Home › Guides › Package publisher data
npm, PyPI and Docker Hub publisher data: does a company really ship a developer product?
Whether a company publishes SDKs on npm, PyPI or Docker Hub — and how recently — is a precise read on whether it has a real developer-facing product. This actor checks all three registries for one organization name and returns one row per package: version, licence, npm download and dependent counts, package status, last-publish date, maintainers and the organization’s website.
Who it is for
- Developer-tools sales and marketing teams — qualifying accounts by whether they maintain SDKs, which signals a real API product.
- Data teams — adding technographic signals to company records.
- Ecosystem and competitive analysts — listing every package published under an organization scope, with licences.
What you get
One row per package, in the same column layout as the other foXLabs company datasets:
| Group | Fields |
|---|---|
| Package | registryName (npm, pypi or docker), packageName, version, description, licenseName, keywords, lastPublishedAt, status and statusRaw, sourceUrl |
| Popularity | downloadsLastMonth and dependentCount (npm), pullCount and starCount (Docker Hub) |
| People and contact | publishers, maintainers (name and email), email with emailSource, phone with phoneSource (from the organization’s website), website with websiteSource |
| Code | repositoryUrl, homepage |
| GitHub (optional) | With your own GitHub token: githubOrganization, githubName, githubUrl, githubLocation, githubEmail, githubVerified, githubPublicRepos, githubFollowers, githubCreatedAt |
| Provenance | companyName, query, scrapedAt, and error when a lookup fails |
A real row from the prefilled run, shortened (the maintainer address is left out here; the dataset carries it):
{
"companyName": "stripe",
"status": "active",
"registryName": "npm",
"packageName": "stripe",
"version": "22.6.2",
"description": "Stripe API wrapper",
"licenseName": "MIT",
"downloadsLastMonth": 72377456,
"dependentCount": 2672,
"keywords": ["stripe", "payment processing", "credit cards", "api"],
"publishers": ["GitHub Actions", "stripe-bindings"],
"website": "https://stripe.com",
"repositoryUrl": "git+https://github.com/stripe/stripe-node.git",
"homepage": "https://github.com/stripe/stripe-node",
"lastPublishedAt": "2026-09-09",
"sourceUrl": "https://www.npmjs.com/package/stripe"
}
Use cases
- Developer-product qualification. A company with maintained SDKs on all three registries has a real API product; one with none does not.
- Technographic enrichment. Which registries a company publishes to, and what its packages are, says what it builds with.
- Ecosystem mapping. Find every package published under an organization scope, with licences.
How to run it
Give the actor organization or npm scope names. This is the prefilled input:
{
"queries": ["stripe", "hashicorp", "vercel"],
"maxResultsPerQuery": 30
}
queries— organization or scope names; all three registries are checked in parallel for each name.maxResultsPerQuery— caps how many rows one query may produce.githubToken— optional GitHub personal access token (no scopes needed; only public data is read). With it, the GitHub organization the packages’ repositories point to adds its profile fields. Without it, GitHub is not called.
No API key and no login are needed for the registries. Results export to CSV, Excel, JSON, XML or HTML, or can be pulled through the Apify API.
You pay only for delivered rows. A query that finds nothing still returns a row carrying your query and an error explaining why — and that row is not charged.
Honest limits
- PyPI has no organization index. The actor probes the obvious project names and then verifies provenance: a project is credited to the company only when the company owns something on it — an address at its domain, a homepage on its domain, a repository under its account, or its name as author. That keeps an unrelated project with a similar name (Hive Solutions’
stripe-apiis not Stripe’s) out of the results. - Deprecated npm packages are not listed. npm’s search leaves them out, so npm rows are live packages. PyPI status comes from the Development Status classifier and yanked releases, Docker Hub’s from the repository status.
- Docker Hub is thinner. It publishes no licence and no maintainer addresses.
- Website only when it is clear.
websiteis the domain carrying the organization’s name that its package homepages point to most often. Homepages on GitHub, a registry or a product domain give none —hashicorp’s packages point to GitHub, so its rows stay empty. - Maintainer addresses are personal data. They are returned as the registries publish them, skipping bot and no-reply addresses. If you store or contact them, data-protection and anti-spam rules such as GDPR and CAN-SPAM apply to you.
- Not a company register. Registration number, tax number, legal form and similar company fields stay empty on every row;
cityandcountryNameare filled only from a GitHub profile.
Where the data comes from
npm, PyPI and Docker Hub all serve public package metadata through documented APIs with no key, and every run queries them live. Public package metadata is published by each registry precisely so it can be indexed and reused. Source: npm registry, PyPI JSON API and Docker Hub API.
Related data and guides
- Browse the company and developer datasets on the home page.
- Developer ecosystem signals — GitHub trending, Hacker News and community data as market signal.
- BuiltWith alternative — finding a company’s tech stack pay-as-you-go.
- Company ID crosswalk — the identifiers to join package data onto company records.
Frequently asked questions
Which registries does it check?
npm, PyPI and Docker Hub, all three for each organization name you give.
How does it avoid crediting someone else’s package?
npm is searched by scope and by maintainer. PyPI has no organization index, so a project is credited to the company only when the company owns something on it: an address at its domain, a homepage on its domain, a repository under its account, or its name as author.
Are maintainer emails included?
Yes, as each registry publishes them, skipping bot and no-reply addresses. They are personal data, so if you store or contact them, data-protection and anti-spam rules such as GDPR and CAN-SPAM apply to you.
Do I need a GitHub token?
No. It is optional. With a GitHub personal access token (no scopes needed), the organization’s public GitHub profile is added; without it, GitHub is not called.
Do deprecated packages show up?
npm’s search leaves deprecated packages out, so npm rows are live packages. PyPI status comes from the Development Status classifier and yanked releases, and Docker Hub’s from the repository status.
Start with the prefilled input — stripe, hashicorp and vercel — and export the package rows to CSV, Excel or JSON.
Open Package Publisher Data on Apify →