Package Registry Scraper — npm, PyPI & crates.io
Pricing
from $2.00 / 1,000 packages
Package Registry Scraper — npm, PyPI & crates.io
Scrape software packages from npm, PyPI, crates.io, RubyGems and Packagist through one unified schema: version, description, licence, downloads, dependents, dependency and version counts, maintainers, repository, publish dates and deprecation status. No API key.
Pricing
from $2.00 / 1,000 packages
Rating
0.0
(0)
Developer
Hichem Ben Moussa
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
a day ago
Last modified
Categories
Share
Package Registry Scraper — npm, PyPI, crates.io & More
Scrape software packages from five registries through one unified schema: npm (JavaScript), PyPI (Python), crates.io (Rust), RubyGems (Ruby) and Packagist (PHP).
Downloads, licences, dependency and version counts, maintainers, repository links, publish dates and deprecation status — the same field names whatever the ecosystem, so one pipeline handles all five.
No API key required.
What you get
| Field | Description |
|---|---|
registry | Which registry the row came from |
name, version | Package identity and current version |
description | Summary |
license | Licence identifier |
homepage, repository | Links, with git URLs normalised to browsable HTTPS |
author, maintainers, maintainerCount | A single maintainer on a widely used package is a supply-chain risk signal |
downloadsLastWeek, downloadsLastMonth, downloadsTotal | Whichever the registry publishes |
dependents | How many packages depend on this one |
dependencyCount | How many it pulls in itself |
versionCount | Release count |
publishedAt, lastPublishedAt | First and latest release — the staleness signal |
stars, forks, openIssues | Repository stats, where the registry exposes them |
requiresRuntime | Node/Python/PHP/Rust version constraint |
isDeprecated, deprecationReason | Deprecated or yanked, and why |
url | Package page |
Coverage by registry
Registries publish different things, and this actor reports what each one actually has rather than inventing the rest:
| npm | PyPI | crates.io | RubyGems | Packagist | |
|---|---|---|---|---|---|
| Keyword search | ✅ | ❌ | ✅ | ✅ | ✅ |
| Weekly / monthly downloads | ✅ | ❌ | monthly | ❌ | monthly |
| Lifetime downloads | ❌ | ❌ | ✅ | ✅ | ✅ |
| Dependents count | ✅ | ❌ | ❌ | ❌ | ✅ |
| Repository stars | ❌ | ❌ | ❌ | ❌ | ✅ |
| Version count | ❌ | ✅ | ✅ | ❌ | ✅ |
PyPI has retired its public search API — it now returns an HTML page, not JSON. So for PyPI you must name the packages you want in Specific packages; a search term there returns nothing and the actor says so in the log instead of failing quietly. PyPI also publishes no download counts through its JSON API.
Example input
{"registry": "npm","searchTerm": "http client","minDownloads": 100000,"maxPackages": 100}
Audit an exact dependency list, on any registry:
{ "registry": "pypi", "packages": ["requests", "urllib3", "certifi"] }{ "registry": "npm", "packages": ["express", "@types/node", "lodash"] }{ "registry": "crates", "packages": ["serde", "tokio"] }
Example output
{"registry": "npm","name": "express","version": "5.2.1","description": "Fast, unopinionated, minimalist web framework","license": "MIT","repository": "https://github.com/expressjs/express","maintainers": ["wesleytodd", "jonchurch"],"maintainerCount": 2,"downloadsLastWeek": 158867531,"downloadsLastMonth": 536200734,"dependencyCount": 31,"isDeprecated": false,"url": "https://www.npmjs.com/package/express"}
Who uses this
- Developer-tool marketing — size your category: which packages in "http client" have real adoption, and which are abandoned
- Supply-chain security — flag dependencies that are deprecated, single-maintainer, or have not shipped in years
- Licence compliance — pull the licence for every package in your manifest across all five ecosystems in one run
- Open-source maintainers — track your download curve against direct competitors weekly
- Technical due diligence — assess a target's dependency health before an acquisition
- Package comparison sites — populate a directory with real numbers rather than estimates
The staleness screen is the most valuable one: lastPublishedAt more than a year old plus a high dependents count is exactly the shape of the dependencies that cause incidents.
Notes
- npm's per-package document is ~800 KB because it embeds every version and the readme. The actor reads the compact
/latestview and fetches download counts separately, which keeps runs fast. - Download windows are not comparable across registries. npm reports a rolling week and month; crates.io and Packagist report monthly plus lifetime; RubyGems reports lifetime only. Compare within a registry, not across them, and use
minDownloadsknowing it tests the best figure available for that row. - Search results are ranked by the registry's own relevance or download sort, not re-ranked here.
isDeprecatedcovers npm'sdeprecatedfield, PyPI and crates.io yanks, and RubyGems yanks — different mechanisms, one boolean.- This is an unofficial actor and is not affiliated with npm, the PSF, the Rust Foundation, RubyGems or Packagist.
Pricing
Pay per result. Each package returned counts as one result, and the download filter is applied before charging.