311-manylinux_2_5_i686.manylinux1_i686.whl; py_svg_hush-0.3.0-cp311-cp311-musllinux_1_2_aarch64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “svg sanitization”
- py_svg_hushSanitizes SVG files by removing malicious elements, attributes, and…
- lxml-html-cleanCleans and sanitizes HTML by removing unwanted tags and attributes…
- bleach-allowlistProvides curated allowlists of HTML tags, attributes, and CSS styles…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also nh3 · scour · resvg_py · html-sanitizer · lxml-html-clean · bleach · CairoSVG · svgelements · faicons · typst