crates.io package intelligence

reqwest — deep security report

ShadowCanopy's full breakdown of reqwest on crates.io: verdict, AI analysis, dependency chain, network behavior, prebuilds, and obfuscated code.

Safe to use
Deep-scanned by ShadowCanopy — no threats found in its code, dependencies, or network behavior.
Scanned 9/15/2026
Approvedreqwest@0.13.5View on registry ↗latest: 0.13.5

Legitimate, widely-used Rust HTTP client (reqwest 0.13.5). No static findings, no suspicious source, standard crate layout.

Protect your projects free

AI breakdown

Plain-English summary of what this package does and how it behaves.

reqwest 0.13.5 is the source package for a Rust HTTP client library providing async and blocking APIs for HTTP requests.

Capabilities

  • Provides async HTTP client
  • Provides blocking HTTP client
  • Supports HTTP/3
  • Handles multipart forms
  • Manages cookies
  • Configurable DNS resolution

Data access

  • None observed

Network

  • Makes outbound HTTP requests

Standard HTTP client crate with no scripts or dependencies listed in manifest and no static findings; introduces normal network capabilities for a developer choosing an HTTP library.

Files in package (94)

.cargo_vcs_info.jsonreqwest-0.13.5/.cargo_vcs_info.jsonCargo.lockreqwest-0.13.5/Cargo.lockCargo.tomlreqwest-0.13.5/Cargo.tomlCargo.toml.origreqwest-0.13.5/Cargo.toml.origLICENSE-APACHEreqwest-0.13.5/LICENSE-APACHELICENSE-MITreqwest-0.13.5/LICENSE-MITREADME.mdreqwest-0.13.5/README.mdsrc/async_impl/body.rsreqwest-0.13.5/src/async_impl/body.rssrc/async_impl/client.rsreqwest-0.13.5/src/async_impl/client.rssrc/async_impl/h3_client/connect.rsreqwest-0.13.5/src/async_impl/h3_client/connect.rssrc/async_impl/h3_client/dns.rsreqwest-0.13.5/src/async_impl/h3_client/dns.rssrc/async_impl/h3_client/mod.rsreqwest-0.13.5/src/async_impl/h3_client/mod.rssrc/async_impl/h3_client/pool.rsreqwest-0.13.5/src/async_impl/h3_client/pool.rssrc/async_impl/mod.rsreqwest-0.13.5/src/async_impl/mod.rssrc/async_impl/multipart.rsreqwest-0.13.5/src/async_impl/multipart.rssrc/async_impl/request.rsreqwest-0.13.5/src/async_impl/request.rssrc/async_impl/response.rsreqwest-0.13.5/src/async_impl/response.rssrc/async_impl/upgrade.rsreqwest-0.13.5/src/async_impl/upgrade.rssrc/blocking/body.rsreqwest-0.13.5/src/blocking/body.rssrc/blocking/client.rsreqwest-0.13.5/src/blocking/client.rs

How ShadowCanopy checks crates.io packages

ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.

Protect your projects freeSee what's being blocked

This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/crates/reqwest