secure
A lightweight package that adds security headers for Python web frameworks.
Decision gist · record as of 2026-08-14
Yes. Secure solves a real problem—header policy drift in web applications—with zero dependencies, active maintenance, and a clean API. The MIT license and support for current Python versions (3.10+) make it a low-risk addition. Install it if you manage HTTP security headers in any Python web framework; the preset defaults are sensible and the builder API scales to custom policies.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Low friction: zero runtime dependencies, pure Python wheel, requires Python 3.10+.
- Active maintenance with recent release (114 days ago) and 1049 repository stars.
License · maintenance · safety
MIT (permissive) — MIT license permits unrestricted use, modification, and distribution in both open-source and proprietary projects with minimal obligations.
last release 2026-04-22 (114 days) · last repo commit 2026-07-23 · 1,049 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 2,109,290 downloads/mo, #3,289 on PyPI
Alternatives
Verify before relying
pip install secure
from secure import Secure
from secure.middleware import SecureASGIMiddleware
secure_headers = Secure.with_default_headers()
# Apply via app.add_middleware(SecureASGIMiddleware, secure=secure_headers)- Whether the package's header policies align with current OWASP or industry security recommendations.
- Performance overhead of header application at scale or in high-throughput scenarios.
- Coverage of emerging security headers beyond the three preset tiers.
What it is and what it does
Secure centralizes HTTP security header management for Python web applications, replacing ad hoc header strings scattered across routes and middleware. Instead of copying header policy into view code, you configure one Secure instance with an opinionated preset (BALANCED, BASIC, or STRICT) and apply it consistently across all responses. The package handles Content-Security-Policy, Strict-Transport-Security, referrer policy, permissions policy, and browser protection headers.
It supports both synchronous and asynchronous response objects through a small public API and typed builders for custom policies. Middleware integrations for WSGI and ASGI let you apply headers app-wide rather than per-route. The package has no external dependencies and is fully typed, making it straightforward to integrate into existing frameworks.
Use it for
- Apply HSTS, CSP, and referrer policies consistently across a web application via middleware.
- Tune specific security headers for compliance or hardening without rewriting header strings in every route.
- Start with BALANCED preset for a modern baseline and upgrade to STRICT when deploying a high-security application.
- Validate and normalize dynamically composed headers before emission to catch policy drift.
- Migrate legacy applications from ad hoc header code to a centralized, maintainable policy object.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Secure solves a real problem—header policy drift in web applications—with zero dependencies, active maintenance, and a clean API. The MIT license and support for current Python versions (3.10+) make it a low-risk addition. Install it if you manage HTTP security headers in any Python web framework; the preset defaults are sensible and the builder API scales to custom policies.
Install
secure on PyPI
Before you install
Low friction: zero runtime dependencies, pure Python wheel, requires Python 3.10+. Active maintenance with recent release (114 days ago) and 1049 repository stars.
Requires Python 3.10 or later.
License in practice
MIT license permits unrestricted use, modification, and distribution in both open-source and proprietary projects with minimal obligations.
Quickstart
pip install secure
from secure import Secure
from secure.middleware import SecureASGIMiddleware
secure_headers = Secure.with_default_headers()
# Apply via app.add_middleware(SecureASGIMiddleware, secure=secure_headers)
Verify before relying
- Whether the package's header policies align with current OWASP or industry security recommendations.
- Performance overhead of header application at scale or in high-throughput scenarios.
- Coverage of emerging security headers beyond the three preset tiers.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 114 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 2,109,290 / month, #3,289 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Software Development :: LibrariesTyping :: Typed |
Evidence: secure-2.0.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “HTTP security headers Python”
- secureApplies HTTP security headers to Python web responses through a…
- flask-talismanFlask extension that automatically sets HTTP security headers to…
- SecwebSecweb applies security headers (CSP, HSTS, X-Frame-Options, and 13…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also django-csp · flask-talisman · hstspreload · Secweb · django-permissions-policy · asgi-csrf · starlette-csrf · piccolo-api · fastapi-csrf-protect · zope.security