piccolo

pypiv1.33.0

A fast, user friendly ORM and query builder which supports asyncio.

License MITpermissive292 versions1 maintainers17 deps53,484 weekly dl
piccolo-orm/piccolo
67
/ 100
Health
do not use

piccolo has critical vulnerabilities — do not use

Update to >= 82679eb8cd1449cf31d87c9914a072e70168b6eb to fix known vulnerabilities

  • 1 critical vulnerabilities
Health breakdown0 – 100
20/25
maintenance
10/20
popularity
15/25
security
15/15
maturity
7/15
community
Vulnerabilities
1
1 critical
Advisories (1)
SeverityIDSummaryFixed in
criticalCVE-2023-47128Piccolo is an object-relational mapping and query builder which supports asyncio. Prior to version 1.1.1, the handling of named transaction `savepoints` in all database implementations is vulnerable to SQL Injection via f-strings. While the likelihood of an end developer exposing a `savepoints` `name` parameter to a user is highly unlikely, it would not be unheard of. If a malicious user was able to abuse this functionality they would have essentially direct access to the database and the abilit82679eb8cd1449cf31d87c9914a072e70168b6eb

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/pypi/piccolo

Last updated · 2026-03-06T17:13:04.487887Z

piccolo — Health Score 67/100 | DepScope