crates.io package intelligence

reqwest — deep security report

ShadowCanopy's full breakdown of reqwest on crates.io: verdict, AI analysis, dependency chain, network behavior, prebuilds, and obfuscated code.

Safe to use
Deep-scanned by ShadowCanopy — no threats found in its code, dependencies, or network behavior.
Scanned 8/4/2026
Approvedreqwest@0.13.4View on registry ↗latest: 0.13.4

reqwest 0.13.4 is the legitimate, well-known Rust HTTP client. No static findings, no suspicious files or behavior in the package contents.

Protect your projects free

AI breakdown

Plain-English summary of what this package does and how it behaves.

reqwest 0.13.4 is a Rust HTTP client library providing both asynchronous and blocking APIs for sending HTTP requests.

Capabilities

  • Provides async HTTP client
  • Provides blocking HTTP client
  • Supports multipart requests
  • Handles cookies

Data access

  • None observed

Network

  • Makes outbound HTTP requests

Standard HTTP client with empty scripts, no listed dependencies, and no static findings; low risk when sourced from crates.io.

Files in package (94)

.cargo_vcs_info.jsonreqwest-0.13.4/.cargo_vcs_info.jsonCargo.lockreqwest-0.13.4/Cargo.lockCargo.tomlreqwest-0.13.4/Cargo.tomlCargo.toml.origreqwest-0.13.4/Cargo.toml.origLICENSE-APACHEreqwest-0.13.4/LICENSE-APACHELICENSE-MITreqwest-0.13.4/LICENSE-MITREADME.mdreqwest-0.13.4/README.mdsrc/async_impl/body.rsreqwest-0.13.4/src/async_impl/body.rssrc/async_impl/client.rsreqwest-0.13.4/src/async_impl/client.rssrc/async_impl/h3_client/connect.rsreqwest-0.13.4/src/async_impl/h3_client/connect.rssrc/async_impl/h3_client/dns.rsreqwest-0.13.4/src/async_impl/h3_client/dns.rssrc/async_impl/h3_client/mod.rsreqwest-0.13.4/src/async_impl/h3_client/mod.rssrc/async_impl/h3_client/pool.rsreqwest-0.13.4/src/async_impl/h3_client/pool.rssrc/async_impl/mod.rsreqwest-0.13.4/src/async_impl/mod.rssrc/async_impl/multipart.rsreqwest-0.13.4/src/async_impl/multipart.rssrc/async_impl/request.rsreqwest-0.13.4/src/async_impl/request.rssrc/async_impl/response.rsreqwest-0.13.4/src/async_impl/response.rssrc/async_impl/upgrade.rsreqwest-0.13.4/src/async_impl/upgrade.rssrc/blocking/body.rsreqwest-0.13.4/src/blocking/body.rssrc/blocking/client.rsreqwest-0.13.4/src/blocking/client.rs

How ShadowCanopy checks crates.io packages

ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.

Protect your projects freeSee what's being blocked

This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/crates/reqwest