$npx skillfedfor your agent

sslyze

Fast and powerful SSL/TLS scanning library.

With conditionsPyPI MonitoringReleased Mar 2026127.1K downloads / moAGPLSource build

Decision gist · record as of 2026-08-14

sdist only — sslyze-6.3.1.tar.gz · builds from source
v6.3.1 · released 2026-03-29 · Python >=3.10 · 4 runtime deps: nassl, cryptography, tls-parser, pydantic

Yes, with conditions. SSLyze is actively maintained, has no known vulnerabilities, and is well-suited for TLS auditing and compliance checking. However, the AGPL license is restrictive—proprietary projects must either accept copyleft obligations or avoid it. High install friction (native dependencies) may complicate deployment in some environments. Install if you need TLS scanning and can accept AGPL terms.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Native compilation dependencies (nassl, cryptography) must build successfully on your platform.
  • High install friction due to compiled dependencies (nassl, cryptography, tls-parser).

License · maintenance · safety

AGPL (agpl) — SSLyze is licensed under AGPL, which requires that any modifications or derivative works using this library must also be released under AGPL. This is a copyleft license with strong reciprocal obligations; proprietary or closed-source projects should verify compatibility before depending on it.

last release 2026-03-29 (138 days) · last repo commit 2026-07-29 · 3,770 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 127,082 downloads/mo, #11,754 on PyPI

Verify before relying

pip install sslyze
python -m sslyze www.example.com

# Or via Python API:
from sslyze import ServerScanRequest, Scanner
request = ServerScanRequest(hostname="www.example.com")
scanner = Scanner()
results = scanner.run(request)
  • Whether the AGPL license applies to indirect use (e.g., calling sslyze from a web service) and what derivative-work obligations that triggers
  • Performance characteristics when scanning hundreds of thousands of servers as claimed in the description
Same gist for agents: .md · .json

What it is and what it does

SSLyze is a Python library and command-line tool for analyzing the SSL/TLS configuration of remote servers. It connects to a server, inspects its certificate, supported cipher suites, protocol versions, and elliptic curves, then reports on encryption strength and known vulnerabilities like Heartbleed, ROBOT, and OpenSSL CCS injection. It supports scanning non-HTTP servers including SMTP, XMPP, LDAP, POP, IMAP, RDP, Postgres, and FTP.

The tool is designed for both one-off security audits and continuous compliance checking. It can validate server configurations against Mozilla's recommended TLS profiles (old, intermediate, modern) or custom JSON-defined policies, making it suitable for CI/CD integration. Results can be exported to JSON for further processing. The library exposes a full Python API for embedding scans into applications, such as Lambda functions or custom security tools.

Use it for

  • Audit a web server's TLS configuration to identify weak ciphers or outdated protocol versions before deployment.
  • Run SSLyze as a CI/CD step to enforce Mozilla's modern TLS configuration and fail builds that don't comply.
  • Scan SMTP or LDAP servers to verify they support strong encryption and are not vulnerable to known attacks.
  • Build a security monitoring dashboard that periodically scans your organization's servers and exports results to JSON for alerting.
  • Test a custom TLS policy by defining allowed certificate types, cipher suites, and versions in a JSON file and validating servers against it.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, with conditions.

SSLyze is actively maintained, has no known vulnerabilities, and is well-suited for TLS auditing and compliance checking. However, the AGPL license is restrictive—proprietary projects must either accept copyleft obligations or avoid it. High install friction (native dependencies) may complicate deployment in some environments. Install if you need TLS scanning and can accept AGPL terms.

Install

sslyze on PyPI

Before you install

High install friction due to compiled dependencies (nassl, cryptography, tls-parser). The package is actively maintained with recent releases and a stable repository, but setup requires building native extensions.

Requires Python 3.10 or later. Native compilation dependencies (nassl, cryptography) must build successfully on your platform.

License in practice

SSLyze is licensed under AGPL, which requires that any modifications or derivative works using this library must also be released under AGPL. This is a copyleft license with strong reciprocal obligations; proprietary or closed-source projects should verify compatibility before depending on it.

Quickstart

pip install sslyze
python -m sslyze www.example.com

# Or via Python API:
from sslyze import ServerScanRequest, Scanner
request = ServerScanRequest(hostname="www.example.com")
scanner = Scanner()
results = scanner.run(request)

Verify before relying

  • Whether the AGPL license applies to indirect use (e.g., calling sslyze from a web service) and what derivative-work obligations that triggers
  • Performance characteristics when scanning hundreds of thousands of servers as claimed in the description

Package facts

LicenseAGPL agpl
Python supportSupports the current Python release >=3.10
Install frictionHigh. Source build required
Runtime dependencies
4 packages
nasslcryptographytls-parserpydantic
MaintenanceActively maintained 138 days since the last release
Last repo commit
First released
Downloads127,082 / month, #11,754 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersIntended Audience :: System AdministratorsLicense :: OSI Approved :: GNU Affero General Public License v3Natural Language :: FrenchProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: SecurityTopic :: System :: MonitoringTopic :: System :: NetworkingTopic :: System :: Networking :: Monitoring

Evidence: sslyze-6.3.1.tar.gz

Tags

Capabilities
ssl tls certificate scanningtls configuration auditssl vulnerability testingcipher suite analysisssl compliance checkingtls security assessmentcertificate validation tool
Topics
tls-auditcompliance-checkingcryptography
PyPI keywords
ssltlsscansecuritylibrary

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ssl tls certificate scanning”

  • sslyzeSSLyze is a fast SSL/TLS scanning tool and Python library that…
  • tlslite-ngPure Python implementation of SSL/TLS protocols (SSLv3.0, TLS…
  • pyOpenSSLpyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing…

Give your agent the search over MCP, or paste the wish link into any chat.

More Monitoring packages

tqdm Worth it
PyPI · Libraries · released Jul 2026

Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.

copyleftpure Python · 3.8+
648.6Mdownloads / mo
opentelemetry-semantic-conventions Worth it
PyPI · Monitoring · released Jul 2026

Provides generated Python code for OpenTelemetry semantic conventions, enabling standardized attribute naming and constant definitions for instrumentation and telemetry collection.

Install it if you are using OpenTelemetry and want to follow semantic conventions correctly.

Apache-2.0pure Python · 3.10+
542.9Mdownloads / mo
opentelemetry-sdk Worth it
PyPI · Monitoring · released Jul 2026

Provides the reference implementation of the OpenTelemetry API for collecting and exporting traces, metrics, and logs from Python applications.

Apache-2.0pure Python · 3.10+
521.8Mdownloads / mo
opentelemetry-api With conditions
PyPI · Monitoring · released Jul 2026

Provides the abstract API and interfaces for OpenTelemetry instrumentation in Python, defining how to emit traces, metrics, and logs without tying code to a specific SDK implementation.

Apache-2.0pure Python · 3.10+
463.8Mdownloads / mo
opentelemetry-exporter-otlp-proto-http Worth it
PyPI · Monitoring · released Jul 2026

Exports OpenTelemetry observability data to an OpenTelemetry Collector using Protobuf-encoded messages over HTTP.

Install it if you are using OpenTelemetry in Python and need to send data to a Collector over HTTP.

Apache-2.0pure Python · 3.10+
409.9Mdownloads / mo
opentelemetry-instrumentation Worth it
PyPI · Monitoring · released Jul 2026

Provides automatic instrumentation commands and programmatic APIs to inject distributed tracing into Python applications without code changes, detecting and instrumenting packages used by your program.

Install it if you need distributed tracing without code changes and have compatible instrumented packages in your environment.

Apache-2.0pure Python · 3.10+
393.5Mdownloads / mo

See also nassl · tls-parser · secure-smtplib · django-sslserver · oscrypto · pip-system-certs · python-certifi-win32 · trustme · pyOpenSSL · python-nmap