Is pip healthy, maintained, and safe?
Maintained, but watch it — pip has real signals (drift, thin maintenance, or advisories) worth tracking.
The verdict
pip earns a health score of 55/100, a medium risk rating, computed deterministically from live PyPI release history, and the OSV vulnerability database. Maintained, but watch it — pip has real signals (drift, thin maintenance, or advisories) worth tracking.
Its most recent release shipped on 4 August 2026 — 33 days ago — so development is clearly active. Across 156 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.
OSV lists 26 known advisories for pip, including 4 high. Review whether your version is in the affected range and whether a fixed release is available before depending on it. Each advisory is listed with its OSV/GHSA identifier below.
pip is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail — deterministic, auditable
Known vulnerabilities (26)
Improper Link Resolution Before File Access in pip
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
pip lack of randomness in build directory
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
Improper Input Validation in pip
pip Path Traversal vulnerability
Improper Authentication in pip
Improper Input Validation in pip
Path Traversal in pip
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
Command Injection in pip when used with Mercurial
pip would incorrectly handle doubly-encoded package URLs from indexes
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code vi
pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwri
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest
When installing a package from a Mercurial VCS URL (ie "pip install
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
pip Path Traversal vulnerability
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outs
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.
Key facts
- Latest version
- v26.2.1
- Last release
- 4 August 2026 (33 days ago)
- Total releases
- 156
- First release
- 28 October 2008
- Package age
- 17.9 years
- Maintainers
- not exposed by PyPI
- Known advisories
- 26
- Confidence
- High
Frequently asked
Is pip still maintained?
Yes — pip released as recently as 4 August 2026 (33 days ago), so it is actively maintained.
Does pip have known security vulnerabilities?
Yes — OSV lists 26 advisories for pip. See the advisory list on this page for the OSV/GHSA identifiers.
Is pip safe to use?
Maintained, but watch it — pip has real signals (drift, thin maintenance, or advisories) worth tracking. OSPulse rates it 55/100 (medium risk) based on release recency, cadence and known vulnerabilities.
Other PyPI packages we've checked
pip is one package. What about the other hundreds in your tree?
Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the PyPI registry & OSV.dev · snapshot generated 2026-09-07 · scores are deterministic and recomputed on each refresh.
