PyPI package intelligence

flask — deep security report

ShadowCanopy's full breakdown of flask on PyPI: verdict, AI analysis, dependency chain, network behavior, prebuilds, and obfuscated code.

Safe to use
Deep-scanned by ShadowCanopy — no threats found in its code, dependencies, or network behavior.
Scanned 8/7/2026
Approvedflask@3.1.3View on registry ↗latest: 3.1.3

The flagged file is Flask's own legitimate test_json.py. The byte patterns (deadbeef UUID, snowman unicode, and a datetime string) are ordinary test data, not obfuscation or exfiltration. No malicious behavior present.

Protect your projects free

AI breakdown

Plain-English summary of what this package does and how it behaves.

Flask is a PyPI package described as a simple framework for building complex web applications. The sample files consist entirely of documentation, license, changelog, and related assets with no application source shown.

Capabilities

  • No scripts defined in manifest
  • Includes documentation for web app development and deployment

Data access

  • None observed

Network

  • Hardcoded public IP in network code (per static findings)

Static findings flag obfuscated files and hardcoded IPs, though the manifest and sampled files show only standard documentation for the well-known Flask framework.

Dependency & execution chain

Every package this one pulls in, colored by verdict. Expand to walk the tree.

29 packages8 direct
flask@3.1.34 findings
blinker@1.9.0
click@8.4.26 findings
jinja2@3.1.66 findings
werkzeug@3.1.8

Security findings (4)

Static analysis rule matches, with the exact code that triggered them.

mediumObfuscated source fileATK-023tests/test_json.py

Multiple obfuscation patterns in tests/test_json.py

mediumObfuscated source fileATK-023flask-3.1.3/tests/test_json.py

Multiple obfuscation patterns in flask-3.1.3/tests/test_json.py

highHardcoded public IP in network codeATK-028tests/test_json.py

File tests/test_json.py contains a hardcoded public IP (07:15:00) used in network code — review for hidden exfiltration or C2 endpoints.

highHardcoded public IP in network codeATK-028flask-3.1.3/tests/test_json.py

File flask-3.1.3/tests/test_json.py contains a hardcoded public IP (07:15:00) used in network code — review for hidden exfiltration or C2 endpoints.

Package metadata

LicenseUnknown

A simple framework for building complex web applications.

Files in package (436)

CHANGES.rstflask-3.1.3/CHANGES.rstLICENSE.txtflask-3.1.3/LICENSE.txtREADME.mdflask-3.1.3/README.mddocs/Makefileflask-3.1.3/docs/Makefiledocs/_static/debugger.pngflask-3.1.3/docs/_static/debugger.pngdocs/_static/flask-icon.svgflask-3.1.3/docs/_static/flask-icon.svgdocs/_static/flask-logo.svgflask-3.1.3/docs/_static/flask-logo.svgdocs/_static/flask-name.svgflask-3.1.3/docs/_static/flask-name.svgdocs/_static/pycharm-run-config.pngflask-3.1.3/docs/_static/pycharm-run-config.pngdocs/api.rstflask-3.1.3/docs/api.rstdocs/appcontext.rstflask-3.1.3/docs/appcontext.rstdocs/async-await.rstflask-3.1.3/docs/async-await.rstdocs/blueprints.rstflask-3.1.3/docs/blueprints.rstdocs/changes.rstflask-3.1.3/docs/changes.rstdocs/cli.rstflask-3.1.3/docs/cli.rstdocs/conf.pyflask-3.1.3/docs/conf.pydocs/config.rstflask-3.1.3/docs/config.rstdocs/contributing.rstflask-3.1.3/docs/contributing.rstdocs/debugging.rstflask-3.1.3/docs/debugging.rstdocs/deploying/apache-httpd.rstflask-3.1.3/docs/deploying/apache-httpd.rst

How ShadowCanopy checks PyPI packages

ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.

Protect your projects freeSee what's being blocked

This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/pypi/flask