quick-xml

A high-performance, near-zero-copy XML pull parser and writer for Rust

Library
Cargo
v0.42.0
1,570 stars
MIT License

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
84 /100 Excellent
Development Activity 84
Maintenance 84
Community 68
Maturity 60
Momentum 40

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
75 /100 Good
Architecture 80
Code Quality 85
Innovation 75
Learning Curve 60

quick-xml is a Rust library for reading and writing XML that prioritizes raw throughput and low memory overhead. Its reader is a pull-based event API — callers drive a loop pulling Start/End/Text/Eof events rather than being pushed a full DOM tree — and it borrows from the input buffer using Cow wherever possible instead of copying, while letting callers reuse buffers across reads to keep allocations low.

Beyond the low-level event reader/writer, quick-xml ships an optional serialize feature that integrates with Serde’s Serialize/Deserialize traits, letting Rust structs map directly to XML elements and attributes (including the special $text/$value conventions for tag bodies). Benchmarks in the project’s own README show it roughly 10-50x faster than the older xml-rs crate, which has made it the default choice for XML-heavy Rust codebases handling large or high-throughput documents.

What You Get

  • A pull-based Reader emitting borrowed (Cow-backed) Start/End/Text/Eof events with minimal copying
  • A Writer API for constructing XML documents element-by-element, including attribute manipulation
  • Optional Serde Serialize/Deserialize support for mapping Rust structs directly to XML via the serialize feature
  • An encoding feature for handling non-UTF-8 XML documents and namespace resolution
  • Reusable read buffers so long-running parsers can keep allocation overhead low

Common Use Cases

  • Parsing large or high-throughput XML documents (logs, feeds, exports) where allocation overhead matters
  • Deserializing/serializing typed configuration or data-interchange formats expressed as XML via Serde
  • Building XML-based file format readers/writers (e.g. SVG, RSS, Office Open XML-style formats)
  • Streaming XML processing where holding a full DOM in memory is undesirable

Under The Hood

Architecture: quick-xml centers on a pull-parser Reader that callers drive in a loop, calling read_event() or read_event_into() and matching on an Event enum (Start, End, Text, Eof, and others) rather than the library pushing a full parsed tree; a companion Writer mirrors this by accepting Event values and serializing them back to bytes via a Cursor-backed sink. Because the reader hands back borrowed Cow-based views into the input rather than copying by default, the API pushes callers to manage a scratch buffer themselves (buf.clear() between iterations), trading some ergonomic overhead for lower allocation pressure. The optional serde module layers typed (de)serialization on top of this same event stream, translating XML elements/attributes to Rust struct fields using @-prefixed and $text/$value naming conventions inspired by serde-xml-rs.

Tech Stack: The crate is pure Rust (100% of tracked bytes) with an MSRV of 1.79.0, gated features for encoding (non-UTF-8 input) and serialize (Serde integration) so consumers opt into only the functionality they need, and a documented benchmark suite comparing itself against xml-rs and serde-xml-rs to substantiate its performance claims.

Code Quality: The repository includes 25 dedicated test files under tests/, a fuzz/ directory for fuzz-testing the parser against malformed input, a benches/ directory with criterion-style benchmarks, and a test-gen/ helper for generating additional test fixtures — a notably mature testing setup for a parsing library where malformed-input robustness matters. CI runs via GitHub Actions (badge in README) and the project publishes coverage via codecov. With 135 contributors and steady commit cadence (34 tagged releases, ~17 commits/month), maintenance is active and broad-based rather than single-maintainer.

API Design: The event-driven Reader/Writer API keeps the core surface small — a handful of methods (read_event, write_event, config_mut) cover most usage — but requires callers to understand pull-parsing and buffer-reuse patterns upfront, which raises the initial learning curve compared to a simple parse_str() -> Document API. The optional serde layer substantially lowers this barrier for typed use cases, letting users skip the event loop entirely and just derive Serialize/Deserialize on their structs.

Used by 7 apps in this directory

TypeScript
80%
GPL 3.0

Bramble

Authentication · Password Manager · Security

399

Local-first, end-to-end encrypted password manager that syncs your vault directly between your own devices over a private peer-to-peer mesh — no server, no account, no cloud in the middle.

View details
75
Repo Health
84
Technical
68
Dependency
Built with
TypeScript 80%
Updated 5 days ago
Rust
80%
MIT

fabro

Developer Tools · Devops

1,658

Define AI agent workflows as code graphs, route tasks across any LLM, and intervene only where it matters.

View details
82
Repo Health
83
Technical
67
Dependency
Built with
Rust 80%
TypeScript 15%
Updated 5 days ago
Rust
99%
Other

Fluree DB

Databases

469

A temporal, verifiable graph database with git-like branching, integrated vector/text/geo search, and RDF/SPARQL/JSON-LD/openCypher support — benchmarked at 10.4x faster than the next database on the full Wikidata dump.

View details
87
Repo Health
74
Technical
65
Dependency
Built with
Rust 99%
Updated 5 days ago
Rust
52%
Other

Jan

AI Assistants

44,680

Run LLMs 100% locally with full privacy, or connect to cloud AI — your machine, your data, your control.

View details
90
Repo Health
81
Technical
65
Dependency
Built with
Rust 52%
TypeScript 44%
Updated 4 days ago
Rust
68%
MIT

Readur

Bookmarks Archiving · File Storage · Knowledge Management

797

A self-hosted document management system that OCRs, indexes, and makes every PDF, scan, and Office file instantly searchable.

View details
81
Repo Health
78
Technical
67
Dependency
Built with
Rust 68%
TypeScript 30%
Updated 4 days ago
Rust
98%

Stalwart

Collaboration

14,848

All-in-one secure mail and collaboration server covering IMAP, JMAP, SMTP, CalDAV, CardDAV, and WebDAV in a single memory-safe Rust binary.

View details
89
Repo Health
81
Technical
65
Dependency
Built with
Rust 98%
Updated 5 days ago
Rust
64%
Apache 2.0

Temps

Analytics · Devops · Monitoring

801

A self-hosted Rust PaaS that replaces Vercel, Sentry, PostHog, Pingdom, Resend, and E2B with one binary — plus 440+ CLI operations agents like Claude Code can drive directly.

View details
81
Repo Health
86
Technical
70
Dependency
Built with
Rust 64%
TypeScript 34%
Updated 4 days ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers