$npx skillfedfor your agent

secure

A lightweight package that adds security headers for Python web frameworks.

Worth itPyPI LibrariesReleased Apr 20262.1M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — secure-2.0.1-py3-none-any.whl
v2.0.1 · released 2026-04-22 · Python >=3.10

Yes. Secure solves a real problem—header policy drift in web applications—with zero dependencies, active maintenance, and a clean API. The MIT license and support for current Python versions (3.10+) make it a low-risk addition. Install it if you manage HTTP security headers in any Python web framework; the preset defaults are sensible and the builder API scales to custom policies.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Low friction: zero runtime dependencies, pure Python wheel, requires Python 3.10+.
  • Active maintenance with recent release (114 days ago) and 1049 repository stars.

License · maintenance · safety

MIT (permissive) — MIT license permits unrestricted use, modification, and distribution in both open-source and proprietary projects with minimal obligations.

last release 2026-04-22 (114 days) · last repo commit 2026-07-23 · 1,049 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 2,109,290 downloads/mo, #3,289 on PyPI

Verify before relying

pip install secure

from secure import Secure
from secure.middleware import SecureASGIMiddleware

secure_headers = Secure.with_default_headers()
# Apply via app.add_middleware(SecureASGIMiddleware, secure=secure_headers)
  • Whether the package's header policies align with current OWASP or industry security recommendations.
  • Performance overhead of header application at scale or in high-throughput scenarios.
  • Coverage of emerging security headers beyond the three preset tiers.
Same gist for agents: .md · .json

What it is and what it does

Secure centralizes HTTP security header management for Python web applications, replacing ad hoc header strings scattered across routes and middleware. Instead of copying header policy into view code, you configure one Secure instance with an opinionated preset (BALANCED, BASIC, or STRICT) and apply it consistently across all responses. The package handles Content-Security-Policy, Strict-Transport-Security, referrer policy, permissions policy, and browser protection headers.

It supports both synchronous and asynchronous response objects through a small public API and typed builders for custom policies. Middleware integrations for WSGI and ASGI let you apply headers app-wide rather than per-route. The package has no external dependencies and is fully typed, making it straightforward to integrate into existing frameworks.

Use it for

  • Apply HSTS, CSP, and referrer policies consistently across a web application via middleware.
  • Tune specific security headers for compliance or hardening without rewriting header strings in every route.
  • Start with BALANCED preset for a modern baseline and upgrade to STRICT when deploying a high-security application.
  • Validate and normalize dynamically composed headers before emission to catch policy drift.
  • Migrate legacy applications from ad hoc header code to a centralized, maintainable policy object.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Secure solves a real problem—header policy drift in web applications—with zero dependencies, active maintenance, and a clean API. The MIT license and support for current Python versions (3.10+) make it a low-risk addition. Install it if you manage HTTP security headers in any Python web framework; the preset defaults are sensible and the builder API scales to custom policies.

Install

secure on PyPI

Before you install

Low friction: zero runtime dependencies, pure Python wheel, requires Python 3.10+. Active maintenance with recent release (114 days ago) and 1049 repository stars.

Requires Python 3.10 or later.

License in practice

MIT license permits unrestricted use, modification, and distribution in both open-source and proprietary projects with minimal obligations.

Quickstart

pip install secure

from secure import Secure
from secure.middleware import SecureASGIMiddleware

secure_headers = Secure.with_default_headers()
# Apply via app.add_middleware(SecureASGIMiddleware, secure=secure_headers)

Verify before relying

  • Whether the package's header policies align with current OWASP or industry security recommendations.
  • Performance overhead of header application at scale or in high-throughput scenarios.
  • Coverage of emerging security headers beyond the three preset tiers.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 114 days since the last release
Last repo commit
First released
Downloads2,109,290 / month, #3,289 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Software Development :: LibrariesTyping :: Typed

Evidence: secure-2.0.1-py3-none-any.whl

Tags

Capabilities
HTTP security headers PythonHSTS CSP middlewareweb security headers frameworksecure response headerssecurity headers middlewareWSGI ASGI middleware securitycontent security policy builder
Topics
security-headersmiddlewareweb-framework
PyPI keywords
securityheaderswebframeworkHTTP

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “HTTP security headers Python”

  • secureApplies HTTP security headers to Python web responses through a…
  • flask-talismanFlask extension that automatically sets HTTP security headers to…
  • SecwebSecweb applies security headers (CSP, HSTS, X-Frame-Options, and 13…

Give your agent the search over MCP, or paste the wish link into any chat.

More Libraries packages

urllib3 Worth it
PyPI · Libraries · released May 2026

urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.

MITpure Python · 3.10+
1.8Bdownloads / mo
requests Worth it
PyPI · Libraries · released May 2026

Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.

Apache-2.0pure Python · 3.10+
1.8Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
python-dateutil Worth it
PyPI · Libraries · released Mar 2024

Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.

Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.

Apache-2.0pure Python
1.2Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo
pytest Worth it
PyPI · Libraries · released Jun 2026

pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.

MITpure Python · 3.10+
1.1Bdownloads / mo

See also django-csp · flask-talisman · hstspreload · Secweb · django-permissions-policy · asgi-csrf · starlette-csrf · piccolo-api · fastapi-csrf-protect · zope.security