zope.security
Zope Security Framework
Decision gist · record as of 2026-08-14
Yes, if you are building a Zope application or a Python system that requires declarative, policy-driven access control on objects. The framework is mature, actively maintained, and has no known vulnerabilities. However, it carries medium install friction and depends on the full Zope ecosystem, so it is best suited to projects already committed to that architecture. For simpler authorization needs or non-Zope frameworks, lighter alternatives may be more practical.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Depends on zope.component, zope.interface, zope.location, zope.proxy, zope.schema, and zope.i18nmessageid; these must be available in your environment.
- Medium install friction due to compiled wheels across multiple platforms and Python versions (3.10–3.13+).
License · maintenance · safety
ZPL-2.1 (unclear) — Licensed under ZPL-2.1 (Zope Public License 2.1), but license treatment is marked unclear in the metadata. Verify compatibility with your project's license requirements before use.
last release 2025-11-17 (270 days) · last repo commit 2026-08-14 · 6 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 197,325 downloads/mo, #9,762 on PyPI
Alternatives
Verify before relying
pip install zope.security
from zope.security.decorator import protected
from zope.security.permission import Permission
@protected(Permission('view'))
def my_protected_function():
return 'secured'- Specific security policy implementation patterns and how they integrate with non-Zope frameworks
- Performance characteristics when securing large object hierarchies
- Compatibility with async/await patterns in modern Python applications
What it is and what it does
zope.security is a declarative security framework for Python that enforces access control policies on objects through permissions and principals. It provides decorators and configuration mechanisms to protect methods and attributes, making it possible to define who can do what with your code's objects without embedding authorization logic throughout your codebase.
The package is part of the Zope ecosystem and integrates deeply with zope.interface, zope.component, and related libraries. It's designed for applications that need fine-grained, policy-driven security—particularly web frameworks and complex object systems where access control must be flexible and centrally managed. The framework has been in production use since 2007 and remains actively maintained.
Use it for
- Protect methods and attributes in Zope-based web applications with declarative permission checks
- Implement role-based access control (RBAC) where different principals have different permissions on shared objects
- Enforce security policies in content management systems or document repositories with hierarchical object structures
- Audit and control who can access or modify sensitive business logic in multi-tenant applications
- Define security rules centrally rather than scattering authorization checks throughout application code
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building a Zope application or a Python system that requires declarative, policy-driven access control on objects.
The framework is mature, actively maintained, and has no known vulnerabilities. However, it carries medium install friction and depends on the full Zope ecosystem, so it is best suited to projects already committed to that architecture. For simpler authorization needs or non-Zope frameworks, lighter alternatives may be more practical.
Install
zope-security on PyPI
Before you install
Medium install friction due to compiled wheels across multiple platforms and Python versions (3.10–3.13+). Active maintenance with recent commits; last release 270 days ago. Depends on six zope ecosystem packages, which may require additional setup in non-zope environments.
Requires Python 3.10 or later. Depends on zope.component, zope.interface, zope.location, zope.proxy, zope.schema, and zope.i18nmessageid; these must be available in your environment.
License in practice
Licensed under ZPL-2.1 (Zope Public License 2.1), but license treatment is marked unclear in the metadata. Verify compatibility with your project's license requirements before use.
Quickstart
pip install zope.security
from zope.security.decorator import protected
from zope.security.permission import Permission
@protected(Permission('view'))
def my_protected_function():
return 'secured'
Verify before relying
- Specific security policy implementation patterns and how they integrate with non-Zope frameworks
- Performance characteristics when securing large object hierarchies
- Compatibility with async/await patterns in modern Python applications
Package facts
| License | ZPL-2.1 unclear |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | 6 packageszope.componentzope.i18nmessageidzope.interfacezope.locationzope.proxyzope.schema |
| Maintenance | Actively maintained 270 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 197,325 / month, #9,762 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentFramework :: Zope :: 3Intended Audience :: DevelopersOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Internet :: WWW/HTTP |
Evidence: zope_security-8.3-cp310-cp310-macosx_10_9_x86_64.whl; zope_security-8.3-cp310-cp310-macosx_11_0_arm64.whl; zope_security-8.3-cp310-cp310-manylinux1_i686.manylinux2014_i686.manylinux_2_17_i686.manylinux_2_5_i686.whl; zope_security-8.3-cp310-cp310-manylinux1_x86_64.manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_5_x86_64.whl; zope_security-8.3-cp310-cp310-manylinux2014_aarch64.manylinux_2_17_aarch64.whl; zope_security-8.3-cp310-cp310-win_amd64.whl; zope_security-8.3-cp311-cp311-macosx_10_9_x86_64.whl; zope_security-8.3-cp311-cp311-macosx_11_0_arm64.whl; zope_security-8.3-cp311-cp311-manylinux1_i686.manylinux2014_i686.manylinux_2_17_i686.manylinux_2_5_i686.whl; zope_security-8.3-cp311-cp311-manylinux1_x86_64.manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_5_x86_64.whl; zope_security-8.3-cp311-cp311-manylinux2014_aarch64.manylinux_2_17_aarch64.whl; zope_security-8.3-cp311-cp311-win_amd64.whl; zope_security-8.3-cp312-cp312-macosx_10_9_x86_64.whl; zope_security-8.3-cp312-cp312-macosx_11_0_arm64.whl; zope_security-8.3-cp312-cp312-manylinux1_i686.manylinux2014_i686.manylinux_2_17_i686.manylinux_2_5_i686.whl; zope_security-8.3-cp312-cp312-manylinux1_x86_64.manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_5_x86_64.whl; zope_security-8.3-cp312-cp312-manylinux2014_aarch64.manylinux_2_17_aarch64.whl; zope_security-8.3-cp312-cp312-win_amd64.whl; zope_security-8.3-cp313-cp313-macosx_10_9_x86_64.whl; zope_security-8.3-cp313-cp313-macosx_11_0_arm64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “permission-based authorization”
- zope.securityProvides a generic security framework for implementing access control…
- axioms-fastapiAdds OAuth2/OIDC JWT token validation and claim-based authorization…
- django-permissionedformsExtends Django's forms framework to conditionally show or hide form…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also cedarpy · drf-access-policy · zope.proxy · AccessControl · cerbos · Acquisition · oso-cloud · Flask-Principal · pycasbin · djangorestframework-api-key