Is celery healthy, maintained, and safe?
Maintained, but watch it — celery has real signals (drift, thin maintenance, or advisories) worth tracking.
The verdict
celery earns a health score of 56/100, a medium risk rating, computed deterministically from live PyPI release history, and the OSV vulnerability database. Maintained, but watch it — celery has real signals (drift, thin maintenance, or advisories) worth tracking.
The last release was 26 March 2026 (124 days ago); still within a normal window, but the cadence has quietened. Across 222 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.
OSV lists 4 known advisories for celery, including 1 high. Review whether your version is in the affected range and whether a fixed release is available before depending on it. Each advisory is listed with its OSV/GHSA identifier below.
celery is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail — deterministic, auditable
Known vulnerabilities (4)
OS Command Injection in celery
Celery local privilege escalation vulnerability
Celery 2.1 and 2.2 before 2.2.8, 2.3 before 2.3.4, and 2.4 before 2.4.4 changes the effective id but not the real id during processing of the --uid and --gid arguments to celerybeat, celeryd_detach, c
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized.
Key facts
- Latest version
- v5.6.3
- Last release
- 26 March 2026 (124 days ago)
- Total releases
- 222
- First release
- 27 April 2009
- Package age
- 17.3 years
- Maintainers
- not exposed by PyPI
- Known advisories
- 4
- Confidence
- High
Frequently asked
Is celery still maintained?
Partly — the most recent release was 26 March 2026 (124 days ago), so maintenance has slowed but not fully stopped.
Does celery have known security vulnerabilities?
Yes — OSV lists 4 advisories for celery. See the advisory list on this page for the OSV/GHSA identifiers.
Is celery safe to use?
Maintained, but watch it — celery has real signals (drift, thin maintenance, or advisories) worth tracking. OSPulse rates it 56/100 (medium risk) based on release recency, cadence and known vulnerabilities.
Other PyPI packages we've checked
celery is one package. What about the other hundreds in your tree?
Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the PyPI registry & OSV.dev · snapshot generated 2026-07-28 · scores are deterministic and recomputed on each refresh.
