NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2372 most downloaded on PyPI
Keep track of failed login attempts in Django-powered sites.
Last release 7 months ago
11 Feb 2026
Release timing varies
gaps range from 1 weeks to 7 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
18 years old
166 releases · first in 2008
Clean up test structure and migrate tests outside the main package for a smaller wheel distributions. [aleksihakli]
Clean up test structure and migrate tests outside the main package for a smaller wheel distributions. [aleksihakli]
Move configuration to pyproject.toml for cleaner layout. [aleksihakli]
Clean up test settings override configuration. [hramezani]
Fix cache entry creations for None username. [cabarnes]
Fix cache entry creations for None username. [cabarnes]
One column per quarter.
Add lockout view CORS support with AXES_ALLOWED_CORS_ORIGINS configuration flag. [vladox]
Add lockout view CORS support with AXES_ALLOWED_CORS_ORIGINS configuration flag. [vladox]
Add missing @wraps decorator to axes.decorators.axes_dispatch. [aleksihakli]
Add DEFAULT_AUTO_FIELD to test settings. [hramezani]
Add DEFAULT_AUTO_FIELD to test settings. [hramezani]
Fix documentation language. [danielquinn]
Fix Python package version specifiers and remove redundant imports. [aleksihakli]
Deprecate stock DRF support from 5.8.0, require users to set it up per project. Check the documentation for more information. [aleksihakli]
Deprecate stock DRF support from 5.8.0, require users to set it up per project. Check the documentation for more information. [aleksihakli]
Move tests to GitHub Actions [jezdez]
Move tests to GitHub Actions [jezdez]
Fix running Axes code in middleware when AXES_ENABLED is False. [ashokdelphia]
Add Python 3.9 support. [hramezani]
Add Python 3.9 support. [hramezani]
Prevent AccessAttempt creation with database handler when username is not set and AXES_ONLY_USER_FAILURES setting is not set. [hramezani]
Improve Django REST Framework (DRF) integration. [Anatoly]
Improve Django REST Framework (DRF) integration. [Anatoly]
Adjust settings import and handling chain for cleaner module import and invocation order. [aleksihakli]
Adjust settings import and handling chain for cleaner module import and invocation order. [aleksihakli]
Adjust the use of AXES_ENABLED flag so that imports are always done the same way and initial log is written regardless of the setting and it only affects code that is decorated or wrapped with toggleable. [alekshakli]
Deprecate AXES_LOGGER Axes setting and move to __name__ based logging and fully qualified Python module name log identifiers. [aleksihakli]
Deprecate AXES_LOGGER Axes setting and move to __name__ based logging and fully qualified Python module name log identifiers. [aleksihakli]
Fix regression in axes_reset_user management command. [aleksihakli]
Fix regression in axes_reset_user management command. [aleksihakli]
Improve test dependency management and upgrade black code formatter. [smithdc1]
Improve test dependency management and upgrade black code formatter. [smithdc1]
Deprecate django-appconf and use plain settings for Axes. [aleksihakli]
Add proper development subTest support via pytest-subtests package. [smithdc1]
Deprecate django-appconf and use plain settings for Axes. [aleksihakli]
Update deprecating use of the request.is_ajax method. [smithdc1]
Update deprecating use of the request.is_ajax method. [smithdc1]
Update deprecated uses of Django modules and members. [smithdc1]
Update deprecated uses of Django modules and members. [smithdc1]
Deprecate Signal providing_args for Django 3.1 support. [coredumperror]
Add support for locking requests based on username OR IP address with inclusive or using the LOCK_OUT_BY_USER_OR_IP flag. [PetrDlouhy]
Deprecate Signal providing_args for Django 3.1 support. [coredumperror]
Add Django 3.1 support. [hramezani]
Add Django 3.1 support. [hramezani]
Add ABC or abstract base class implementation for handlers. [jorlugaqui]
Add ABC or abstract base class implementation for handlers. [jorlugaqui]
Fix code styling for linters. [aleksihakli]
Fix code styling for linters. [aleksihakli]
Restrict ipware version for version compatibility. [aleksihakli]
Restrict ipware version for version compatibility. [aleksihakli]
Deprecate Django 1.11 LTS support. [aleksihakli]
Deprecate Django 1.11 LTS support. [aleksihakli]
Fix AXES_ONLY_ADMIN_SITE functionality when no default admin site is defined in the URL configuration. [igor-shevchenko]
Fix AXES_ONLY_ADMIN_SITE functionality when no default admin site is defined in the URL configuration. [igor-shevchenko]
Fix AppConf settings prefix for Fargate. [marksweb]
Fix AppConf settings prefix for Fargate. [marksweb]
Fix null byte ValueError bug in ORM. [ddimmich]
Fix null byte ValueError bug in ORM. [ddimmich]
Improve Django REST Framework compatibility. [I0x4dI]
Improve Django REST Framework compatibility. [I0x4dI]
Add missing proxy implementation for axes.handlers.proxy.AxesProxyHandler.get_failures. [aleksihakli]
Add missing proxy implementation for axes.handlers.proxy.AxesProxyHandler.get_failures. [aleksihakli]
Add django-reversion compatibility notes. [mark-mishyn]
Add django-reversion compatibility notes. [mark-mishyn]
Add pluggable lockout responses and the AXES_LOCKOUT_CALLABLE configuration flag. [aleksihakli]
Add a test handler. [aidanlister]
Add a test handler. [aidanlister]
Add pluggable user account whitelisting and the AXES_WHITELIST_CALLABLE configuration flag. [aleksihakli]
Add pluggable user account whitelisting and the AXES_WHITELIST_CALLABLE configuration flag. [aleksihakli]
Fix django-allauth compatibility issue. [hramezani]
Fix django-allauth compatibility issue. [hramezani]
Improve tests for login attempt monitoring. [hramezani]
Add reverse proxy documentation. [ckcollab]
Update OAuth documentation examples. [aleksihakli]
Optimize access attempt fetching in database handler. [hramezani]
Optimize access attempt fetching in database handler. [hramezani]
Optimize request data fetching in proxy handler. [hramezani]
Add cooloff_timedelta context variable to lockout responses. [jstockwin]
Add cooloff_timedelta context variable to lockout responses. [jstockwin]
Safer string formatting for user input. [aleksihakli]
Safer string formatting for user input. [aleksihakli]
Fix string formatting bug in logging. [zerolab]
Fix string formatting bug in logging. [zerolab]
Add AXES_ENABLE_ADMIN flag. [flannelhead]
Add AXES_ENABLE_ADMIN flag. [flannelhead]
Docs, CI pipeline, and code formatting improvements [aleksihakli]
Docs, CI pipeline, and code formatting improvements [aleksihakli]
Python 3.8 and PyPy support. [aleksihakli]
Python 3.8 and PyPy support. [aleksihakli]
Migrate to setuptools_scm and automatic versioning. [aleksihakli]
Support callables for AXES_COOLOFF_TIME setting. [DariaPlotnikova]
Support callables for AXES_COOLOFF_TIME setting. [DariaPlotnikova]
Fix typo in rST formatting that prevented 5.0.10 release to PyPI. [aleksihakli]
Fix typo in rST formatting that prevented 5.0.10 release to PyPI. [aleksihakli]
Add better handling for attempt and log resets by moving them into handlers which allows customization and more configurability. Unimplemented handler
Add better handling for attempt and log resets by moving them into handlers which allows customization and more configurability. Unimplemented handlers raise NotImplementedError by default. [aleksihakli]
Add Python 3.8 dev version and PyPy to the Travis test matrix. [aleksihakli]
Add AXES_ONLY_ADMIN_SITE flag for only running Axes on admin site. [hramezani]
Add AXES_ONLY_ADMIN_SITE flag for only running Axes on admin site. [hramezani]
Add axes_reset_logs command for removing old AccessLog records. [tlebrize]
Allow AxesBackend subclasses to pass the axes.W003 system check. [adamchainz]
Fix lockout message showing when lockout is disabled with the AXES_LOCK_OUT_AT_FAILURE setting. [mogzol]
Fix lockout message showing when lockout is disabled with the AXES_LOCK_OUT_AT_FAILURE setting. [mogzol]
Add support for callable AXES_FAILURE_LIMIT setting. [bbayles]
Deprecate AXES_DISABLE_SUCCESS_ACCESS_LOG flag in favour of AXES_DISABLE_ACCESS_LOG which has mostly the same functionality. Update documentation to b…
Deprecate AXES_DISABLE_SUCCESS_ACCESS_LOG flag in favour of AXES_DISABLE_ACCESS_LOG which has mostly the same functionality. Update documentation to better reflect the behaviour of the flag. [aleksihakli]
Move request attribute calculation from middleware to handler layer. Deprecate axes.request.AxesHttpRequest object type definition. [aleksihakli]
Change the lockout response calculation to request flagging instead of exception throwing in the signal handler and middleware. Move request attribute calculation from middleware to handler layer. Deprecate axes.request.AxesHttpRequest object type definition. [aleksihakli]
Deprecate the old version 4.x axes.backends.AxesModelBackend class. [aleksihakli]
Improve documentation on attempt tracking, resets, Axes customization, project and component compatibility and integrations, and other things. [aleksihakli]
Fix regression with OAuth2 authentication backends not having remote IP addresses set and throwing an exception in cache key calculation. [aleksihakli
Fix regression with OAuth2 authentication backends not having remote IP addresses set and throwing an exception in cache key calculation. [aleksihakli]
Fix django.contrib.auth module login and logout functionality so that they work with the handlers without the an AxesHttpRequest to improve cross comp
Fix django.contrib.auth module login and logout functionality so that they work with the handlers without the an AxesHttpRequest to improve cross compatibility with other Django applications. [aleksihakli]
Change IP address resolution to allow empty or missing addresses. [aleksihakli]
Add error logging for missing request attributes in the handler layer so that users get better indicators of misconfigured applications. [aleksihakli]
Add AXES_ENABLED setting for disabling Axes with e.g. tests that use Django test client login, logout, and force_login methods, which do not supply th
Add AXES_ENABLED setting for disabling Axes with e.g. tests that use Django test client login, logout, and force_login methods, which do not supply the request argument to views, preventing Axes from functioning correctly in certain test setups. [aleksihakli]
Add changelog to documentation. [aleksihakli]
Add changelog to documentation. [aleksihakli]
Deprecate Python 2.7, 3.4 and 3.5 support. [aleksihakli]
Deprecate Python 2.7, 3.4 and 3.5 support. [aleksihakli]
Remove automatic decoration and monkey-patching of Django views and forms. Decorators are available for login function and method decoration as before. [aleksihakli]
Use backend, middleware, and signal handlers for tracking login attempts and implementing user lockouts. [aleksihakli, jorlugaqui, joshua-s]
Add AxesDatabaseHandler, AxesCacheHandler, and AxesDummyHandler handler backends for processing user login and logout events and failures. Handlers are configurable with the AXES_HANDLER setting. [aleksihakli, jorlugaqui, joshua-s]
Improve management commands and separate commands for resetting all access attempts, attempts by IP, and attempts by username. New command names are axes_reset, axes_reset_ip and axes_reset_username. [aleksihakli]
Add support for string import for AXES_USERNAME_CALLABLE that supports dotted paths in addition to the old callable type such as a function or a class method. [aleksihakli]
Deprecate one argument call signature for AXES_USERNAME_CALLABLE. From now on, the callable needs to accept two arguments, the HttpRequest and credentials that are supplied to the Django authenticate method in authentication backends. [aleksihakli]
Move axes.attempts.is_already_locked function to axes.handlers.AxesProxyHandler.is_locked. Various other previously undocumented methods have been deprecated and moved inside the project. The new documented public APIs can be considered as stable and can be safely utilized by other projects. [aleksihakli]
Improve documentation layouting and contents. Add public API reference section. [aleksihakli]
Nothing published for this version
Nothing published for this version
Improve README and documentation [aleksihakli]
Improve README and documentation [aleksihakli]
Remove the unused AccessAttempt.trusted flag from models [aleksihakli]
Remove the unused AccessAttempt.trusted flag from models [aleksihakli]
Improve README and Travis CI setups [aleksihakli]
Added Turkish translations [obayhan]
Added Turkish translations [obayhan]
Removed duplicated check that was causing issues when using APIs. [camilonova]
Removed duplicated check that was causing issues when using APIs. [camilonova]
Added Russian translations [lubicz-sielski]
Improve support for custom authentication credentials using the AXES_USERNAME_FORM_FIELD and AXES_USERNAME_CALLABLE settings. [mastacheata]
Improve support for custom authentication credentials using the AXES_USERNAME_FORM_FIELD and AXES_USERNAME_CALLABLE settings. [mastacheata]
Updated behaviour for fetching username from request or credentials: If no AXES_USERNAME_CALLABLE is configured, the optional credentials that are supplied to the axes utility methods are now the default source for client username and the HTTP request POST is the fallback for fetching the user information. AXES_USERNAME_CALLABLE implements an alternative signature with two arguments request, credentials in addition to the old request call argument signature in a backwards compatible fashion. [aleksihakli]
Add official support for the Django 2.1 version and Python 3.7. [aleksihakli]
Improve the requirements, documentation, tests, and CI setup. [aleksihakli]
Fix MANIFEST.in missing German translations [aleksihakli]
Fix MANIFEST.in missing German translations [aleksihakli]
Add AXES_RESET_ON_SUCCESS configuration flag [arjenzijlstra]
fix missing migration and add check to prevent it happening again. [markddavidoff]
fix missing migration and add check to prevent it happening again. [markddavidoff]
Add a German translation [adonig]
Add a German translation [adonig]
Documentation wording changes [markddavidoff]
Use get_client_username in log_user_login_failed instead of credentials [markddavidoff]
pin prospector to 0.12.11, and pin astroid to 1.6.5 [hsiaoyi0504]
Added AXES_USERNAME_CALLABLE [jaadus]
Added AXES_USERNAME_CALLABLE [jaadus]
Your coding agent can read these notes before it upgrades. Set up the MCP server →