Is pycrypto healthy, maintained, and safe?
No. pycrypto carries 1 unpatched critical advisory and should not be adopted without a remediation plan.
The verdict
On the OSPulse health scale, pycrypto lands at 0/100, a critical risk rating, computed deterministically from live PyPI release history, and the OSV vulnerability database. No. pycrypto carries 1 unpatched critical advisory and should not be adopted without a remediation plan.
The last sign of life was 20 June 2014, more than 12 years ago (4470 days). By any practical measure the package looks abandoned. Historically it released far more frequently, so the current silence reads as a genuine collapse in velocity rather than a natural gap. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here. Treat maintenance depth as unknown rather than assumed.
OSV lists 8 known advisories for pycrypto, including 1 critical and 2 high. Open critical advisories are the strongest possible signal to pin to a patched version, replace, or fork before shipping. Each advisory is listed with its OSV/GHSA identifier below.
The safest reading is to replace, fork, or tightly pin pycrypto and stop taking on new exposure to it. This is a one-time snapshot of a single package. Real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail: deterministic, auditable
Known vulnerabilities (8)
Pycrypto generates weak key parameters
Buffer Overflow in pycrypto
PyCrypto makes Use of Insufficiently Random Values
PyCrypto does not properly reseed PRNG before allowing access
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers t
The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for co
Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv pa
lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not ha
Key facts
- Latest version
- v2.6.1
- Last release
- 20 June 2014 (4470 days ago)
- Total releases
- 9
- First release
- 17 December 2010
- Package age
- 15.8 years
- Maintainers
- not exposed by PyPI
- Known advisories
- 8
- Confidence
- High
Frequently asked
Is pycrypto still maintained?
It doesn't appear to be. The last release was 20 June 2014, over two years ago, which usually indicates an abandoned package.
Does pycrypto have known security vulnerabilities?
Yes. OSV lists 8 advisories for pycrypto, including 1 rated critical. See the advisory list on this page for the OSV/GHSA identifiers.
Is pycrypto safe to use?
No. pycrypto carries 1 unpatched critical advisory and should not be adopted without a remediation plan. OSPulse rates it 0/100 (critical risk) based on release recency, cadence and known vulnerabilities.
Other PyPI packages we've checked
pycrypto is one package. What about the other hundreds in your tree?
Paste your own requirements.txt into the free health check for an instant snapshot, or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the PyPI registry & OSV.dev · snapshot generated 2026-09-15 · scores are deterministic and recomputed on each refresh.
