pycrypto
Cryptographic modules for Python.
Decision gist · record as of 2026-08-14
No. Do not install pycrypto for new projects. The package is abandoned, carries four known vulnerabilities (GHSA-6528-wvf6-f6qg, GHSA-cq27-v7xp-c356, PYSEC-2017-94, PYSEC-2018-97), and has not been maintained for 4438 days. High install friction compounds the risk. For legacy code only.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires C compiler and Python development headers (python-dev on Debian/Ubuntu, python2-devel on Red Hat).
- Will fail to build on systems without compilation tools.
- High install friction: requires compilation of C extensions.
License · maintenance · safety
Public domain (permissive) — Public domain license permits unrestricted use, modification, and distribution without attribution requirements.
last release 2014-06-20 (4438 days)
4 known vulnerabilities (OSV.dev, 2026-08-14) · 8,514,383 downloads/mo, #1,613 on PyPI
Alternatives
Verify before relying
pip install pycrypto==2.6.1
from Crypto.Hash import SHA256
hash = SHA256.new()
hash.update(b'message')
print(hash.digest())- Whether the 4 known vulnerabilities (GHSA-6528-wvf6-f6qg, GHSA-cq27-v7xp-c356, PYSEC-2017-94, PYSEC-2018-97) remain exploitable in version 2.6.1.
- Current status of Python 3 compatibility given the package's age and evolution since first release 2010-12-17.
- Whether compilation succeeds on modern systems with current toolchains.
- Availability of drop-in replacement packages for new projects.
What it is and what it does
PyCrypto is a collection of cryptographic primitives for Python, providing secure hash functions, symmetric ciphers (AES, DES), asymmetric algorithms (RSA, ElGamal), and a cryptographically secure random number generator. It was designed to make adding new cryptographic modules straightforward and was considered production-stable at release.
The package has been abandoned since 2014-06-20 and receives no maintenance. While it remains downloadable and installable, it carries four known security vulnerabilities and lacks support for modern Python versions and security practices. Installation requires a C compiler and Python development headers, adding friction to deployment.
Use it for
- Legacy systems or applications that already depend on pycrypto and cannot be migrated to newer libraries.
- Educational projects learning cryptographic algorithms where the implementation details matter more than production security.
- Prototyping public-key algorithms in Python where arbitrary-length integer support is needed.
- Encrypting data in daemons or servers where mutual authentication between clients and servers is required.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
Do not install pycrypto for new projects. The package is abandoned, carries four known vulnerabilities (GHSA-6528-wvf6-f6qg, GHSA-cq27-v7xp-c356, PYSEC-2017-94, PYSEC-2018-97), and has not been maintained for 4438 days. High install friction compounds the risk. For legacy code only.
Install
pycrypto on PyPI
Before you install
High install friction: requires compilation of C extensions. Package is abandoned as of 2014-06-20 with no maintenance for 4438 days. Strongly consider using actively maintained alternatives instead.
Requires C compiler and Python development headers (python-dev on Debian/Ubuntu, python2-devel on Red Hat). Will fail to build on systems without compilation tools.
License in practice
Public domain license permits unrestricted use, modification, and distribution without attribution requirements.
Quickstart
pip install pycrypto==2.6.1
from Crypto.Hash import SHA256
hash = SHA256.new()
hash.update(b'message')
print(hash.digest())
Verify before relying
- Whether the 4 known vulnerabilities (GHSA-6528-wvf6-f6qg, GHSA-cq27-v7xp-c356, PYSEC-2017-94, PYSEC-2018-97) remain exploitable in version 2.6.1.
- Current status of Python 3 compatibility given the package's age and evolution since first release 2010-12-17.
- Whether compilation succeeds on modern systems with current toolchains.
- Availability of drop-in replacement packages for new projects.
Package facts
| License | Public domain permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Abandoned 4,438 days since the last release |
| First released | |
| Downloads | 8,514,383 / month, #1,613 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | 4 GHSA-6528-wvf6-f6qg, GHSA-cq27-v7xp-c356, PYSEC-2017-94, PYSEC-2018-97 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: Public DomainOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: UnixProgramming Language :: Python :: 2Programming Language :: Python :: 3Topic :: Security :: Cryptography |
Evidence: pycrypto-2.6.1.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “python cryptography toolkit”
- pycryptoProvides cryptographic hash functions (SHA256, RIPEMD160) and…
- M2CryptoM2Crypto wraps OpenSSL via SWIG to provide Python access to…
- malduckMalduck provides cryptographic, compression, and memory-analysis…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also pycryptodomex · sslcrypto · pyAesCrypt · pqcrypto · py3rijndael · pysnmpcrypto · pyaes · oscrypto · lightphe · unicrypto