Dangerous Packages

BinComp Dashboard →
Python packages ranked by binary-level compound risk. Risk combines ROP gadget count, missing hardening (partial RELRO, no canary, no FORTIFY), unsafe libc calls, and known CVEs against the package or its bundled shared libraries.
474
Scanned Packages
114,462.0
Total Gadgets
61,328.0
GOT Entries
894.0
Binaries Scanned
255.7
Avg Compound Risk

Hardening Grade Distribution

B: 1C: 5D: 16F: 65N: 387
Per-row analysis by Repobility · https://repobility.com
# Package Grade Compound Risk Gadgets GOT Bins Unsafe Calls R/C/F Size
Repobility — the code-quality scanner for AI-generated software · https://repobility.com
1pillow
12.2.0
F12554.27,10152126142/1/117.4 MB
2urllib3
2.6.3
N11455.300000/0/00.0 MB
3transformers
5.5.3
N10146.500000/0/00.0 MB
4aiohttp
3.13.5
F8061.4354143400/0/05.3 MB
5cryptography
46.0.7
D7302.12,147184151/0/012.2 MB
6fastmcp
3.2.4
N5776.000000/0/00.0 MB
7semver
3.0.4
N5565.000000/0/00.0 MB
8litellm
1.83.7
N5510.800000/0/00.0 MB
9langchain-core
1.2.28
N5427.600000/0/00.0 MB
10torch
2.11.0
F5116.61,25720,84113171/4/1954.1 MB
11nltk
3.9.4
N4931.700000/0/00.0 MB
12authlib
1.6.9
N4609.500000/0/00.0 MB
13jinja2
3.1.6
N4187.000000/0/00.0 MB
14requests
2.33.1
N3687.000000/0/00.0 MB
15langsmith
0.7.31
N2115.700000/0/00.0 MB
16gunicorn
25.3.0
N2072.400000/0/00.0 MB
17pygments
2.20.0
N2032.800000/0/00.0 MB
18black
26.3.1
F1959.89928373000/0/04.7 MB
19pyjwt
2.12.1
N1770.000000/0/00.0 MB
20python-multipart
0.0.26
N1658.900000/0/00.0 MB
21starlette
1.0.0
N1608.000000/0/00.0 MB
22notebook
7.5.5
N1006.900000/0/00.0 MB
23mcp
1.27.0
N971.500000/0/00.0 MB
24werkzeug
3.1.8
N865.800000/0/00.0 MB
25anthropic
0.95.0
N846.600000/0/00.0 MB
26markdown
3.10.2
N787.500000/0/00.0 MB
27ipython
9.12.0
N738.000000/0/00.0 MB
28json5
0.14.0
N724.200000/0/00.0 MB
29protobuf
7.34.1
F658.523927110/0/00.4 MB
30nbconvert
7.17.1
N631.700000/0/00.0 MB
31flask
3.1.3
N574.200000/0/00.0 MB
32tornado
6.5.5
F561.854100/0/00.0 MB
33h11
0.16.0
N546.000000/0/00.0 MB
34brotli
1.2.0
F465.034912100/0/04.9 MB
35h2
4.3.0
N457.500000/0/00.0 MB
36jupyter-core
5.9.1
N403.900000/0/00.0 MB
37pyasn1
0.6.3
N382.500000/0/00.0 MB
38filelock
3.25.2
N342.000000/0/00.0 MB
39orjson
3.11.8
D336.621584101/0/00.2 MB
40marshmallow
4.3.0
N265.000000/0/00.0 MB
41pymysql
1.1.2
N264.600000/0/00.0 MB
42pymongo
4.16.0
F263.2413128800/0/02.9 MB
43rsa
4.9.1
N224.000000/0/00.0 MB
44pymupdf
1.27.2.2
F188.82,467856460/1/050.4 MB
45fonttools
4.62.1
F144.9667235600/0/010.7 MB
46virtualenv
21.2.1
N126.000000/0/00.0 MB
47zipp
3.23.0
N124.000000/0/00.0 MB
48jaraco-context
6.1.2
N120.400000/0/00.0 MB
49deepdiff
9.0.0
N106.900000/0/00.0 MB
50pip
24.0
N100.300000/0/00.0 MB
51pyopenssl
26.0.0
N96.000000/0/00.0 MB
52pydantic-ai-slim
1.80.0
N86.000000/0/00.0 MB
53ray
2.55.0
F58.99356,6941172/2/250.0 MB
54dbt-core
1.11.8
N53.000000/0/00.0 MB
55bcrypt
5.0.0
D48.0363119111/0/00.6 MB
56sentry-sdk
2.57.0
N35.000000/0/00.0 MB
57pynacl
1.6.2
C22.53576100/1/13.5 MB
58azure-core
1.39.0
N15.000000/0/00.0 MB
59poetry
2.3.4
N13.600000/0/00.0 MB
60uv
0.11.6
N2.100000/0/00.0 MB
61google-api-core
2.30.3
N0.000000/0/00.0 MB
62markdown-it-py
4.0.0
N0.000000/0/00.0 MB
63anyio
4.13.0
N0.000000/0/00.0 MB
64uvicorn
0.44.0
N0.000000/0/00.0 MB
65google-auth
2.49.2
N0.000000/0/00.0 MB
66pydantic-core
2.45.0
D0.01,321207111/0/04.5 MB
67python-dateutil
2.9.0.post0
N0.000000/0/00.0 MB
68multidict
6.7.1
F0.04018100/0/00.8 MB
69yarl
1.23.0
F0.08936100/0/00.1 MB
70jsonschema
4.26.0
N0.000000/0/00.0 MB
71attrs
26.1.0
N0.000000/0/00.0 MB
72aiobotocore
3.4.0
N0.000000/0/00.0 MB
73rich
14.3.4
N0.000000/0/00.0 MB
74click
8.3.2
N0.000000/0/00.0 MB
75pytz
2026.1.post1
N0.000000/0/00.0 MB
76botocore
1.42.88
N0.000000/0/00.0 MB
77httpcore
1.0.9
N0.000000/0/00.0 MB
78python-dotenv
1.2.2
N0.000000/0/00.0 MB
79s3transfer
0.16.0
N0.000000/0/00.0 MB
80typing-inspection
0.4.2
N0.000000/0/00.0 MB
81cachetools
7.0.5
N0.000000/0/00.0 MB
82httpx
0.28.1
N0.000000/0/00.0 MB
83pluggy
1.6.0
N0.000000/0/00.0 MB
84idna
3.11
N0.000000/0/00.0 MB
85setuptools
82.0.1
N0.000000/0/00.0 MB
86tenacity
9.1.4
N0.000000/0/00.0 MB
87aiohappyeyeballs
2.6.1
N0.000000/0/00.0 MB
88pathspec
1.0.4
N0.000000/0/00.0 MB
89pydantic
2.12.5
N0.000000/0/00.0 MB
90pyparsing
3.3.2
N0.000000/0/00.0 MB
91pyarrow
23.0.1
F0.08,5054,66037170/4/4132.9 MB
92opentelemetry-api
1.41.0
N0.000000/0/00.0 MB
93requests-oauthlib
2.0.0
N0.000000/0/00.0 MB
94annotated-doc
0.0.4
N0.000000/0/00.0 MB
95sqlalchemy
2.0.49
F0.0376160500/0/04.8 MB
96regex
2026.4.4
F0.021622100/0/02.5 MB
97psutil
7.2.2
F0.01916110/0/00.1 MB
98opentelemetry-semantic-conventions
0.62b0
N0.000000/0/00.0 MB
99hatchling
1.29.0
N0.000000/0/00.0 MB
100importlib-metadata
9.0.0
N0.000000/0/00.0 MB
Data from the BinComp PyPI crawler. One row per (package, version). The crawler runs continuously and grows this list over time.