crates.io package intelligence

reqwest — deep security report

ShadowCanopy's full breakdown of reqwest on crates.io: verdict, AI analysis, dependency chain, network behavior, prebuilds, and obfuscated code.

Safe to use
Deep-scanned by ShadowCanopy — no threats found in its code, dependencies, or network behavior.
Scanned 8/11/2026
Approvedreqwest@0.13.4View on registry ↗latest: 0.13.4

This is the legitimate, well-known reqwest HTTP client crate (0.13.4). No static findings, only standard source files, no evidence of malice.

Protect your projects free

AI breakdown

Plain-English summary of what this package does and how it behaves.

reqwest 0.13.4 is the source package for the popular Rust HTTP client library, providing async and blocking APIs for HTTP requests.

Capabilities

  • Provides async HTTP client
  • Provides blocking HTTP client
  • Supports multipart forms
  • Handles cookies
  • Includes DNS and connection pooling

Data access

  • Filesystem (via config and cookie modules)
  • Environment variables (not directly evidenced in sample)

Network

  • Makes outbound HTTP requests
  • Supports HTTP/3

No scripts, dependencies, or static findings are present in the provided manifest. As a widely used crates.io library with transparent source, it presents typical supply-chain risk for any third-party dependency.

Files in package (94)

.cargo_vcs_info.jsonreqwest-0.13.4/.cargo_vcs_info.jsonCargo.lockreqwest-0.13.4/Cargo.lockCargo.tomlreqwest-0.13.4/Cargo.tomlCargo.toml.origreqwest-0.13.4/Cargo.toml.origLICENSE-APACHEreqwest-0.13.4/LICENSE-APACHELICENSE-MITreqwest-0.13.4/LICENSE-MITREADME.mdreqwest-0.13.4/README.mdsrc/async_impl/body.rsreqwest-0.13.4/src/async_impl/body.rssrc/async_impl/client.rsreqwest-0.13.4/src/async_impl/client.rssrc/async_impl/h3_client/connect.rsreqwest-0.13.4/src/async_impl/h3_client/connect.rssrc/async_impl/h3_client/dns.rsreqwest-0.13.4/src/async_impl/h3_client/dns.rssrc/async_impl/h3_client/mod.rsreqwest-0.13.4/src/async_impl/h3_client/mod.rssrc/async_impl/h3_client/pool.rsreqwest-0.13.4/src/async_impl/h3_client/pool.rssrc/async_impl/mod.rsreqwest-0.13.4/src/async_impl/mod.rssrc/async_impl/multipart.rsreqwest-0.13.4/src/async_impl/multipart.rssrc/async_impl/request.rsreqwest-0.13.4/src/async_impl/request.rssrc/async_impl/response.rsreqwest-0.13.4/src/async_impl/response.rssrc/async_impl/upgrade.rsreqwest-0.13.4/src/async_impl/upgrade.rssrc/blocking/body.rsreqwest-0.13.4/src/blocking/body.rssrc/blocking/client.rsreqwest-0.13.4/src/blocking/client.rs

How ShadowCanopy checks crates.io packages

ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.

Protect your projects freeSee what's being blocked

This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/crates/reqwest