twofish
Bindings for the Twofish implementation by Niels Ferguson
Decision gist · record as of 2026-08-14
No. The package is abandoned, unmaintained since 2013, and documented only for end-of-life Python versions (2.6–3.3). Modern Python compatibility is unverified. High install friction (compiled C extension + system library) and the explicit warning that it requires external cipher-mode wrapping make it unsuitable for new projects. Use a maintained cryptography library like cryptography or PyCryptodome instead.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires libtwofish-dev system library installed; high compilation friction.
- Designed for Python 2.6–3.3; compatibility with modern Python versions is unverified.
- High install friction: the package requires a compiled C extension and the libtwofish-dev system library.
License · maintenance · safety
3-clause BSD (permissive) — Licensed under 3-clause BSD (permissive), allowing commercial and private use with attribution and liability disclaimer. No restrictions on redistribution or modification.
last release 2013-11-15 (4655 days) · last repo commit 2022-02-27 · 28 stars · archived
0 known vulnerabilities (OSV.dev, 2026-08-14) · 462,586 downloads/mo, #6,525 on PyPI
Alternatives
Verify before relying
pip install twofish
from twofish import Twofish
T = Twofish(b'*secret*')
encrypted = T.encrypt(b'YELLOWSUBMARINES')
decrypted = T.decrypt(encrypted)- Whether the package compiles and runs on Python 3.8 or later (only 3.3 is documented)
- Current status of the underlying Niels Ferguson Twofish implementation and any known cryptographic weaknesses
- Whether libtwofish-dev is available in current Linux distributions or requires manual installation
What it is and what it does
Twofish is a Python wrapper around the Twofish block cipher, a symmetric encryption algorithm designed by Niels Ferguson. It exposes a simple API: create a Twofish instance with a binary key (0–32 bytes), then call encrypt() and decrypt() on 16-byte blocks. The library performs a self-test on import to verify the underlying C implementation.
This is a low-level cryptographic primitive, not a complete cipher system. The documentation explicitly warns that it must be used within a proper cipher mode (CTR, CBC, etc.) to be secure; using it directly on plaintext is cryptographically unsafe. The package is unmaintained since 2013 and archived, with no support for modern Python versions beyond 3.3.
Use it for
- Legacy system integration where Twofish is mandated by existing protocols or data formats
- Educational exploration of block cipher mechanics and symmetric encryption primitives
- Decryption of historical data encrypted with Twofish in a supported cipher mode
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
The package is abandoned, unmaintained since 2013, and documented only for end-of-life Python versions (2.6–3.3). Modern Python compatibility is unverified. High install friction (compiled C extension + system library) and the explicit warning that it requires external cipher-mode wrapping make it unsuitable for new projects. Use a maintained cryptography library like cryptography or PyCryptodome instead.
Install
twofish on PyPI
Before you install
High install friction: the package requires a compiled C extension and the libtwofish-dev system library. The project is archived and unmaintained since 2013, with no updates for over a decade. Compatibility claims are limited to Python 2.6, 2.7, and 3.3—all end-of-life versions.
Requires libtwofish-dev system library installed; high compilation friction. Designed for Python 2.6–3.3; compatibility with modern Python versions is unverified.
License in practice
Licensed under 3-clause BSD (permissive), allowing commercial and private use with attribution and liability disclaimer. No restrictions on redistribution or modification.
Quickstart
pip install twofish
from twofish import Twofish
T = Twofish(b'*secret*')
encrypted = T.encrypt(b'YELLOWSUBMARINES')
decrypted = T.decrypt(encrypted)
Verify before relying
- Whether the package compiles and runs on Python 3.8 or later (only 3.3 is documented)
- Current status of the underlying Niels Ferguson Twofish implementation and any known cryptographic weaknesses
- Whether libtwofish-dev is available in current Linux distributions or requires manual installation
Package facts
| License | 3-clause BSD permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Abandoned 4,655 days since the last release |
| Last repo commit | repository archived |
| First released | |
| Downloads | 462,586 / month, #6,525 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseProgramming Language :: Python :: 2.6Programming Language :: Python :: 2.7Programming Language :: Python :: 3.3Topic :: Security :: CryptographyTopic :: Software Development :: Libraries |
Evidence: twofish-0.3.0.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “twofish encryption python”
- twofishProvides Python bindings to the Twofish block cipher for encrypting…
- pyragepyrage provides Python bindings to the Rust implementation of age,…
- eciespyEncrypts and decrypts data using Elliptic Curve Integrated Encryption…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also xxtea · pyDes · pyaes · pyAesCrypt · pyscrypt · py3rijndael · pyrage · aes-pkcs5 · pqcrypto · kasa-crypt