$npx skillfedfor your agent

pycrypto

Cryptographic modules for Python.

SkipPyPI CryptographyReleased Jun 20148.5M downloads / moPublic domainSource build

Decision gist · record as of 2026-08-14

sdist only — pycrypto-2.6.1.tar.gz · builds from source
v2.6.1 · released 2014-06-20

No. Do not install pycrypto for new projects. The package is abandoned, carries four known vulnerabilities (GHSA-6528-wvf6-f6qg, GHSA-cq27-v7xp-c356, PYSEC-2017-94, PYSEC-2018-97), and has not been maintained for 4438 days. High install friction compounds the risk. For legacy code only.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires C compiler and Python development headers (python-dev on Debian/Ubuntu, python2-devel on Red Hat).
  • Will fail to build on systems without compilation tools.
  • High install friction: requires compilation of C extensions.

License · maintenance · safety

Public domain (permissive) — Public domain license permits unrestricted use, modification, and distribution without attribution requirements.

last release 2014-06-20 (4438 days)

4 known vulnerabilities (OSV.dev, 2026-08-14) · 8,514,383 downloads/mo, #1,613 on PyPI

Verify before relying

pip install pycrypto==2.6.1
from Crypto.Hash import SHA256
hash = SHA256.new()
hash.update(b'message')
print(hash.digest())
  • Whether the 4 known vulnerabilities (GHSA-6528-wvf6-f6qg, GHSA-cq27-v7xp-c356, PYSEC-2017-94, PYSEC-2018-97) remain exploitable in version 2.6.1.
  • Current status of Python 3 compatibility given the package's age and evolution since first release 2010-12-17.
  • Whether compilation succeeds on modern systems with current toolchains.
  • Availability of drop-in replacement packages for new projects.
Same gist for agents: .md · .json

What it is and what it does

PyCrypto is a collection of cryptographic primitives for Python, providing secure hash functions, symmetric ciphers (AES, DES), asymmetric algorithms (RSA, ElGamal), and a cryptographically secure random number generator. It was designed to make adding new cryptographic modules straightforward and was considered production-stable at release.

The package has been abandoned since 2014-06-20 and receives no maintenance. While it remains downloadable and installable, it carries four known security vulnerabilities and lacks support for modern Python versions and security practices. Installation requires a C compiler and Python development headers, adding friction to deployment.

Use it for

  • Legacy systems or applications that already depend on pycrypto and cannot be migrated to newer libraries.
  • Educational projects learning cryptographic algorithms where the implementation details matter more than production security.
  • Prototyping public-key algorithms in Python where arbitrary-length integer support is needed.
  • Encrypting data in daemons or servers where mutual authentication between clients and servers is required.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Skip

No.

Do not install pycrypto for new projects. The package is abandoned, carries four known vulnerabilities (GHSA-6528-wvf6-f6qg, GHSA-cq27-v7xp-c356, PYSEC-2017-94, PYSEC-2018-97), and has not been maintained for 4438 days. High install friction compounds the risk. For legacy code only.

Install

pycrypto on PyPI

Before you install

High install friction: requires compilation of C extensions. Package is abandoned as of 2014-06-20 with no maintenance for 4438 days. Strongly consider using actively maintained alternatives instead.

Requires C compiler and Python development headers (python-dev on Debian/Ubuntu, python2-devel on Red Hat). Will fail to build on systems without compilation tools.

License in practice

Public domain license permits unrestricted use, modification, and distribution without attribution requirements.

Quickstart

pip install pycrypto==2.6.1
from Crypto.Hash import SHA256
hash = SHA256.new()
hash.update(b'message')
print(hash.digest())

Verify before relying

  • Whether the 4 known vulnerabilities (GHSA-6528-wvf6-f6qg, GHSA-cq27-v7xp-c356, PYSEC-2017-94, PYSEC-2018-97) remain exploitable in version 2.6.1.
  • Current status of Python 3 compatibility given the package's age and evolution since first release 2010-12-17.
  • Whether compilation succeeds on modern systems with current toolchains.
  • Availability of drop-in replacement packages for new projects.

Package facts

LicensePublic domain permissive
Python supportNot specified
Install frictionHigh. Source build required
Runtime dependenciesNone
MaintenanceAbandoned 4,438 days since the last release
First released
Downloads8,514,383 / month, #1,613 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilities4 GHSA-6528-wvf6-f6qg, GHSA-cq27-v7xp-c356, PYSEC-2017-94, PYSEC-2018-97
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: Public DomainOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: UnixProgramming Language :: Python :: 2Programming Language :: Python :: 3Topic :: Security :: Cryptography

Evidence: pycrypto-2.6.1.tar.gz

Tags

Capabilities
python cryptography toolkitAES encryption librarySHA256 hash functionsRSA public key cryptographysecure random number generatorsymmetric encryption pythoncryptographic algorithms
Topics
abandonedhigh-install-frictionsecurity-vulnerabilities

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “python cryptography toolkit”

  • pycryptoProvides cryptographic hash functions (SHA256, RIPEMD160) and…
  • M2CryptoM2Crypto wraps OpenSSL via SWIG to provide Python access to…
  • malduckMalduck provides cryptographic, compression, and memory-analysis…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also pycryptodomex · sslcrypto · pyAesCrypt · pqcrypto · py3rijndael · pysnmpcrypto · pyaes · oscrypto · lightphe · unicrypto