Skip to content

Modern Python library for HTTP security headers with safe defaults, configurable presets, and first-class ASGI/WSGI middleware (FastAPI, Django, Flask, Shiny, and more).

active 2024-07-222026-07-23 (UTC)

Partial coverage15,013 / 18,378 hourly files (82%) · 2 absent upstream · 3,364 failed, retryable2024-07-072026-08-11 (UTC)— sampled evenly across the window, so rankings and trends hold; absolute counts scale up.
Events
220
Pushes
28
Pull requests
6
Issues
8
Stars
148
Forks
1

Activity over time

Daily event counts in the loaded window

Line chart, 732 days from 2024-07-22 to 2026-07-23. Pushes: 28 total, peak 3 in a day. Pull requests: 6 total, peak 2 in a day. Issues: 8 total, peak 3 in a day. Comments: 15 total, peak 4 in a day. Stars: 148 total, peak 14 in a day.

  • Pushes
  • Pull requests
  • Issues
  • Comments
  • Stars

Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.

Top contributors

Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity

ContributorContributionsPushesPRsComments
cak5228512
fnep2002
BoboTiG1010
davidwtbuxton1000
chadwhawkins1001

Recent activity

Latest issues, pull requests and releases

  • Releasecak2026-04-22 10:02
    secure v2.0.1 – Middleware, Presets, and Safer Defaults
  • Pull request#42cak2026-04-22 01:20
  • Issue comment#41chadwhawkins2026-04-08 00:57
    `middleware` directory is missing
  • Issue comment#38cak2025-12-16 12:08
    Potential Thread-Safety Concern with `@cached_property` Usage
  • Issue comment#36cak2025-12-16 12:07
    Lack of Duplicate Header Detection in `Secure` Class
  • Issue comment#34cak2025-12-16 12:07
    Missing Error Handling in `set_headers` and `set_headers_async`
  • Issue comment#30cak2025-12-16 11:59
    Suggestion: Add Mypy library stubs / typing
  • Issue#29cak2025-12-16 10:45
    PermissionsPolicy missing some permissions
  • Issue#32cak2025-12-16 10:45
    AttributeError: 'Secure' object has no attribute 'hsts'
  • Issue#31cak2025-12-16 10:45
    Suggestion: Remove X-Frame-Options header
  • Pull request#40cak2025-12-16 10:42
  • Issue comment#35cak2025-11-08 14:38
    Lack of Allowlisting for Header Names in `Secure` Class
  • Issue comment#38cak2025-10-25 23:09
    Potential Thread-Safety Concern with `@cached_property` Usage
  • Pull request#39BoboTiG2025-06-14 17:05
  • Issue comment#26cak2024-10-18 09:30
    Performance of `Secure.set_headers(response)`
  • Releasecak2024-10-18 09:29
    v1.0.1 - Performance Improvements for Secure.set_headers
  • Issue#26cak2024-10-18 09:22
    Performance of `Secure.set_headers(response)`
  • Pull request#27cak2024-10-18 09:22
  • Issue comment#26cak2024-10-16 23:05
    Performance of `Secure.set_headers(response)`
  • Issue#26davidwtbuxton2024-10-16 20:54
    Performance of `Secure.set_headers(response)`
  • Issue comment#23fnep2024-09-30 07:36
    starlette `middleware` decorator is deprecated
  • Releasecak2024-09-27 09:07
    v1.0.0 – Full Redesign and Modernization of secure.py
  • Issue#23cak2024-09-27 08:45
    starlette `middleware` decorator is deprecated
  • Issue#24cak2024-09-27 08:45
    Typos
  • Issue#22cak2024-09-27 08:45
    Server header is not overridden

Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 148 stars here means stars gained during the window, not the repo's star count.