$npx skillfedfor your agent

requests-hardened

A library that overrides the default behaviors of the requests library, and adds new security features.

With conditionsPyPI SecurityReleased Jul 2026190.4K downloads / moBSD-3-ClausePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — requests_hardened-1.3.0-py3-none-any.whl
v1.3.0 · released 2026-07-14 · Python >=3.10 · 1 runtime deps: requests

Yes, if you make HTTP requests based on untrusted user input or need to enforce consistent security defaults across your application. The single dependency on requests, active maintenance, permissive license, and zero known vulnerabilities make it a low-risk addition. Install it if SSRF protection or global timeout/redirect policies matter for your threat model; skip it if your requests are fully trusted or you handle these concerns elsewhere.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • For SOCKS4/SOCKS5 proxy support, requires pip install requests[socks].
  • Low install friction with a single runtime dependency on requests.

License · maintenance · safety

BSD-3-Clause (permissive) — BSD-3-Clause permissive license allows commercial and private use with minimal restrictions.

last release 2026-07-14 (31 days) · last repo commit 2026-08-10 · 12 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 190,369 downloads/mo, #9,913 on PyPI

Verify before relying

pip install requests-hardened

from requests_hardened import Config, Manager

http_manager = Manager(
    Config(
        default_timeout=(2, 10),
        ip_filter_enable=True,
        ip_filter_allow_loopback_ips=False
    )
)
resp = http_manager.send_request("GET", "https://example.com")
  • Whether SSRF filtering covers all edge cases in URL parsing or DNS rebinding attacks.
  • Performance overhead of IP filtering on high-throughput HTTP clients.
  • Compatibility with requests library versions beyond the tested range.
Same gist for agents: .md · .json

What it is and what it does

requests-hardened is a security-focused wrapper around the requests library that applies hardened defaults and adds SSRF protection. It lets you configure global security policies like enforcing request timeouts, disabling redirects, and filtering outbound requests to private IP ranges—preventing server-side request forgery attacks where untrusted user input could be used to probe internal infrastructure.

The library works by wrapping requests.Session and intercepting HTTP calls through a Manager and Config object. You set security policies once (timeout, redirect behavior, SSRF filtering rules) and then use the manager to send requests or get sessions, ensuring those policies apply consistently. It supports proxies including SOCKS4/SOCKS5, and the SSRF filter can be tuned to allow or block loopback addresses depending on your threat model.

Use it for

  • Protect web applications that make HTTP requests based on user input from SSRF attacks by filtering private IP ranges.
  • Enforce organization-wide HTTP client security policies like mandatory request timeouts and disabled redirects across multiple services.
  • Build secure API clients that reject redirects and enforce User-Agent headers to prevent header injection or redirect-based attacks.
  • Combine with proxy configurations for defense-in-depth, filtering tunneled requests while trusting the proxy itself.
  • Harden microservices that call internal APIs to prevent attackers from pivoting through HTTP requests to localhost or private networks.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you make HTTP requests based on untrusted user input or need to enforce consistent security defaults across your application.

The single dependency on requests, active maintenance, permissive license, and zero known vulnerabilities make it a low-risk addition. Install it if SSRF protection or global timeout/redirect policies matter for your threat model; skip it if your requests are fully trusted or you handle these concerns elsewhere.

Install

requests-hardened on PyPI

Before you install

Low install friction with a single runtime dependency on requests. Active maintenance with a recent release 31 days ago and a commit from 2026-08-10.

Requires Python 3.10 or later. For SOCKS4/SOCKS5 proxy support, requires pip install requests[socks].

License in practice

BSD-3-Clause permissive license allows commercial and private use with minimal restrictions.

Quickstart

pip install requests-hardened

from requests_hardened import Config, Manager

http_manager = Manager(
    Config(
        default_timeout=(2, 10),
        ip_filter_enable=True,
        ip_filter_allow_loopback_ips=False
    )
)
resp = http_manager.send_request("GET", "https://example.com")

Verify before relying

  • Whether SSRF filtering covers all edge cases in URL parsing or DNS rebinding attacks.
  • Performance overhead of IP filtering on high-throughput HTTP clients.
  • Compatibility with requests library versions beyond the tested range.

Package facts

LicenseBSD-3-Clause permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
requests
MaintenanceActively maintained 31 days since the last release
Last repo commit
First released
Downloads190,369 / month, #9,913 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseNatural Language :: EnglishOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: POSIXOperating System :: POSIX :: BSDOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Security

Evidence: requests_hardened-1.3.0-py3-none-any.whl

Tags

Capabilities
ssrf filter requestsrequests security hardeningblock private ip addresses httpsecure http client defaultsrequests library security wrapper
Topics
ssrf-protectionhttp-securityrequests-wrapper

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ssrf filter requests”

  • requests-hardenedWraps the requests library to enforce security defaults and block…
  • advocateAdvocate wraps the requests library to prevent SSRF attacks by…
  • safehttpxWraps httpx.AsyncClient.get() with DNS validation and DNS rebinding…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also advocate · safehttpx · wrapper-tls-requests · redfish · django-xff · requests-ntlm2 · PySocks · requests-mock · pproxy · requests-ntlm3