pyAesCrypt
Encrypt and decrypt files and streams in AES Crypt format (version 2)
Decision gist · record as of 2026-08-14
Yes, if you need straightforward AES256-CBC file encryption compatible with the AES Crypt format and can accept dormant maintenance. The package is stable with no known vulnerabilities and handles the common case well. Install it if you are not expecting active security updates or bug fixes; avoid it if you require ongoing support or are encrypting data where file-size tampering is a threat model.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Version 2 of the AES Crypt file format does not authenticate the file size modulo 16 byte, so an attacker with write access to the encrypted file may alter the plaintext file size by up to 15 bytes.
- Python has no low-level memory management, so sensitive information cannot be wiped from memory.
- Low install friction with a single runtime dependency (cryptography).
License · maintenance · safety
Apache License 2.0 (permissive) — Released under Apache License 2.0 (permissive), so you can use it freely in commercial and private projects with minimal legal constraints.
last release 2023-11-11 (1007 days) · last repo commit 2023-11-11 · 247 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 215,839 downloads/mo, #9,392 on PyPI
Alternatives
Verify before relying
import pyAesCrypt
password = "please-use-a-long-and-random-password"
pyAesCrypt.encryptFile("data.txt", "data.txt.aes", password)
pyAesCrypt.decryptFile("data.txt.aes", "dataout.txt", password)- Whether dormant maintenance status poses a practical risk for your use case, given no known vulnerabilities are currently recorded.
- Performance characteristics and suitability for large files or high-throughput scenarios.
- Current real-world adoption and whether the AES Crypt format version 2 limitations are acceptable for your threat model.
What it is and what it does
pyAesCrypt is a Python 3 module for encrypting and decrypting files and binary streams using AES256-CBC. It implements the AES Crypt file format (version 2) and can be used as both a library and a command-line tool. The module provides three main interfaces: file-level encryption/decryption, stream-oriented operations for handling large data, and in-memory encryption/decryption via BytesIO.
The package depends only on cryptography and installs with low friction. Maintenance is dormant—the last release was in November 2023. The documentation includes important security caveats: the AES Crypt format version 2 does not authenticate file size metadata, allowing potential tampering with plaintext length, and Python's lack of low-level memory management means sensitive data cannot be securely wiped from RAM.
Use it for
- Encrypt sensitive files before storing them in untrusted locations or cloud storage.
- Decrypt files encrypted by the AES Crypt tool or other compatible implementations.
- Build a file encryption feature into a Python application using password-based encryption.
- Process large files or streams with custom buffer sizes to manage memory usage.
- Perform in-memory encryption/decryption of binary data using BytesIO without touching the filesystem.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need straightforward AES256-CBC file encryption compatible with the AES Crypt format and can accept dormant maintenance.
The package is stable with no known vulnerabilities and handles the common case well. Install it if you are not expecting active security updates or bug fixes; avoid it if you require ongoing support or are encrypting data where file-size tampering is a threat model.
Install
pyaescrypt on PyPI
Before you install
Low install friction with a single runtime dependency (cryptography). Maintenance is dormant—last release was in November 2023—so expect no active bug fixes or security updates, though the repository remains public and unarchived.
Version 2 of the AES Crypt file format does not authenticate the file size modulo 16 byte, so an attacker with write access to the encrypted file may alter the plaintext file size by up to 15 bytes. Python has no low-level memory management, so sensitive information cannot be wiped from memory.
License in practice
Released under Apache License 2.0 (permissive), so you can use it freely in commercial and private projects with minimal legal constraints.
Quickstart
import pyAesCrypt
password = "please-use-a-long-and-random-password"
pyAesCrypt.encryptFile("data.txt", "data.txt.aes", password)
pyAesCrypt.decryptFile("data.txt.aes", "dataout.txt", password)
Verify before relying
- Whether dormant maintenance status poses a practical risk for your use case, given no known vulnerabilities are currently recorded.
- Performance characteristics and suitability for large files or high-throughput scenarios.
- Current real-world adoption and whether the AES Crypt format version 2 limitations are acceptable for your threat model.
Package facts
| License | Apache License 2.0 permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagecryptography |
| Maintenance | Dormant 1,007 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 215,839 / month, #9,392 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Topic :: SecurityTopic :: Security :: CryptographyTopic :: Utilities |
Evidence: pyAesCrypt-6.1.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “AES file encryption”
- pyAesCryptEncrypts and decrypts files and binary streams using AES256-CBC,…
- pyzipperpyzipper replaces Python's standard zipfile module to read and write…
- pyaesPure-Python implementation of AES encryption with support for all key…
Give your agent the search over MCP, or paste the wish link into any chat.
More Utilities packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.
Install it if you need to display or transform source code.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
See also ansible-vault · crypto · kasa-crypt · pyaes · pyzipper · pyrage · pyscrypt · aes-pkcs5 · pycrypto · msoffcrypto-tool