OSPulse

Is pycrypto healthy, maintained, and safe?

0/ 100
pycryptov2.6.1
Critical riskconfidence: Highview on pypi.org

No. pycrypto carries 1 unpatched critical advisory and should not be adopted without a remediation plan.

vital-signs traceflatline

The verdict

On the OSPulse health scale, pycrypto lands at 0/100, a critical risk rating, computed deterministically from live PyPI release history, and the OSV vulnerability database. No. pycrypto carries 1 unpatched critical advisory and should not be adopted without a remediation plan.

The last sign of life was 20 June 2014, more than 12 years ago (4470 days). By any practical measure the package looks abandoned. Historically it released far more frequently, so the current silence reads as a genuine collapse in velocity rather than a natural gap. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here. Treat maintenance depth as unknown rather than assumed.

OSV lists 8 known advisories for pycrypto, including 1 critical and 2 high. Open critical advisories are the strongest possible signal to pin to a patched version, replace, or fork before shipping. Each advisory is listed with its OSV/GHSA identifier below.

The safest reading is to replace, fork, or tightly pin pycrypto and stop taking on new exposure to it. This is a one-time snapshot of a single package. Real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.

Evidence trail: deterministic, auditable

Last release recency
4470 days ago · likely abandoned
-45
Release cadence
typical gap ~132d · now 4470d · velocity collapse
-15
Maintainer bus factor
not available from PyPI, not penalised
Known vulnerabilities (OSV)
8 advisories · 1 critical · 2 high
-45
Package age
15.8 years · 9 releases

Known vulnerabilities (8)

  • GHSA-6528-wvf6-f6qgHIGHCVE-2018-6594PYSEC-2018-97

    Pycrypto generates weak key parameters

  • GHSA-cq27-v7xp-c356CRITICALCVE-2013-7459PYSEC-2017-94

    Buffer Overflow in pycrypto

  • GHSA-v367-p58w-98h5MODERATECVE-2012-2417PYSEC-2012-16

    PyCrypto makes Use of Insufficiently Random Values

  • GHSA-x377-f64p-hf5jHIGHCVE-2013-1445PYSEC-2013-29

    PyCrypto does not properly reseed PRNG before allowing access

  • PYSEC-2012-16UNKNOWNCVE-2012-2417GHSA-v367-p58w-98h5

    PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers t

  • PYSEC-2013-29UNKNOWNCVE-2013-1445GHSA-x377-f64p-hf5j

    The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for co

  • PYSEC-2017-94UNKNOWNCVE-2013-7459GHSA-cq27-v7xp-c356

    Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv pa

  • PYSEC-2018-97UNKNOWNCVE-2018-6594GHSA-6528-wvf6-f6qg

    lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not ha

Key facts

Latest version
v2.6.1
Last release
20 June 2014 (4470 days ago)
Total releases
9
First release
17 December 2010
Package age
15.8 years
Maintainers
not exposed by PyPI
Known advisories
8
Confidence
High

Frequently asked

Is pycrypto still maintained?

It doesn't appear to be. The last release was 20 June 2014, over two years ago, which usually indicates an abandoned package.

Does pycrypto have known security vulnerabilities?

Yes. OSV lists 8 advisories for pycrypto, including 1 rated critical. See the advisory list on this page for the OSV/GHSA identifiers.

Is pycrypto safe to use?

No. pycrypto carries 1 unpatched critical advisory and should not be adopted without a remediation plan. OSPulse rates it 0/100 (critical risk) based on release recency, cadence and known vulnerabilities.

Other PyPI packages we've checked

Browse all checked packages →

pycrypto is one package. What about the other hundreds in your tree?

Paste your own requirements.txt into the free health check for an instant snapshot, or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.

Data from the PyPI registry & OSV.dev · snapshot generated 2026-09-15 · scores are deterministic and recomputed on each refresh.