NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2062 most downloaded on PyPI
Keep track of failed login attempts in Django-powered sites.
Last release 7 months ago
11 Feb 2026
Release timing varies
gaps range from 1 weeks to 7 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
18 years old
166 releases · first in 2008
Implement custom lazy object to avoid JSON errors with Celery by @aleksihakli in https://github.com/jazzband/django-axes/pull/1392
Full Changelog: https://github.com/jazzband/django-axes/compare/8.3.0...8.3.1
Full Changelog: 8.3.0...8.3.1
Fix configuration JSON serialization errors for Celery. [aleksihakli]
One column per quarter.
Docs: Replace removed pkg_resources with stdlib by @hugovk in https://github.com/jazzband/django-axes/pull/1388
pkg_resources with stdlib by @hugovk in https://github.com/jazzband/django-axes/pull/1388Full Changelog: https://github.com/jazzband/django-axes/compare/8.2.0...8.3.0
Fix: custom user model circular import by @rodrigobnogueira in https://github.com/jazzband/django-axes/pull/1376
Full Changelog: https://github.com/jazzband/django-axes/compare/8.1.0...8.2.0
Full Changelog: 8.1.0...8.2.0
Fix AttributeError when optional settings are undefined. [rodrigo.nogueira]
Fix circular import with custom user models. [rodrigo.nogueira]
Add unit tests for security check W006. [shayanTaki]
Add Persian (fa) translation for django-axes by @AmirAli-BahramJerdi in https://github.com/jazzband/django-axes/pull/1308
Full Changelog: https://github.com/jazzband/django-axes/compare/8.0.0...8.1.0
Full Changelog: 8.0.0...8.1.0
Add Persion (fa) translations for django-axes. [AmirAli-BahramJerdi]
Add individual attempt expiry support. [kuldeepkhatke]
Add checks for missing ip_address in lockout params. [shayanTaki]
Add missing settings.AXES_IPWARE_PROXY_ORDER documentation. [ram98kgp]
Enhance get_lockout_response to receive original response as parameter. [mounirmesselmeni]
Update documentation.
Add Python 3.14 support.
Add Django 6.0 support.
Remove Python 3.9 support (EOL).
Remove Django 5.1 support (EOL).
chore: move clean expired attempt function to db handler method by @nefrob in https://github.com/jazzband/django-axes/pull/1305
Full Changelog: https://github.com/jazzband/django-axes/compare/7.1.0...8.0.0
Full Changelog: 7.1.0...8.0.0
Move all database related logic to the default axes.handlers.database.AxesDatabaseHandler. [nefrob]
docs - table in 4_configuration overflowing by @Jacobus-afk in https://github.com/jazzband/django-axes/pull/1281
Full Changelog: https://github.com/jazzband/django-axes/compare/7.0.2...7.1.0
Full Changelog: 7.0.2...7.1.0
Provide credentials to expired credentials cleanup method. [parul-aro]
Update support matrix for Django 5.2. [mkniewallner]
Fix documentation. [chango-goat]
Update 4_configuration.rst - aligned table pipe column by @Jacobus-afk in https://github.com/jazzband/django-axes/pull/1274
Full Changelog: https://github.com/jazzband/django-axes/compare/7.0.1...7.0.2
Full Changelog: 7.0.1...7.0.2
Fix documentation. [Jacobus-afk]
Default to using settings.AUTH_USER_MODEL.USERNAME_FIELD for resolving settings.AXES_USERNAME_FORM_FIELD if otherwise unset (previously "username"). [amneher]
Deprecate support for Python 3.8 Add support for Python 3.13
Update Python support matrix
Deprecate support for Python 3.8
Add support for Python 3.13
Add Python 3.13 support. [aleksihakli]
Deprecate Python 3.8 support. [aleksihakli]
Add support for dynamic cooloff time calculation from request. This is a breaking change. Please see version 7 upgrade notes in the documentation _. […
Add support for dynamic cooloff time calculation from request. This is a breaking change. Please see version 7 upgrade notes in the documentation. [browniebroke]
Add test matrix support for Django 5.1.
Add test matrix support for Django 5.1.
Drop support for EOL Django 3.2.
Drop support for PyPy 3.10.
Make 0007_alter_accessattempt_unique_together.py migration backwards compatible. [hirotasoshu]
Make 0007_alter_accessattempt_unique_together.py migration backwards compatible. [hirotasoshu]
Add session hash to access log. [sevdog]
Add session hash to access log. [sevdog]
Add support for Python 3.12 and Django 5.0, drop support for Django 4.1. [aleksihakli]
Add support for Python 3.12 and Django 5.0, drop support for Django 4.1. [aleksihakli]
Drop setuptools and pkg_resources dependencies. [Viicos]
Drop setuptools and pkg_resources dependencies. [Viicos]
Add async support to middleware. [Taikono-Himazin]
Add async support to middleware. [Taikono-Himazin]
Update documentation. [funkybob]
Update documentation. [funkybob]
Add new management command axes_reset_ip_username. [p-l-]
Add French translations. [laulaz]
Avoid running data migration on incorrect databases. [christianbundy]
Fix TransactionManagementError when using the database handler with a custom database with for AccessAttempt or AccessFailureLog. [hirotasoshu]
Fix TransactionManagementError when using the database handler with a custom database with for AccessAttempt or AccessFailureLog. [hirotasoshu]
Set AXES_SENSITIVE_PARAMETERS default value to ["username", "ip_address"] in addition to the AXES_PASSWORD_FORM_FIELD configuration flag. This masks t
Set AXES_SENSITIVE_PARAMETERS default value to ["username", "ip_address"] in addition to the AXES_PASSWORD_FORM_FIELD configuration flag. This masks the username and IP address fields by default in the logs when writing information about login attempts to the application logs. Reverting to old configuration default of [] can be done by setting AXES_SENSITIVE_PARAMETERS = [] in the Django project settings file. [GitRon]
Improve documentation on GDPR and privacy notes and configuration flags. [GitRon]
Add Indonesion translation. [kiraware]
Add Indonesion translation. [kiraware]
Remove unused methods from AxesStandaloneBackend. [314eter]
Remove unused methods from AxesStandaloneBackend. [314eter]
Add username to admin fieldsets. [sevdog]
Add username to admin fieldsets. [sevdog]
Add Django system checks for validating callable import path settings. [iafisher]
Add Django system checks for validating callable import path settings. [iafisher]
Improve documentation. [hirotasoshu]
Improve repository issue and PR templates. [hirotasoshu]
Fine-tune CI pipelines and RTD build requirements. [aleksihakli]
Fine-tune CI pipelines and RTD build requirements. [aleksihakli]
Deprecate Python 3.7 support. [aleksihakli]
Version 6 is a breaking release. Please see the documentation for upgrade instructions.
Deprecate Python 3.7 support. [aleksihakli]
Deprecate is_admin_site API call with misleading naming. [hirotasoshu]
Add AXES_LOCKOUT_PARAMETERS configuration flag that will supersede AXES_ONLY_USER_FAILURES, AXES_LOCK_OUT_BY_COMBINATION_USER_AND_IP, AXES_LOCK_OUT_BY_USER_OR_IP, and AXES_USE_USER_AGENT configurations. Add deprecation warnings for old flags. See project documentation on RTD for update instructions. [hirotasoshu]
Improve translations. [hirotasoshu]
Use Django cache.incr API for atomic cached failure counting [hirotasoshu, aleksihakli]
Make django-ipware an optional dependency. Install it with e.g. pip install django-axes[ipware] package and extras specifier. [aleksihakli]
AXES_PROXY_ORDER is now AXES_IPWARE_PROXY_ORDER,
AXES_PROXY_COUNT is now AXES_IPWARE_PROXY_COUNT,
AXES_PROXY_TRUSTED_IPS is now AXES_IPWARE_PROXY_TRUSTED_IPS, and
AXES_META_PRECEDENCE_ORDER is now AXES_IPWARE_META_PRECEDENCE_ORDER.
Set 429 as the default lockout response code. [hirotasoshu]
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix sensitive parameter logging for database handler. [stereodamage]
Fix sensitive parameter logging for database handler. [stereodamage]
Add AXES_CLIENT_CALLABLE setting. [hirotasoshu]
Fix tests. [hirotasoshu]
Add AXES_CLIENT_CALLABLE setting. [hirotasoshu]
Update Python, Django, and package versions. [hramezani]
Fix bug in user agent request blocking. [PetrDlouhy]
Fix bug in user agent request blocking. [PetrDlouhy]
Update packages and linters for new version support. [hramezani]
Update packages and linters for new version support. [hramezani]
Update documentation links. [Arhell]
Use importlib instead of setuptools for Python 3.8+. [jedie]
Python 3.11 support. [joshuadavidthomas]
Documentation improvements. [nsht]
Documentation improvements. [timgates42]
Utilize new backend class in tests to fix false negative system check warnings. [simonkern]
Utilize new backend class in tests to fix false negative system check warnings. [simonkern]
Adjust changelog so release notes are correctly visible on PyPy and released package. [aleksihakli]
Adjust changelog so release notes are correctly visible on PyPy and released package. [aleksihakli]
Add Django 4.1 support. PyPy 3.8 has a known issue with Django 4.1 and is exempted. [hramezani]
Add Django 4.1 support. PyPy 3.8 has a known issue with Django 4.1 and is exempted. [hramezani]
Add AxesStandaloneBackend without ModelBackend dependencies. [jcgiuffrida]
Add AxesStandaloneBackend without ModelBackend dependencies. [jcgiuffrida]
Add Arabic translations. [YDA93]
Add Arabic translations. [YDA93]
Improve German translations. [GitRon]
Improve German translations. [GitRon]
Migrate MD5 cache key digests to SHA256. [aleksihakli]
Migrate MD5 cache key digests to SHA256. [aleksihakli]
Improve and streamline startup logging. [ShaheedHaque]
Improve module typing. [hramezani]
Add support for float or partial hours for AXES_COOLOFF_TIME. [hramezani]
Add support for persistent failure logging where failed login attempts are persisted in the database until a specific threshold is reached. [p1-gdd]
Add support for persistent failure logging where failed login attempts are persisted in the database until a specific threshold is reached. [p1-gdd]
Add support for not resetting login times when users try to login during the lockout cooloff period. [antoine-42]
Adjust version specifiers for newer Python and other package versions. Set package minimum Python version to 3.7. Relax django-ipware version requirem
Adjust version specifiers for newer Python and other package versions. Set package minimum Python version to 3.7. Relax django-ipware version requirements to allow newer versions. [aleksihakli]
Fix package build error in 5.29.0 to allow publishing. [aleksihakli]
Fix package build error in 5.29.0 to allow publishing. [aleksihakli]
Drop Django < 3.2 support. [hramezani]
Drop Django < 3.2 support. [hramezani]
Add Django 4.0 to test matrix. [hramezani]
Fix pkg_resources missing for package version resolution on runtime due to setuptools not being a runtime dependency. [asherf]
Fix pkg_resources missing for package version resolution on runtime due to setuptools not being a runtime dependency. [asherf]
Add Python 3.10 and Django 3.2 support. [hramezani]
Fix AXES_USERNAME_CALLABLE not receiving credentials attribute in Axes middleware lockout response when user is locked out. [rootart]
Fix AXES_USERNAME_CALLABLE not receiving credentials attribute in Axes middleware lockout response when user is locked out. [rootart]
Fix duplicated AccessAttempts with updated database model unique_together constraints and data and schema migration. [PetrDlouhy]
Fix duplicated AccessAttempts with updated database model unique_together constraints and data and schema migration. [PetrDlouhy]
Use atomic transaction for updating AccessAttempts in database handler. [okapies]
Use atomic transaction for updating AccessAttempts in database handler. [okapies]
Pass request as argument to AXES_CLIENT_STR_CALLABLE. [sarahboyce]
Pass request as argument to AXES_CLIENT_STR_CALLABLE. [sarahboyce]
Improve failures_since_start handling by moving the counter incrementation from non-atomic Python code call to atomic database function. [okapies]
Improve failures_since_start handling by moving the counter incrementation from non-atomic Python code call to atomic database function. [okapies]
Add publicly available request.axes_failures_since_start attribute. [okapies]
Add configurable lockout HTTP status code responses with the new AXES_HTTP_RESPONSE_CODE setting. [phil-bell]
Add configurable lockout HTTP status code responses with the new AXES_HTTP_RESPONSE_CODE setting. [phil-bell]
Improve race condition handling in e.g. multi-process environments by using get_or_create for access attempt fetching and updates. [uli-klank]
Improve race condition handling in e.g. multi-process environments by using get_or_create for access attempt fetching and updates. [uli-klank]
- Add Polish locale. [Quadric]
Add Polish locale. [Quadric]
Fix default_auto_field warning. [zkanda]
Fix default_auto_field warning. [zkanda]
Fix default_app_config deprecation. Django 3.2 automatically detects AppConfig and therefore this setting is no longer required. [nikolaik]
Fix default_app_config deprecation. Django 3.2 automatically detects AppConfig and therefore this setting is no longer required. [nikolaik]
Add AXES_CLIENT_STR_CALLABLE setting. [smtydn]
Add AXES_CLIENT_STR_CALLABLE setting. [smtydn]
Add option to cleanse sensitive GET and POST params in database handler with the AXES_SENSITIVE_PARAMETERS setting. [mcoconnor]
Add option to cleanse sensitive GET and POST params in database handler with the AXES_SENSITIVE_PARAMETERS setting. [mcoconnor]
Improve message formatting for lockout message and translations. [ashokdelphia]
Improve message formatting for lockout message and translations. [ashokdelphia]
Remove support for Django 3.0. [hramezani]
Add support for Django 3.2. [hramezani]
Default AXES_VERBOSE to AXES_ENABLED configuration setting, disabling verbose startup logging when Axes itself is disabled. [christianbundy]
Default AXES_VERBOSE to AXES_ENABLED configuration setting, disabling verbose startup logging when Axes itself is disabled. [christianbundy]
Update documentation. [KStenK]
Add support for resetting attempts with cache backend. [nattyg93]
Add support for resetting attempts with cache backend. [nattyg93]
Your coding agent can read these notes before it upgrades. Set up the MCP server →