Package Registry Scraper — npm, PyPI & crates.io avatar

Package Registry Scraper — npm, PyPI & crates.io

Pricing

from $2.00 / 1,000 packages

Go to Apify Store
Package Registry Scraper — npm, PyPI & crates.io

Package Registry Scraper — npm, PyPI & crates.io

Scrape software packages from npm, PyPI, crates.io, RubyGems and Packagist through one unified schema: version, description, licence, downloads, dependents, dependency and version counts, maintainers, repository, publish dates and deprecation status. No API key.

Pricing

from $2.00 / 1,000 packages

Rating

0.0

(0)

Developer

Hichem Ben Moussa

Hichem Ben Moussa

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

a day ago

Last modified

Share

Package Registry Scraper — npm, PyPI, crates.io & More

Scrape software packages from five registries through one unified schema: npm (JavaScript), PyPI (Python), crates.io (Rust), RubyGems (Ruby) and Packagist (PHP).

Downloads, licences, dependency and version counts, maintainers, repository links, publish dates and deprecation status — the same field names whatever the ecosystem, so one pipeline handles all five.

No API key required.

What you get

FieldDescription
registryWhich registry the row came from
name, versionPackage identity and current version
descriptionSummary
licenseLicence identifier
homepage, repositoryLinks, with git URLs normalised to browsable HTTPS
author, maintainers, maintainerCountA single maintainer on a widely used package is a supply-chain risk signal
downloadsLastWeek, downloadsLastMonth, downloadsTotalWhichever the registry publishes
dependentsHow many packages depend on this one
dependencyCountHow many it pulls in itself
versionCountRelease count
publishedAt, lastPublishedAtFirst and latest release — the staleness signal
stars, forks, openIssuesRepository stats, where the registry exposes them
requiresRuntimeNode/Python/PHP/Rust version constraint
isDeprecated, deprecationReasonDeprecated or yanked, and why
urlPackage page

Coverage by registry

Registries publish different things, and this actor reports what each one actually has rather than inventing the rest:

npmPyPIcrates.ioRubyGemsPackagist
Keyword search✅❌✅✅✅
Weekly / monthly downloads✅❌monthly❌monthly
Lifetime downloads❌❌✅✅✅
Dependents count✅❌❌❌✅
Repository stars❌❌❌❌✅
Version count❌✅✅❌✅

PyPI has retired its public search API — it now returns an HTML page, not JSON. So for PyPI you must name the packages you want in Specific packages; a search term there returns nothing and the actor says so in the log instead of failing quietly. PyPI also publishes no download counts through its JSON API.

Example input

{
"registry": "npm",
"searchTerm": "http client",
"minDownloads": 100000,
"maxPackages": 100
}

Audit an exact dependency list, on any registry:

{ "registry": "pypi", "packages": ["requests", "urllib3", "certifi"] }
{ "registry": "npm", "packages": ["express", "@types/node", "lodash"] }
{ "registry": "crates", "packages": ["serde", "tokio"] }

Example output

{
"registry": "npm",
"name": "express",
"version": "5.2.1",
"description": "Fast, unopinionated, minimalist web framework",
"license": "MIT",
"repository": "https://github.com/expressjs/express",
"maintainers": ["wesleytodd", "jonchurch"],
"maintainerCount": 2,
"downloadsLastWeek": 158867531,
"downloadsLastMonth": 536200734,
"dependencyCount": 31,
"isDeprecated": false,
"url": "https://www.npmjs.com/package/express"
}

Who uses this

  • Developer-tool marketing — size your category: which packages in "http client" have real adoption, and which are abandoned
  • Supply-chain security — flag dependencies that are deprecated, single-maintainer, or have not shipped in years
  • Licence compliance — pull the licence for every package in your manifest across all five ecosystems in one run
  • Open-source maintainers — track your download curve against direct competitors weekly
  • Technical due diligence — assess a target's dependency health before an acquisition
  • Package comparison sites — populate a directory with real numbers rather than estimates

The staleness screen is the most valuable one: lastPublishedAt more than a year old plus a high dependents count is exactly the shape of the dependencies that cause incidents.

Notes

  • npm's per-package document is ~800 KB because it embeds every version and the readme. The actor reads the compact /latest view and fetches download counts separately, which keeps runs fast.
  • Download windows are not comparable across registries. npm reports a rolling week and month; crates.io and Packagist report monthly plus lifetime; RubyGems reports lifetime only. Compare within a registry, not across them, and use minDownloads knowing it tests the best figure available for that row.
  • Search results are ranked by the registry's own relevance or download sort, not re-ranked here.
  • isDeprecated covers npm's deprecated field, PyPI and crates.io yanks, and RubyGems yanks — different mechanisms, one boolean.
  • This is an unofficial actor and is not affiliated with npm, the PSF, the Rust Foundation, RubyGems or Packagist.

Pricing

Pay per result. Each package returned counts as one result, and the download filter is applied before charging.