PyPI package intelligence

numpy — deep security report

ShadowCanopy's full breakdown of numpy on PyPI: verdict, AI analysis, dependency chain, network behavior, prebuilds, and obfuscated code.

Safe to use
Deep-scanned by ShadowCanopy — no threats found in its code, dependencies, or network behavior.
Scanned 8/19/2026
Approvednumpy@2.4.2View on registry ↗latest: 2.4.2

The single finding is a harmless version mismatch inside a stray doc/build artifact (a MathJax grunt helper package.json). No malicious behavior, no runtime code, no exfiltration or execution sinks present.

Protect your projects free

AI breakdown

Plain-English summary of what this package does and how it behaves.

numpy 2.4.2 is the fundamental package for array computing in Python, providing multidimensional arrays and related numerical operations.

Capabilities

  • Provides array computing functionality

Data access

  • None observed

Network

  • No network access observed

Standard scientific computing library with no scripts or dependencies listed in manifest; one static finding notes a version metadata mismatch.

Security findings (1)

Static analysis rule matches, with the exact code that triggered them.

mediumVersion metadata mismatchATK-007doc/source/_static/scipy-mathjax/package.json

Version mismatch in doc/source/_static/scipy-mathjax/package.json

Package metadata

LicenseUnknown

Fundamental package for array computing in Python

Files in package (500)

.circleci/config.ymlnumpy-2.4.2/.circleci/config.yml.cirrus.starnumpy-2.4.2/.cirrus.star.clang-formatnumpy-2.4.2/.clang-format.codecov.ymlnumpy-2.4.2/.codecov.yml.coveragercnumpy-2.4.2/.coveragerc.ctags.dnumpy-2.4.2/.ctags.d.devcontainer/devcontainer.jsonnumpy-2.4.2/.devcontainer/devcontainer.json.devcontainer/setup.shnumpy-2.4.2/.devcontainer/setup.sh.editorconfignumpy-2.4.2/.editorconfig.gitattributesnumpy-2.4.2/.gitattributes.github/CONTRIBUTING.mdnumpy-2.4.2/.github/CONTRIBUTING.md.github/ISSUE_TEMPLATE/bug-report.ymlnumpy-2.4.2/.github/ISSUE_TEMPLATE/bug-report.yml.github/ISSUE_TEMPLATE/config.ymlnumpy-2.4.2/.github/ISSUE_TEMPLATE/config.yml.github/ISSUE_TEMPLATE/documentation.ymlnumpy-2.4.2/.github/ISSUE_TEMPLATE/documentation.yml.github/ISSUE_TEMPLATE/feature-request.ymlnumpy-2.4.2/.github/ISSUE_TEMPLATE/feature-request.yml.github/ISSUE_TEMPLATE/post-install.ymlnumpy-2.4.2/.github/ISSUE_TEMPLATE/post-install.yml.github/ISSUE_TEMPLATE/typing.ymlnumpy-2.4.2/.github/ISSUE_TEMPLATE/typing.yml.github/PULL_REQUEST_TEMPLATE.mdnumpy-2.4.2/.github/PULL_REQUEST_TEMPLATE.md.github/check-warnings/action.ymlnumpy-2.4.2/.github/check-warnings/action.yml.github/check-warnings/msvc-allowed-warnings.txtnumpy-2.4.2/.github/check-warnings/msvc-allowed-warnings.txt

How ShadowCanopy checks PyPI packages

ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.

Protect your projects freeSee what's being blocked

This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/pypi/numpy