shodan
Python library and command-line utility for Shodan (https://developer.shodan.io)
Decision gist · record as of 2026-08-14
Yes, if you need Shodan integration and have an active API key. The package is stable and dependency-free, but its dormancy (no updates since late 2024) means you should verify compatibility with your Python version and test against current Shodan API behavior before relying on it in production. No known vulnerabilities are recorded.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a valid Shodan API key from https://account.shodan.io to make any queries.
- High install friction with no runtime dependencies.
- The package is dormant (last release 2023-12-17, no commits since 2024-08-05), though it remains marked Production/Stable and has accumulated 2941 GitHub stars.
License · maintenance · safety
permissive license (permissive) — Licensed under MIT (permissive), so you can use it freely in commercial and private projects without copyleft obligations.
last release 2023-12-17 (971 days) · last repo commit 2024-08-05 · 2,941 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 467,163 downloads/mo, #6,500 on PyPI
Alternatives
Verify before relying
pip install shodan
from shodan import Shodan
api = Shodan('YOUR_API_KEY')
ipinfo = api.host('8.8.8.8')
print(ipinfo)- Whether the package works reliably with modern Python versions (classifiers list Python 2.6–3.6 but no newer versions are declared).
- Current state of Shodan's API compatibility and whether the library's dormancy affects real-world usability.
What it is and what it does
Shodan is a Python client library for the Shodan search engine, which indexes Internet-connected devices rather than websites. It wraps Shodan's REST API and streaming endpoints, allowing you to search for devices by attributes, retrieve bulk IP information, monitor network alerts, and access exploit data—all from Python code or the command line.
The library has no runtime dependencies, making installation straightforward, but it requires a Shodan API key to function. It is marked Production/Stable and has been in use since 2010, though development is dormant as of late 2024. The package is useful for security researchers, network administrators, and developers automating device discovery and reconnaissance tasks.
Use it for
- Automate security audits by searching for specific device types or services exposed on the Internet.
- Perform bulk IP lookups to gather geolocation, hosting, and service information for a list of addresses.
- Monitor your organization's network perimeter by setting up alerts for newly discovered exposed services.
- Build reconnaissance tools that integrate Shodan queries into existing security workflows.
- Stream real-time data from Shodan's firehose to detect newly indexed devices matching your criteria.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need Shodan integration and have an active API key.
The package is stable and dependency-free, but its dormancy (no updates since late 2024) means you should verify compatibility with your Python version and test against current Shodan API behavior before relying on it in production. No known vulnerabilities are recorded.
Install
shodan on PyPI
Before you install
High install friction with no runtime dependencies. The package is dormant (last release 2023-12-17, no commits since 2024-08-05), though it remains marked Production/Stable and has accumulated 2941 GitHub stars. Maintenance is stalled but the codebase is not archived.
Requires a valid Shodan API key from https://account.shodan.io to make any queries.
License in practice
Licensed under MIT (permissive), so you can use it freely in commercial and private projects without copyleft obligations.
Quickstart
pip install shodan
from shodan import Shodan
api = Shodan('YOUR_API_KEY')
ipinfo = api.host('8.8.8.8')
print(ipinfo)
Verify before relying
- Whether the package works reliably with modern Python versions (classifiers list Python 2.6–3.6 but no newer versions are declared).
- Current state of Shodan's API compatibility and whether the library's dormancy affects real-world usability.
Package facts
| License | permissive license permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Dormant 971 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 467,163 / month, #6,500 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 2Programming Language :: Python :: 2.6Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.4Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Topic :: Software Development :: Libraries :: Python Modules |
Evidence: shodan-1.31.0.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “shodan api client”
- shodanProvides Python access to Shodan's search engine for…
- codewords-clientA Python client library for the Codewords API with built-in FastAPI…
- twentyc.rpcA client library for consuming 20c's RESTful API, built on top of the…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also ipinfo · censys · ipwhois · nslookup · pyasn · netaddr · aiodiscover · ip3country · dnspython · geoip2fast