Home › Guides › Package publisher data

npm, PyPI and Docker Hub publisher data: does a company really ship a developer product?

Whether a company publishes SDKs on npm, PyPI or Docker Hub — and how recently — is a precise read on whether it has a real developer-facing product. This actor checks all three registries for one organization name and returns one row per package: version, licence, npm download and dependent counts, package status, last-publish date, maintainers and the organization’s website.

Who it is for

What you get

One row per package, in the same column layout as the other foXLabs company datasets:

GroupFields
PackageregistryName (npm, pypi or docker), packageName, version, description, licenseName, keywords, lastPublishedAt, status and statusRaw, sourceUrl
PopularitydownloadsLastMonth and dependentCount (npm), pullCount and starCount (Docker Hub)
People and contactpublishers, maintainers (name and email), email with emailSource, phone with phoneSource (from the organization’s website), website with websiteSource
CoderepositoryUrl, homepage
GitHub (optional)With your own GitHub token: githubOrganization, githubName, githubUrl, githubLocation, githubEmail, githubVerified, githubPublicRepos, githubFollowers, githubCreatedAt
ProvenancecompanyName, query, scrapedAt, and error when a lookup fails

A real row from the prefilled run, shortened (the maintainer address is left out here; the dataset carries it):

{
  "companyName": "stripe",
  "status": "active",
  "registryName": "npm",
  "packageName": "stripe",
  "version": "22.6.2",
  "description": "Stripe API wrapper",
  "licenseName": "MIT",
  "downloadsLastMonth": 72377456,
  "dependentCount": 2672,
  "keywords": ["stripe", "payment processing", "credit cards", "api"],
  "publishers": ["GitHub Actions", "stripe-bindings"],
  "website": "https://stripe.com",
  "repositoryUrl": "git+https://github.com/stripe/stripe-node.git",
  "homepage": "https://github.com/stripe/stripe-node",
  "lastPublishedAt": "2026-09-09",
  "sourceUrl": "https://www.npmjs.com/package/stripe"
}

Use cases

How to run it

Give the actor organization or npm scope names. This is the prefilled input:

{
  "queries": ["stripe", "hashicorp", "vercel"],
  "maxResultsPerQuery": 30
}

No API key and no login are needed for the registries. Results export to CSV, Excel, JSON, XML or HTML, or can be pulled through the Apify API.

You pay only for delivered rows. A query that finds nothing still returns a row carrying your query and an error explaining why — and that row is not charged.

Open Package Publisher Data on Apify →

Honest limits

Where the data comes from

npm, PyPI and Docker Hub all serve public package metadata through documented APIs with no key, and every run queries them live. Public package metadata is published by each registry precisely so it can be indexed and reused. Source: npm registry, PyPI JSON API and Docker Hub API.

Related data and guides

Frequently asked questions

Which registries does it check?

npm, PyPI and Docker Hub, all three for each organization name you give.

How does it avoid crediting someone else’s package?

npm is searched by scope and by maintainer. PyPI has no organization index, so a project is credited to the company only when the company owns something on it: an address at its domain, a homepage on its domain, a repository under its account, or its name as author.

Are maintainer emails included?

Yes, as each registry publishes them, skipping bot and no-reply addresses. They are personal data, so if you store or contact them, data-protection and anti-spam rules such as GDPR and CAN-SPAM apply to you.

Do I need a GitHub token?

No. It is optional. With a GitHub personal access token (no scopes needed), the organization’s public GitHub profile is added; without it, GitHub is not called.

Do deprecated packages show up?

npm’s search leaves deprecated packages out, so npm rows are live packages. PyPI status comes from the Development Status classifier and yanked releases, and Docker Hub’s from the repository status.

Start with the prefilled input — stripe, hashicorp and vercel — and export the package rows to CSV, Excel or JSON.

Open Package Publisher Data on Apify →