rsa
Pure-Python RSA implementation
Decision gist · record as of 2026-08-14
No, unless you are maintaining legacy code that already depends on it. The project is archived and abandoned with no active maintenance. The maintainer explicitly warns against taking over the project due to security risks. For new projects, seek a maintained alternative. If you must use this, understand the timing-attack vulnerability and do not rely on it for security-sensitive operations.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Pure-Python implementation is vulnerable to timing attacks; the description notes it is very hard (if not impossible) to make a pure-Python program secure against them.
- Do not use for security-critical applications where timing side-channels are a concern.
- Low install friction with a single runtime dependency (pyasn1).
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache License 2.0 (permissive). You may use, modify, and distribute this code freely, including in commercial projects, provided you include the license notice.
last release 2025-04-16 (485 days) · last repo commit 2025-04-16 · 489 stars · archived
0 known vulnerabilities (OSV.dev, 2026-08-14) · 299,583,903 downloads/mo, #138 on PyPI
Alternatives
Verify before relying
pip install rsa
import rsa
(pubkey, privkey) = rsa.newkeys()
ciphertext = rsa.encrypt(b'hello', pubkey)
message = rsa.decrypt(ciphertext, privkey)- Whether unreleased improvements mentioned in the description have security implications that would affect current use.
- Current real-world security audit status or known vulnerabilities not yet tracked in OSV.
- Whether any active fork or maintained alternative is recommended by the community.
What it is and what it does
Python-RSA is a pure-Python implementation of RSA cryptography that provides encryption, decryption, digital signing, signature verification, and key generation according to PKCS#1 version 1.5. It works as both a Python library and a command-line tool, supporting Python 3.6 through 3.13 on CPython and PyPy.
The project is archived and abandoned by its original maintainer, who explicitly states they lack the time and capacity to maintain it properly. The repository shows no recent activity, and the maintainer does not feel comfortable transferring ownership due to the library's use in high-profile projects. The description warns that pure-Python RSA is inherently vulnerable to timing attacks and should not be used where timing side-channels are a security concern.
Use it for
- Educational projects learning RSA cryptography and PKCS#1 standards without external C dependencies.
- Legacy systems already depending on this library where migration is not feasible.
- Non-security-critical applications needing basic RSA operations in pure Python.
- Command-line RSA key generation and encryption/decryption tasks in environments without compiled crypto libraries.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No, unless you are maintaining legacy code that already depends on it.
The project is archived and abandoned with no active maintenance. The maintainer explicitly warns against taking over the project due to security risks. For new projects, seek a maintained alternative. If you must use this, understand the timing-attack vulnerability and do not rely on it for security-sensitive operations.
Install
rsa on PyPI
Before you install
Low install friction with a single runtime dependency (pyasn1). However, the project is archived and abandoned—the maintainer explicitly states they lack time to maintain it and do not feel comfortable handing it over. No commits or activity for an extended period. Use only if you have no alternative.
Pure-Python implementation is vulnerable to timing attacks; the description notes it is very hard (if not impossible) to make a pure-Python program secure against them. Do not use for security-critical applications where timing side-channels are a concern.
License in practice
Licensed under Apache License 2.0 (permissive). You may use, modify, and distribute this code freely, including in commercial projects, provided you include the license notice.
Quickstart
pip install rsa
import rsa
(pubkey, privkey) = rsa.newkeys()
ciphertext = rsa.encrypt(b'hello', pubkey)
message = rsa.decrypt(ciphertext, privkey)
Verify before relying
- Whether unreleased improvements mentioned in the description have security implications that would affect current use.
- Current real-world security audit status or known vulnerabilities not yet tracked in OSV.
- Whether any active fork or maintained alternative is recommended by the community.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release <4,>=3.6 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagepyasn1 |
| Maintenance | Abandoned 485 days since the last release |
| Last repo commit | repository archived |
| First released | |
| Downloads | 299,583,903 / month, #138 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersIntended Audience :: EducationIntended Audience :: Information TechnologyLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Security :: Cryptography |
Evidence: rsa-4.9.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “RSA encryption decryption python”
- rsaPure-Python RSA encryption, decryption, signing, and key generation…
- PGPy13PGPy13 is a Python library for OpenPGP encryption, decryption, and…
- PGPyPGPy implements OpenPGP (RFC 4880) in pure Python, enabling you to…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
Keyring provides safe password and credential storage by interfacing with the system's native credential manager (macOS Keychain, Windows Credential Locker, Freedesktop Secret Service, or KDE KWallet).
Install it if your application needs to store or retrieve passwords securely without managing encryption yourself.
See also gmssl · PGPy · python-gnupg · PGPy13 · pysequoia · python-jose · oscrypto · asn1crypto · sslcrypto