WebOb
WSGI request and response object
Decision gist · record as of 2026-08-14
Yes. WebOb is a stable, actively maintained library with low install friction and permissive licensing. Recent security fixes demonstrate ongoing attention to correctness. Install it if you're building or working with WSGI applications and need convenient request/response handling—it's a standard choice in the Python web ecosystem.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires legacy-cgi on Python 3.13+; verify availability in your target environment.
- Low install friction with a single pure-Python wheel dependency.
- Actively maintained with recent security fixes; status is active and latest release was 12 days ago.
License · maintenance · safety
MIT (permissive) — MIT license is permissive, allowing commercial and private use with minimal restrictions.
last release 2026-08-02 (12 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 6,426,596 downloads/mo, #1,913 on PyPI
Alternatives
Verify before relying
pip install webob
from webob import Request, Response
req = Request.blank('/path')
resp = Response('Hello World')
resp.headers['Content-Type'] = 'text/plain'- Whether Python 2.7 support is still practical given its EOL status and whether the package's actual test coverage reflects modern Python versions.
- Current state of the legacy-cgi dependency for Python 3.13+ and whether it introduces any compatibility concerns.
What it is and what it does
WebOb is a mature library that wraps WSGI request environments and response objects to provide a more convenient interface for HTTP handling. It lets you read and write request and response data—parsing headers, query strings, cookies, and form data—without directly manipulating the raw WSGI environ dictionary. The library is bidirectional: you can use it to parse incoming HTTP requests or to construct outgoing responses, making it useful both in WSGI applications and for creating HTTP requests programmatically.
The package is actively maintained by the Pylons Project and has recently addressed multiple security issues related to URL handling and open redirects. It supports a range of Python versions and is designed to work with any WSGI-compliant framework or middleware.
Use it for
- Parse HTTP request headers, query parameters, and form data in a WSGI application without manual environ manipulation.
- Construct HTTP responses with proper headers, cookies, and content negotiation in web frameworks.
- Build HTTP requests programmatically for testing or client-side use.
- Handle cookie management and SameSite attribute configuration in web applications.
- Normalize and validate Location headers in redirect responses to prevent open redirect vulnerabilities.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
WebOb is a stable, actively maintained library with low install friction and permissive licensing. Recent security fixes demonstrate ongoing attention to correctness. Install it if you're building or working with WSGI applications and need convenient request/response handling—it's a standard choice in the Python web ecosystem.
Install
webob on PyPI
Before you install
Low install friction with a single pure-Python wheel dependency. Actively maintained with recent security fixes; status is active and latest release was 12 days ago.
Requires legacy-cgi on Python 3.13+; verify availability in your target environment.
License in practice
MIT license is permissive, allowing commercial and private use with minimal restrictions.
Quickstart
pip install webob
from webob import Request, Response
req = Request.blank('/path')
resp = Response('Hello World')
resp.headers['Content-Type'] = 'text/plain'
Verify before relying
- Whether Python 2.7 support is still practical given its EOL status and whether the package's actual test coverage reflects modern Python versions.
- Current state of the legacy-cgi dependency for Python 3.13+ and whether it introduces any compatibility concerns.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release !=3.0.*,!=3.1.*,!=3.2.*,>=2.7 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagelegacy-cgi |
| Maintenance | Actively maintained 12 days since the last release |
| First released | |
| Downloads | 6,426,596 / month, #1,913 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 6 - MatureIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 2.7Programming Language :: Python :: 3.4Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Internet :: WWW/HTTP :: WSGITopic :: Internet :: WWW/HTTP :: WSGI :: ApplicationTopic :: Internet :: WWW/HTTP :: WSGI :: Middleware |
Evidence: webob-1.8.11-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “wsgi request response objects”
- WebObWebOb provides request and response objects that wrap WSGI…
- WerkzeugWerkzeug is a WSGI utility library providing request/response…
- oslo.middlewareoslo.middleware provides WSGI middleware components for intercepting…
Give your agent the search over MCP, or paste the wish link into any chat.
More WSGI packages
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.
Gunicorn is a WSGI and ASGI HTTP server for Unix that runs Python web applications with a pre-fork worker model, supporting frameworks like Django, Flask, FastAPI, and Starlette.
Install it if you are deploying a WSGI or ASGI application to production on Unix.
Django is a high-level Python web framework for building database-backed web applications with an integrated ORM, admin interface, and form handling.
Install it if you are building a web application that needs ORM, admin interface, authentication, or form handling.
Flask-WTF integrates WTForms with Flask to handle form rendering, validation, and CSRF protection in web applications.
Install it if you are building forms in Flask.
Flask-Session adds server-side session storage to Flask applications, supporting multiple backends including Redis, Memcached, FileSystem, MongoDB, and SQLAlchemy.
However, the aging maintenance status means you should verify compatibility with your target Flask and Python versions before committing to production use.
See also Paste · peppercorn · WSGIProxy2 · pyramid · cookies · django-cors-headers · repoze.who · PasteDeploy · apig-wsgi · oslo.middleware