Skip to main content

stillrunning-pip

The zero-config pip wrapper that catches malicious packages before they install. Try it in 5 seconds. No setup, no signup, no config.

PyPI Threats blocked

Try it now

pip install stillrunning-pip
stillrunning-pip install requests

That's it. Every package you install is now checked against 200,000+ verified malicious packages from OSV.dev, GitHub Advisory, and 6 other threat intelligence sources, updated nightly.

What you get for free

  • 10 scans per day per IP, no signup required
  • Blocks confirmed-malicious packages automatically
  • Warns about suspicious packages
  • Works with pip install <pkg> and pip install -r requirements.txt
  • 5-second installs, 5-second scans

Replace pip globally (optional)

alias pip='stillrunning-pip'

Add to ~/.bashrc or ~/.zshrc for every install in every project to be scanned.

Hit the rate limit?

Get the full stillrunning package — covers pip, uv, poetry, pdm, pipenv, conda, pixi, npm, bun, pnpm, with unlimited scans, AI analysis of unknown packages, and import-time protection:

pip install stillrunning

stillrunning.io/pricing for paid tiers.

How it works

Before each install, stillrunning-pip queries the public API:

GET https://stillrunning.io/api/check-package?name=<pkg>

If the package is on the verified blocklist, the install is halted with a clear message. Every block traces back to a public security advisory you can verify yourself at stillrunning.io/security-advisories.

Power user features

Set STILLRUNNING_TOKEN to unlock unlimited scans and AI analysis of unknown packages. Get a token at stillrunning.io/pricing.

export STILLRUNNING_TOKEN=sr_...
stillrunning-pip install <pkg>

Bypass scanning

If you need to install something stillrunning is blocking and you've verified it's safe:

pip install <package>

Just use vanilla pip directly. stillrunning-pip is opt-in via being the binary you call.

Relationship to stillrunning

stillrunning-pip is the simplest member of the stillrunning family. It does one thing: scans pip installs against the verified threat database.

For broader coverage (uv, poetry, pdm, pipenv, conda, pixi, npm, bun, pnpm), import-time protection, MCP server for Claude Code, GitHub Action for CI, and unlimited scans, install the main package: pip install stillrunning.

License

MIT


stillrunning.io | @bit_bot9000

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

stillrunning_pip-1.2.0.tar.gz (6.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

stillrunning_pip-1.2.0-py3-none-any.whl (6.7 kB view details)

Uploaded Python 3

File details

Details for the file stillrunning_pip-1.2.0.tar.gz.

File metadata

  • Download URL: stillrunning_pip-1.2.0.tar.gz
  • Upload date:
  • Size: 6.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for stillrunning_pip-1.2.0.tar.gz
Algorithm Hash digest
SHA256 31f902599a5455f707a2641e91c6069d1bea3b1920b94d76073c5ba1bd1b9947
MD5 ac0e55c5f85fbf7dffee384a5c1dc1b9
BLAKE2b-256 5d44322ef2fce530cdd784c330e5a0100296c347ec759cf927c133d66f148978

See more details on using hashes here.

File details

Details for the file stillrunning_pip-1.2.0-py3-none-any.whl.

File metadata

File hashes

Hashes for stillrunning_pip-1.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 f7f78a6c4933f4d2502dcbadd13428d12692fbdafb739a78730eb84985b6fca0
MD5 19c3a6285ebf67fe120105ca6858725d
BLAKE2b-256 db7fc4635e0a52cc8ce2273d589c4a42e3ba3bd32eb38f7b031c8db0f7645884

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page