Is scrapy healthy, maintained, and safe?
Maintained, but watch it — Scrapy has real signals (drift, thin maintenance, or advisories) worth tracking.
The verdict
Scrapy earns a health score of 55/100, a medium risk rating, computed deterministically from live PyPI release history, and the OSV vulnerability database. Maintained, but watch it — Scrapy has real signals (drift, thin maintenance, or advisories) worth tracking.
Its most recent release shipped on 7 July 2026 — 20 days ago — so development is clearly active. Across 113 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.
OSV lists 21 known advisories for Scrapy, including 6 high. Review whether your version is in the affected range and whether a fixed release is available before depending on it. Each advisory is listed with its OSV/GHSA identifier below.
Scrapy is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail — deterministic, auditable
Known vulnerabilities (21)
- GHSA-23j4-mw76-5v7h ↗MODERATE
Scrapy allows redirect following in protocols other than HTTP
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
Scrapy leaks the authorization header on same-domain but cross-origin redirects
Scrapy decompression bomb vulnerability
- GHSA-9x8m-2xpf-crp3 ↗MODERATE
Scrapy before 2.6.2 and 1.8.3 vulnerable to one proxy sending credentials to another
Scrapy vulnerable to ReDoS via XMLFeedSpider
Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy
Scrapy authorization header leakage on cross-domain redirect
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
Scrapy denial of service vulnerability
- GHSA-jm3v-qxmh-hxwv ↗MODERATE
Scrapy's redirects ignoring scheme-specific proxy settings
Scrapy HTTP authentication credentials potentially leaked to target websites
- GHSA-mfjm-vh54-3f96 ↗MODERATE
Scrapy cookie-setting is not restricted based on the public suffix list
Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially problematic if the files a
Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests wi
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By crafting malicious XML conte
In scrapy/scrapy, an issue was identified where the Authorization header is not removed during redirects that only change the scheme (e.g., HTTPS to HTTP) but remain within the same domain. This behav
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
Scrapy decompression bomb vulnerability
Scrapy authorization header leakage on cross-domain redirect
Key facts
- Latest version
- v2.17.0
- Last release
- 7 July 2026 (20 days ago)
- Total releases
- 113
- First release
- 12 December 2009
- Package age
- 16.6 years
- Maintainers
- not exposed by PyPI
- Known advisories
- 21
- Confidence
- High
Frequently asked
Is Scrapy still maintained?
Yes — Scrapy released as recently as 7 July 2026 (20 days ago), so it is actively maintained.
Does Scrapy have known security vulnerabilities?
Yes — OSV lists 21 advisories for Scrapy. See the advisory list on this page for the OSV/GHSA identifiers.
Is Scrapy safe to use?
Maintained, but watch it — Scrapy has real signals (drift, thin maintenance, or advisories) worth tracking. OSPulse rates it 55/100 (medium risk) based on release recency, cadence and known vulnerabilities.
Other PyPI packages we've checked
scrapy is one package. What about the other hundreds in your tree?
Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the PyPI registry & OSV.dev · snapshot generated 2026-07-27 · scores are deterministic and recomputed on each refresh.
