PyPI Package Analyzer
Pricing
from $1.00 / 1,000 item processeds
PyPI Package Analyzer
Analyze PyPI Python packages: download stats (day/week/month), release history, maintainers, dependencies, classifiers, and vulnerability scan via OSV.dev. Supports bulk analysis of package lists. No API key required.
Pricing
from $1.00 / 1,000 item processeds
Rating
0.0
(0)
Developer
Hojun Lee
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
2 days ago
Last modified
Categories
Share
PyPI Package Analyzer retrieves download statistics, release history, maintainer info, dependencies, and vulnerability data for any Python package — sourcing from PyPI JSON API, pypistats.org, and OSV.dev. Analyze up to 200 packages per run concurrently. No API key required.
Whether you're auditing dependencies for security, comparing library adoption, or building a Python ecosystem intelligence tool, this actor delivers structured package data in one run.
Why use PyPI Package Analyzer?
- Security auditing before deployment — Check all dependencies for known CVEs before shipping. OSV.dev integration surfaces all advisories for the exact version in use, not just the latest.
- Library adoption comparison — Compare download counts for competing libraries (e.g.,
requestsvshttpxvsaiohttp) to pick the most widely used option for your stack. - Dependency health screening — Check
latest_release_dateandrelease_countto identify abandoned packages. A library with no releases in 2+ years is a maintenance risk. - Open source intelligence — Track which organizations maintain popular packages, who the top maintainers are, and how package stewardship has shifted over time.
- Bulk dependency analysis — Paste your entire
requirements.txtand get a full health + vulnerability report for your entire dependency tree in one run.
How to use
- Open the actor on Apify Store and click Try for free.
- Paste your package list into
packages(e.g.["requests", "numpy", "fastapi"]). - Enable
includeVulnerabilities(default on) to check OSV.dev for known CVEs. - Enable
includeDownloadStats(default on) for daily/weekly/monthly download counts. - Click Start. Returns one record per package with full metadata, download stats, and vulnerabilities.
Input
| Field | Type | Default | Description |
|---|---|---|---|
packages | string[] | required | PyPI package names to analyze (e.g. ["requests", "numpy", "fastapi"]) |
includeVulnerabilities | boolean | true | Query OSV.dev for known CVEs and security advisories |
includeDownloadStats | boolean | true | Fetch day/week/month download counts from pypistats.org |
maxPackages | integer | 50 | Maximum packages per run (1–200) |
Output
{"name": "requests","version": "2.32.3","summary": "Python HTTP for Humans.","author": "Kenneth Reitz","license": "Apache-2.0","requires_python": ">=3.8","requires_dist": ["charset-normalizer<4,>=2", "idna<4,>=2.5", "urllib3<3,>=1.21.1"],"home_page": "https://requests.readthedocs.io","project_url": "https://github.com/psf/requests","release_count": 47,"first_release": "2011-02-14","latest_release_date": "2024-05-29","downloads_day": 8421832,"downloads_week": 58943217,"downloads_month": 241789432,"vulnerability_count": 0,"vulnerabilities": [],"fetched_at": "2026-08-29T10:30:00.000000+00:00"}
Output fields
| Field | Type | Description |
|---|---|---|
name | string | PyPI package name |
version | string | Latest stable version |
license | string | SPDX license identifier |
requires_python | string | Python version requirement |
requires_dist | string[] | Raw dependency specifiers |
release_count | integer | Total number of releases published |
first_release | string | Date of first version release |
latest_release_date | string | Date of most recent release |
downloads_day | integer | Downloads in last 24 hours |
downloads_week | integer | Downloads in last 7 days |
downloads_month | integer | Downloads in last 30 days |
vulnerability_count | integer | Number of known CVEs/advisories |
vulnerabilities | object[] | Full advisory objects from OSV.dev |
APIs used
| API | Endpoint | Purpose |
|---|---|---|
| PyPI JSON API | https://pypi.org/pypi/{package}/json | Metadata, releases, dependencies |
| PyPI Stats | https://pypistats.org/api/packages/{package}/recent | Download counts |
| OSV.dev | https://api.osv.dev/v1/query | Vulnerability database |
All APIs are free and require no authentication.
Cost estimation
Pay-Per-Event: $0.005 per actor start + $0.003 per package analyzed.
| Use case | Packages | Estimated cost |
|---|---|---|
| 10 dependency audit | 10 | ~$0.03/run |
| Full requirements.txt (50 packages) | 50 | ~$0.15/run |
| Bulk ecosystem scan (200 packages) | 200 | ~$0.60/run |
| Weekly security check (30 packages) | 30 | ~$0.09/week |
FAQ
Does the vulnerability check cover all versions or just the latest?
OSV.dev returns all advisories for the package — you can check affected.versions in each advisory to see which versions are impacted. The actor returns the raw advisory objects so you can cross-reference with your pinned version.
How current are download stats? pypistats.org download data lags by approximately 24 hours. The counts represent downloads from the PyPI CDN (not mirrors), which is the industry standard measure.
Can I use this to compare pandas vs polars vs dask?
Yes — pass ["pandas", "polars", "dask"] and compare downloads_month for adoption and latest_release_date + release_count for maintenance health.
Are packages that fail to fetch charged? No — packages that return a 404 (not found) or API error are skipped and not charged.
Related actors
- GitHub Repository Stats Tracker — Complement download stats with GitHub stars, forks, and issue count for the same packages
- Wikidata SPARQL Query — Structured data on the organizations behind major Python packages
Feedback
If this actor is useful, a quick review helps other Python developers find it: Leave a review on Apify Store
Keywords: PyPI package analyzer, Python package vulnerability scan, OSV.dev security check, PyPI dependency graph, package release history, Python maintainer lookup, pip package audit, Python package classifiers, bulk package analysis, Python library security, PyPI metadata scraper, open source dependency tracker, package download stats, Python ecosystem monitor