# PyPI Package Analyzer (`gochujang/pypi-package-analyzer`) Actor

Analyze PyPI Python packages: download stats (day/week/month), release history, maintainers, dependencies, classifiers, and vulnerability scan via OSV.dev. Supports bulk analysis of package lists. No API key required.

- **URL**: https://apify.com/gochujang/pypi-package-analyzer.md
- **Developed by:** [Hojun Lee](https://apify.com/gochujang) (community)
- **Categories:** Developer tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $1.00 / 1,000 item processeds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## PyPI Package Analyzer

**PyPI Package Analyzer** retrieves **download statistics, release history, maintainer info, dependencies, and vulnerability data** for any Python package — sourcing from PyPI JSON API, pypistats.org, and OSV.dev. Analyze up to 200 packages per run concurrently. No API key required.

Whether you're auditing dependencies for security, comparing library adoption, or building a Python ecosystem intelligence tool, this actor delivers structured package data in one run.

***

### Why use PyPI Package Analyzer?

1. **Security auditing before deployment** — Check all dependencies for known CVEs before shipping. OSV.dev integration surfaces all advisories for the exact version in use, not just the latest.
2. **Library adoption comparison** — Compare download counts for competing libraries (e.g., `requests` vs `httpx` vs `aiohttp`) to pick the most widely used option for your stack.
3. **Dependency health screening** — Check `latest_release_date` and `release_count` to identify abandoned packages. A library with no releases in 2+ years is a maintenance risk.
4. **Open source intelligence** — Track which organizations maintain popular packages, who the top maintainers are, and how package stewardship has shifted over time.
5. **Bulk dependency analysis** — Paste your entire `requirements.txt` and get a full health + vulnerability report for your entire dependency tree in one run.

***

### How to use

1. Open the actor on Apify Store and click **Try for free**.
2. Paste your package list into `packages` (e.g. `["requests", "numpy", "fastapi"]`).
3. Enable `includeVulnerabilities` (default on) to check OSV.dev for known CVEs.
4. Enable `includeDownloadStats` (default on) for daily/weekly/monthly download counts.
5. Click **Start**. Returns one record per package with full metadata, download stats, and vulnerabilities.

***

### Input

| Field | Type | Default | Description |
|-------|------|---------|-------------|
| `packages` | string\[] | required | PyPI package names to analyze (e.g. `["requests", "numpy", "fastapi"]`) |
| `includeVulnerabilities` | boolean | `true` | Query OSV.dev for known CVEs and security advisories |
| `includeDownloadStats` | boolean | `true` | Fetch day/week/month download counts from pypistats.org |
| `maxPackages` | integer | `50` | Maximum packages per run (1–200) |

***

### Output

```json
{
  "name": "requests",
  "version": "2.32.3",
  "summary": "Python HTTP for Humans.",
  "author": "Kenneth Reitz",
  "license": "Apache-2.0",
  "requires_python": ">=3.8",
  "requires_dist": ["charset-normalizer<4,>=2", "idna<4,>=2.5", "urllib3<3,>=1.21.1"],
  "home_page": "https://requests.readthedocs.io",
  "project_url": "https://github.com/psf/requests",
  "release_count": 47,
  "first_release": "2011-02-14",
  "latest_release_date": "2024-05-29",
  "downloads_day": 8421832,
  "downloads_week": 58943217,
  "downloads_month": 241789432,
  "vulnerability_count": 0,
  "vulnerabilities": [],
  "fetched_at": "2026-08-29T10:30:00.000000+00:00"
}
```

#### Output fields

| Field | Type | Description |
|-------|------|-------------|
| `name` | string | PyPI package name |
| `version` | string | Latest stable version |
| `license` | string | SPDX license identifier |
| `requires_python` | string | Python version requirement |
| `requires_dist` | string\[] | Raw dependency specifiers |
| `release_count` | integer | Total number of releases published |
| `first_release` | string | Date of first version release |
| `latest_release_date` | string | Date of most recent release |
| `downloads_day` | integer | Downloads in last 24 hours |
| `downloads_week` | integer | Downloads in last 7 days |
| `downloads_month` | integer | Downloads in last 30 days |
| `vulnerability_count` | integer | Number of known CVEs/advisories |
| `vulnerabilities` | object\[] | Full advisory objects from OSV.dev |

***

### APIs used

| API | Endpoint | Purpose |
|-----|----------|---------|
| PyPI JSON API | `https://pypi.org/pypi/{package}/json` | Metadata, releases, dependencies |
| PyPI Stats | `https://pypistats.org/api/packages/{package}/recent` | Download counts |
| OSV.dev | `https://api.osv.dev/v1/query` | Vulnerability database |

All APIs are free and require no authentication.

***

### Cost estimation

**Pay-Per-Event: $0.005 per actor start + $0.003 per package analyzed.**

| Use case | Packages | Estimated cost |
|----------|----------|----------------|
| 10 dependency audit | 10 | ~$0.03/run |
| Full requirements.txt (50 packages) | 50 | ~$0.15/run |
| Bulk ecosystem scan (200 packages) | 200 | ~$0.60/run |
| Weekly security check (30 packages) | 30 | ~$0.09/week |

***

### FAQ

**Does the vulnerability check cover all versions or just the latest?**
OSV.dev returns all advisories for the package — you can check `affected.versions` in each advisory to see which versions are impacted. The actor returns the raw advisory objects so you can cross-reference with your pinned version.

**How current are download stats?**
pypistats.org download data lags by approximately 24 hours. The counts represent downloads from the PyPI CDN (not mirrors), which is the industry standard measure.

**Can I use this to compare `pandas` vs `polars` vs `dask`?**
Yes — pass `["pandas", "polars", "dask"]` and compare `downloads_month` for adoption and `latest_release_date` + `release_count` for maintenance health.

**Are packages that fail to fetch charged?**
No — packages that return a 404 (not found) or API error are skipped and not charged.

***

### Related actors

- [GitHub Repository Stats Tracker](https://apify.com/gochujang/github-repo-stats) — Complement download stats with GitHub stars, forks, and issue count for the same packages
- [Wikidata SPARQL Query](https://apify.com/gochujang/wikidata-sparql-query) — Structured data on the organizations behind major Python packages

### Feedback

If this actor is useful, a quick review helps other Python developers find it: [Leave a review on Apify Store](https://apify.com/gochujang/pypi-package-analyzer#reviews)

***

**Keywords:** PyPI package analyzer, Python package vulnerability scan, OSV.dev security check, PyPI dependency graph, package release history, Python maintainer lookup, pip package audit, Python package classifiers, bulk package analysis, Python library security, PyPI metadata scraper, open source dependency tracker, package download stats, Python ecosystem monitor

# Actor input Schema

## `packages` (type: `array`):

List of PyPI package names to analyze

## `includeVulnerabilities` (type: `boolean`):

Check OSV.dev for known vulnerabilities

## `includeDownloadStats` (type: `boolean`):

Fetch daily/weekly/monthly download counts

## `maxPackages` (type: `integer`):

Maximum number of packages to analyze per run (1–200).

## Actor input object example

```json
{
  "packages": [
    "requests",
    "numpy"
  ],
  "includeVulnerabilities": true,
  "includeDownloadStats": true,
  "maxPackages": 50
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "packages": [
        "requests",
        "numpy"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("gochujang/pypi-package-analyzer").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "packages": [
        "requests",
        "numpy",
    ] }

# Run the Actor and wait for it to finish
run = client.actor("gochujang/pypi-package-analyzer").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "packages": [
    "requests",
    "numpy"
  ]
}' |
apify call gochujang/pypi-package-analyzer --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,gochujang/pypi-package-analyzer"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/gWdt3Hc93Zv30VuR4/builds/wermxKiAJJXnVHVyW/openapi.json
