{"package":"pip","ecosystem":"pypi","latest_version":"26.2.1","description":"The PyPA recommended tool for installing Python packages.","license":"MIT","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://pypi.org/project/pip/","repository":"https://github.com/pypa/pip","downloads_weekly":94198460,"health":{"score":93,"risk":"low","breakdown":{"maintenance":25,"popularity":20,"security":25,"maturity":15,"community":8,"popularity_floor":0},"deprecated":false,"max_score":100},"vulnerabilities":{"count":0,"critical":0,"high":0,"medium":0,"low":0,"details":[]},"versions":{"latest":"26.2.1","total_count":159,"recent":["24.1b2","24.1","24.1.1","24.1.2","24.2","24.3","24.3.1","25.0","25.0.1","25.1","25.1.1","25.2","25.3","26.0","26.0.1","26.1","26.1.1","26.1.2","26.2","26.2.1"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":0,"first_published":null,"last_published":"2026-08-04T22:51:12.472093Z","dependencies_count":0,"dependencies":[]},"github_stats":{"stars":10288,"forks":3387,"open_issues":951,"is_archived":false,"pushed_at":"2026-09-23T23:12:15Z","subscribers_count":316},"bundle":null,"typescript":null,"known_issues":{"bugs_count":25,"bugs_severity":{"high":4,"medium":20,"low":1},"status_breakdown":{"fixed":24,"open":1},"link":"/api/bugs/pypi/pip?version=26.2.1","scope":"version","details":[{"title":"Path Traversal in pip","severity":"high","status":"fixed","affected_version":null,"fixed_version":"19.2","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-20916"},{"title":"Improper Input Validation in pip","severity":"high","status":"fixed","affected_version":null,"fixed_version":"1.3","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-1629"},{"title":"Improper Authentication in pip","severity":"high","status":"fixed","affected_version":null,"fixed_version":"1.5","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-5123"},{"title":"Improper Input Validation in pip","severity":"high","status":"fixed","affected_version":null,"fixed_version":"21.1","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3572"},{"title":"PYSEC-2026-3721: advisory","severity":"medium","status":"fixed","affected_version":null,"fixed_version":"26.2","url":"http://www.openwall.com/lists/oss-security/2026/07/29/7"}]},"historical_compromise":null,"recommendation":{"action":"safe_to_use","issues":[],"use_version":"26.2.1","version_hint":null,"summary":"pip@26.2.1 is safe to use (health: 93/100)"},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/pypi/pip","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/pypi/pip","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/pypi/pip","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate"},"_cache":"hit","_response_ms":0}