Flask-WTF

Simple integration of Flask and WTForms with built-in CSRF, file upload, and reCAPTCHA support

Library
PyPI
v1.3.0
1,510 stars
BSD 3-Clause License

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
64 /100 Good
Development Activity 40
Maintenance 40
Community 88
Maturity 60
Momentum 28

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
75 /100 Good
Architecture 74
Code Quality 80
Innovation 60
Learning Curve 85

Flask-WTF wires WTForms into Flask by binding form data automatically to flask.request.form/request.files, and layers on the pieces most Flask apps need but WTForms doesn’t provide out of the box: CSRF protection via CSRFProtect and generate_csrf(), secure file-upload fields, and reCAPTCHA integration.

Maintained under the Pallets ecosystem (the same organization behind Flask and Jinja), it is the de facto standard way to add HTML form handling and validation to a Flask application without hand-rolling CSRF tokens or file-upload validation yourself.

What You Get

  • FlaskForm, a WTForms Form subclass that auto-binds to flask.request.form/request.files
  • Built-in CSRF protection via CSRFProtect and generate_csrf()/validate_csrf()
  • A FileField/FileRequired/FileAllowed set of fields and validators for secure file uploads
  • reCAPTCHA field and widget integration for spam protection on public forms
  • i18n support for translating form labels/error messages via Flask-Babel

Common Use Cases

  • Adding CSRF-protected HTML forms (login, registration, contact) to a Flask app
  • Handling file upload forms with server-side validation of file type and presence
  • Protecting public-facing forms from spam using integrated reCAPTCHA fields
  • Building multi-language forms where labels and validation errors need translation

Under The Hood

Architecture - The package is a thin, focused integration layer: form.py defines FlaskForm, which overrides WTForms’ Meta class to source CSRF configuration from current_app.config and delegates CSRF validation to a _FlaskFormCSRF meta-class hook defined in csrf.py; csrf.py additionally exposes a standalone CSRFProtect Flask extension that can protect an entire app’s views (not just FlaskForm submissions) via a Flask Blueprint and before-request hook.

Tech Stack - A small, dependency-light Python package (~720 lines across src/flask_wtf/) built on pyproject.toml/hatchling, depending directly on flask, wtforms, werkzeug, markupsafe, and itsdangerous for signed CSRF tokens; no compiled extensions or heavy transitive dependencies.

Code Quality - Six test modules cover FlaskForm binding, CSRF validation (including token expiry via itsdangerous.SignatureExpired), and file-field validators; the codebase is small enough that each module maps to one concern (form.py, csrf.py, file.py, i18n.py, recaptcha/), keeping the surface easy to audit given its security-sensitive role (CSRF token generation/validation).

API Design - Subclassing FlaskForm instead of WTForms’ Form is the only change most users need to make; CSRF protection is on by default and configured entirely through Flask app config keys (WTF_CSRF_ENABLED, WTF_CSRF_SECRET_KEY), which keeps the API surface minimal and consistent with Flask’s own configuration conventions, at the cost of some “magic” for developers unfamiliar with how Flask config cascades into form behavior.

Used by 5 apps in this directory

Python
89%
Apache 2.0

Apache Airflow

Data Engineering

46,995

Define, schedule, and monitor complex data workflows as Python code — with a powerful UI, 80+ provider integrations, and battle-tested scalability across thousands of production deployments.

View details
96
Repo Health
89
Technical
64
Dependency
Built with
Python 89%
Updated 4 days ago
Python
79%
Apache 2.0

changedetection.io

Monitoring

34,605

Self-hosted website change detection with AI-powered smart alerts, browser automation, price tracking, and 85+ notification channels.

View details
91
Repo Health
80
Technical
68
Dependency
Built with
Python 79%
Updated 1 weeks ago
Python
58%
Apache 2.0

MLflow

AI Development · Monitoring

28,154

The open source AI engineering platform for debugging, evaluating, monitoring, and optimizing production LLMs and agents at scale.

View details
97
Repo Health
86
Technical
66
Dependency
Built with
Python 58%
TypeScript 33%
Updated 4 days ago
Python
46%
Other

Redash

Analytics · Data Engineering

28,817

Redash lets anyone connect to 35+ SQL and NoSQL data sources, write a query in the browser, and turn the result into a shared dashboard — no separate BI suite required.

View details
92
Repo Health
74
Technical
60
Dependency
Built with
Python 46%
JavaScript 30%
TypeScript 17%
Updated 4 days ago
Python
54%
AGPL 3.0

Speakr

AI Assistants

4,030

Self-hosted AI transcription with speaker diarization, smart tagging, and multi-user collaboration — your recordings stay on your infrastructure.

View details
82
Repo Health
79
Technical
70
Dependency
Built with
Python 54%
HTML 24%
JavaScript 19%
Updated 1 weeks ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers