python-pcapng
Library to read/write the pcap-ng format used by various packet sniffers.
Decision gist · record as of 2026-08-14
Yes, if you need to work with pcap-ng files in Python and have no better alternative. The library is stable (Production/Stable status), has no known vulnerabilities, and installs with zero friction. However, maintenance is aging (last release 2022-08-23, no active development), so expect no new features or bug fixes—suitable for stable, read-heavy workloads but risky for projects requiring ongoing support.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low friction: pure Python wheel with no runtime dependencies.
- Maintenance is aging—last release was 2022-08-23 and the repository shows no recent activity, though it remains archived=false and the last commit is recent (2026-01-25), suggesting minimal ongoing development.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 is permissive; you can use, modify, and distribute this library freely in commercial and open-source projects, provided you include the license notice.
last release 2022-08-23 (1452 days) · last repo commit 2026-01-25 · 130 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 483,480 downloads/mo, #6,412 on PyPI
Alternatives
Verify before relying
from pcapng import FileScanner
with open('/tmp/mycapture.pcap', 'rb') as fp:
scanner = FileScanner(fp)
for block in scanner:
pass # do something with the block- Performance characteristics compared to C-based alternatives or Cython ports mentioned in the description.
- Completeness of pcap-ng format support relative to the full specification.
- Whether the library handles all edge cases in real-world captures from different packet sniffers.
What it is and what it does
Python-pcapng is a pure-Python library for reading and writing pcap-ng packet capture files—the modern format used by Wireshark, dumpcap, and similar network analysis tools. It fills a gap where tcpdump and other tools struggle with pcap-ng files, and where few Python bindings existed for the format. The library parses binary pcap-ng data into block objects that represent packets, interfaces, and metadata, and can also generate valid pcap-ng files from scratch.
The library includes a strictness mode (FORBID, FIX, WARN, NONE) to control how strictly it validates pcap-ng structure during writing, allowing both strict compliance and deliberate generation of edge-case files for testing. It has no external runtime dependencies and runs on modern Python versions (3.5+), making it straightforward to integrate into network analysis pipelines, packet inspection tools, or test suites.
Use it for
- Extract packet data and metadata from pcap-ng files captured by Wireshark or dumpcap for offline analysis.
- Generate synthetic pcap-ng files for testing network analysis tools or packet processing code.
- Convert or migrate packet capture data between formats or tools that require pcap-ng input.
- Build custom packet inspection or filtering tools that need to read modern packet capture formats.
- Validate pcap-ng file structure or repair marginal/broken capture files by re-writing with adjusted strictness.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to work with pcap-ng files in Python and have no better alternative.
The library is stable (Production/Stable status), has no known vulnerabilities, and installs with zero friction. However, maintenance is aging (last release 2022-08-23, no active development), so expect no new features or bug fixes—suitable for stable, read-heavy workloads but risky for projects requiring ongoing support.
Install
python-pcapng on PyPI
Before you install
Low friction: pure Python wheel with no runtime dependencies. Maintenance is aging—last release was 2022-08-23 and the repository shows no recent activity, though it remains archived=false and the last commit is recent (2026-01-25), suggesting minimal ongoing development.
License in practice
Apache-2.0 is permissive; you can use, modify, and distribute this library freely in commercial and open-source projects, provided you include the license notice.
Quickstart
from pcapng import FileScanner
with open('/tmp/mycapture.pcap', 'rb') as fp:
scanner = FileScanner(fp)
for block in scanner:
pass # do something with the block
Verify before relying
- Performance characteristics compared to C-based alternatives or Cython ports mentioned in the description.
- Completeness of pcap-ng format support relative to the full specification.
- Whether the library handles all edge cases in real-world captures from different packet sniffers.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release ~=3.5 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Aging 1,452 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 483,480 / month, #6,412 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: Implementation :: CPython |
Evidence: python_pcapng-2.1.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “pcap-ng file parser”
- python-pcapngParses and writes pcap-ng packet capture files, the format used by…
- pysharkPyshark wraps tshark (Wireshark's command-line tool) to parse network…
- INIToolsINITools parses and manipulates INI-style configuration files through…
Give your agent the search over MCP, or paste the wish link into any chat.
More Networking packages
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
psutil retrieves real-time information about running processes and system resources (CPU, memory, disks, network, sensors) across multiple operating systems, enabling system monitoring, process profiling, and resource management.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
uvloop is a drop-in replacement for Python's built-in asyncio event loop, implemented in Cython and using libuv, that accelerates async I/O operations.
execnet lets you spawn and communicate with Python interpreters across local processes, remote hosts, and different platforms, using a simple API for task distribution and inter-process messaging.
However, the aging maintenance status (275 days since last release) means you should verify it meets your concurrency and performance needs before committing to a…
PyZMQ provides Python bindings for ZeroMQ (ØMQ), a lightweight messaging library that enables fast, asynchronous communication between distributed processes and applications.
See also pyshark · pypcap · pure-pcapy3 · scapy · pydivert · dpkt · rtp · pmd-net-proto · dnslib · ar