vt-py
The official Python client library for VirusTotal
Decision gist · record as of 2026-08-14
Yes, if you need to integrate VirusTotal scanning into Python workflows. The library is official, has low install friction, carries a permissive license, and has no known vulnerabilities. The aging maintenance status (290 days since last release) is a minor concern but does not block adoption for stable API use; monitor the repository for any breaking changes to the VirusTotal REST API v3.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a valid VirusTotal API key; async/await syntax requires Python 3.7+.
- Low install friction with only two async runtime dependencies (aiohttp, aiofiles).
- Maintenance status is aging—last commit was 2025-10-28 and the package has not seen a release in 290 days, though the repository remains active and not archived.
License · maintenance · safety
Apache 2 (permissive) — Licensed under Apache 2 (permissive), allowing use in most commercial and open-source projects without significant restriction.
last release 2025-10-28 (290 days) · last repo commit 2025-10-28 · 772 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 524,403 downloads/mo, #6,189 on PyPI
Alternatives
Verify before relying
pip install vt-py
import vt
async with vt.Client(api_key='your-api-key') as client:
file = await client.get_object('/files/{file_hash}')- Whether the 290-day release gap signals maintenance concerns or reflects API stability.
- Real-world performance characteristics with large-scale file or URL submissions.
- Scope and completeness of VirusTotal Intelligence and Retrohunt features relative to the REST API v3.
What it is and what it does
vt-py is the official Python wrapper around VirusTotal's REST API v3, a cloud-based malware and security threat detection service. It abstracts HTTP communication and authentication, letting you submit files and URLs for scanning, retrieve threat analysis results, search threat intelligence databases, manage LiveHunt detection rules, and run retroactive hunts across VirusTotal's file corpus—all from Python code.
The library uses async I/O (aiohttp, aiofiles) to handle concurrent requests efficiently. It targets Python 3.7 and later, installs with minimal friction, and is maintained by VirusTotal itself, though recent releases have slowed. It's suitable for security teams, malware researchers, and developers integrating threat detection into larger workflows.
Use it for
- Automate malware scanning of files and URLs in security pipelines or incident response workflows.
- Query VirusTotal Intelligence to research file hashes, domains, or IPs for threat analysis.
- Build custom detection rules with LiveHunt and retrieve matches programmatically.
- Integrate threat detection into CI/CD or endpoint protection systems.
- Run retroactive hunts across VirusTotal's file corpus to find samples matching custom criteria.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to integrate VirusTotal scanning into Python workflows.
The library is official, has low install friction, carries a permissive license, and has no known vulnerabilities. The aging maintenance status (290 days since last release) is a minor concern but does not block adoption for stable API use; monitor the repository for any breaking changes to the VirusTotal REST API v3.
Install
vt-py on PyPI
Before you install
Low install friction with only two async runtime dependencies (aiohttp, aiofiles). Maintenance status is aging—last commit was 2025-10-28 and the package has not seen a release in 290 days, though the repository remains active and not archived.
Requires a valid VirusTotal API key; async/await syntax requires Python 3.7+.
License in practice
Licensed under Apache 2 (permissive), allowing use in most commercial and open-source projects without significant restriction.
Quickstart
pip install vt-py
import vt
async with vt.Client(api_key='your-api-key') as client:
file = await client.get_object('/files/{file_hash}')
Verify before relying
- Whether the 290-day release gap signals maintenance concerns or reflects API stability.
- Real-world performance characteristics with large-scale file or URL submissions.
- Scope and completeness of VirusTotal Intelligence and Retrohunt features relative to the REST API v3.
Package facts
| License | Apache 2 permissive |
| Python support | Supports the current Python release >=3.7.0 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesaiohttpaiofiles |
| Maintenance | Aging 290 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 524,403 / month, #6,189 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3 |
Evidence: vt_py-0.22.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “file and url scanning”
- vt-pyOfficial Python client for the VirusTotal REST API v3, enabling file…
- virustotal3Provides a Python 3 client library for the VirusTotal v3 REST API,…
- pyfaup-rsParses URLs into components (scheme, host, port, path, query,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also virustotal3 · OTXv2 · pyClamd · pymisp · pycti · clamd · alibabacloud-sas20181203 · pygitguardian · domaintools-api · assemblyline-ui