$npx skillfedfor your agent

quickjs-rs

Sandboxed JavaScript execution for Python, via wasmtime + rquickjs.

With conditionsPyPI InterpretersReleased Jul 2026305.6K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — quickjs_rs-0.2.5-py3-none-any.whl
v0.2.5 · released 2026-07-24 · Python >=3.11 · 1 runtime deps: wasmtime

Yes, if you need sandboxed JavaScript execution in Python and can tolerate the experimental status. The low install friction, active maintenance, permissive license, and zero known vulnerabilities make it a reasonable choice. Read the security guide before production use—wasmtime updates are critical, and snapshot bytes are treated as trusted input. Not suitable if you need a mature, battle-tested JS runtime or if your Python version is below 3.11.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.11+.
  • wasmtime must be available as a runtime dependency (installed automatically).
  • Low friction: ships as a single universal wheel with no compiled dependencies beyond wasmtime.

License · maintenance · safety

MIT (permissive) — MIT license (permissive) — you may use, modify, and distribute freely with minimal restrictions, provided you retain the license notice.

last release 2026-07-24 (21 days) · last repo commit 2026-07-24 · 11 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 305,638 downloads/mo, #7,793 on PyPI

Verify before relying

pip install quickjs-rs

from quickjs_rs import Runtime

with Runtime() as rt:
    with rt.new_context() as ctx:
        result = ctx.eval("1 + 2")
        print(result)  # 3
  • Performance characteristics and overhead compared to native JS runtimes or other Python JS bindings
  • Completeness of ES module resolution and TypeScript support relative to production use cases
  • Snapshot serialization format stability and forward/backward compatibility guarantees
Same gist for agents: .md · .json

What it is and what it does

quickjs-rs runs JavaScript inside a WebAssembly sandbox, isolating guest code from the Python host. The package bundles quickjs-ng (a QuickJS fork) compiled to WebAssembly and driven by wasmtime; it ships as a pure-Python wheel with no native compilation step. You write Python code that creates a Runtime and Context, then eval JavaScript strings or async code, optionally registering Python callables as JS globals and vice versa.

The sandbox supports ES modules with custom host-controlled resolution, TypeScript source stripping before evaluation, and full async/await semantics bridging Python and JS. You can also capture and restore entire VM snapshots—heap state, closures, pending promises—as binary payloads. The security model relies on WebAssembly's linear-memory isolation; the JS engine cannot access Python's address space, though wasmtime itself remains the residual attack surface.

Use it for

  • Execute untrusted or user-supplied JavaScript safely without exposing the Python process to direct memory access.
  • Bridge Python and JavaScript logic in a single process—call Python functions from JS and vice versa with type conversion.
  • Load and run ES modules with custom resolution policy, enabling plugin architectures or dynamic code loading.
  • Strip and execute TypeScript source code without a separate compilation step or type-checking pipeline.
  • Snapshot a fully initialized JS VM state and restore it into fresh contexts for fast, stateful re-execution.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need sandboxed JavaScript execution in Python and can tolerate the experimental status.

The low install friction, active maintenance, permissive license, and zero known vulnerabilities make it a reasonable choice. Read the security guide before production use—wasmtime updates are critical, and snapshot bytes are treated as trusted input. Not suitable if you need a mature, battle-tested JS runtime or if your Python version is below 3.11.

Install

quickjs-rs on PyPI

Before you install

Low friction: ships as a single universal wheel with no compiled dependencies beyond wasmtime. Active maintenance (last commit 2026-07-24, released 21 days ago). Requires Python 3.11+; runs on Linux, macOS, Windows (x86_64 + arm64).

Requires Python 3.11+. wasmtime must be available as a runtime dependency (installed automatically).

License in practice

MIT license (permissive) — you may use, modify, and distribute freely with minimal restrictions, provided you retain the license notice.

Quickstart

pip install quickjs-rs

from quickjs_rs import Runtime

with Runtime() as rt:
    with rt.new_context() as ctx:
        result = ctx.eval("1 + 2")
        print(result)  # 3

Verify before relying

  • Performance characteristics and overhead compared to native JS runtimes or other Python JS bindings
  • Completeness of ES module resolution and TypeScript support relative to production use cases
  • Snapshot serialization format stability and forward/backward compatibility guarantees

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.11
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
wasmtime
MaintenanceActively maintained 21 days since the last release
Last repo commit
First released
Downloads305,638 / month, #7,793 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 3 - AlphaIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Topic :: Software Development :: Interpreters

Evidence: quickjs_rs-0.2.5-py3-none-any.whl

Tags

Capabilities
sandboxed javascript execution pythonrun js code from pythonwasm javascript interpreterquickjs python bindingjavascript sandbox wasmasync javascript pythones modules javascript python
Topics
javascript-sandboxwasm-runtimeasync-bridge
PyPI keywords
javascriptquickjssandboxwasmwasmtime

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “wasm javascript interpreter”

  • quickjs-rsExecutes JavaScript code inside a WebAssembly sandbox from Python,…
  • mini-racerEmbeds Google's V8 JavaScript engine in Python, allowing you to…
  • wasmerExecutes WebAssembly modules from Python with a complete runtime that…

Give your agent the search over MCP, or paste the wish link into any chat.

More Interpreters packages

asttokens Worth it
PyPI · Python Modules · released Jul 2026

Annotates Python abstract syntax trees with the positions of tokens and source code text, enabling tools to map AST nodes back to their originating code for refactoring, analysis, and transformation.

permissive licensepure Python · 3.8+
134.8Mdownloads / mo
pyinstaller Worth it
PyPI · Software Development · released Aug 2026

PyInstaller bundles a Python application and all its dependencies into a single standalone executable or folder that runs without requiring a Python interpreter or installed modules on the target system.

Install it if you need to distribute Python applications as standalone executables.

GPL-2.0-onlycompiled wheel
12.1Mdownloads / mo
parsy Worth it
PyPI · Text Processing · released Sep 2025

Parsy is a parser combinator library that lets you build complex text parsers by combining small, reusable parser functions together in a declarative style.

Install it if you need to parse structured text and prefer a functional, composable approach over regex or hand-rolled parsing logic.

MITpure Python · 3.9+
3.8Mdownloads / mo
Arpeggio Worth it
PyPI · Python Modules · released Sep 2025

Arpeggio is a recursive descent parser with memoization that implements PEG (Packrat) grammars, letting you define and parse custom languages or structured text formats.

Install it if you need to build a parser for a custom grammar or language; if you want a higher-level interface for language definition, consider textX instead.

MITpure Python
2.1Mdownloads / mo
wasmtime Worth it
PyPI · Compilers · released Jul 2026

Embeds the Wasmtime WebAssembly runtime in Python, allowing you to compile, instantiate, and execute WebAssembly modules and components directly from Python code.

Install it if you need to execute WebAssembly from Python; verify the license terms for your use case first.

Apache-2.0 WITH LLVM-exceptionpure Python · 3.9+
1.9Mdownloads / mo
abnf Worth it
PyPI · Code Generators · released Aug 2026

Generates parsers from ABNF grammars as specified in RFC 5234 and RFC 7405, with 30+ built-in grammar modules for common RFCs like HTTP headers, email addresses, and URIs.

Install it if you need to parse or validate structured text defined by RFCs or custom ABNF grammars.

MITpure Python · 3.10+
1.1Mdownloads / mo

See also quickjs-ng · quickjs · dukpy · langchain-quickjs · mini-racer · py-mini-racer · Js2Py-3.13 · Js2Py · jsii