Is Botocore Safe?

Yes, Botocore is safe to use. Botocore is a Python package with a Nerq Trust Score of 80.8/100 (A-), based on 3 independent data dimensions. It is recommended for production use. Security: 90/100. Popularity: 100/100. Data sourced from PyPI registry, GitHub repository, NVD, OSV.dev, and OpenSSF Scorecard. Last updated: 2026-03-27. Machine-readable data (JSON).

Is Botocore safe?

YES — Botocore has a Nerq Trust Score of 80.8/100 (A-). It meets Nerq's trust threshold with strong signals across security, maintenance, and community adoption. Recommended for production use — review the full report below for specific considerations.

Trust Score Breakdown

Security
90
Popularity
100

Key Findings

Security score: 90/100 (strong)
Popularity: 100/100 — community adoption

Details

AuthorAmazon Web Services
Categorypypi
SourceN/A

Botocore Across Platforms

Same developer/company in other registries:

aws-sdk-amplifybackend
68/100 · gems
aws-sdk-datazone
68/100 · gems
aws-sdk-sso
68/100 · gems
aws-sdk-iotroborunner
68/100 · gems
aws-sdk-pcaconnectorad
68/100 · gems

Safety Guide: Botocore

What is Botocore?

Botocore is a Python package — Low-level, data-driven core of boto 3..

How to Verify Safety

Run pip audit or safety check. Review on PyPI for download stats.

You can also check the trust score via API: GET /v1/preflight?target=botocore

Key Safety Concerns for Python packages

When evaluating any Python package, watch for: dependency vulnerabilities, malicious uploads, maintenance status.

Trust Assessment

Botocore has a Nerq Trust Score of 81/100 (A-) and meets Nerq trust threshold. This score is based on automated analysis of security, maintenance, community, and quality signals.

Key Takeaways

Detailed Score Analysis

DimensionScore
Security90/100
Privacy80/100
Reliability90/100
Transparency85/100
Maintenance60/100

Based on 5 dimensions. Data from PyPI registry, GitHub repository, NVD, OSV.dev, and OpenSSF Scorecard.

What data does Botocore collect?

Botocore is a Python package maintained by Amazon Web Services. It receives approximately 273,580,224 weekly downloads. Licensed under Apache-2.0.

As a development package, Botocore does not directly collect end-user personal data. However, applications built with it may collect data depending on implementation. Privacy score: 80/100.

Review the package's dependencies for potential supply chain risks. Run your package manager's audit command regularly.

Full analysis: Botocore Privacy Report · Privacy review

Is Botocore secure?

Security score: 90/100. Botocore has 0 known vulnerabilities (CVEs) in the National Vulnerability Database. This is a clean record.

Licensed under Apache-2.0, allowing code inspection. Open-source packages allow independent security review of the source code.

Run your package manager's audit command (`npm audit`, `pip audit`, `cargo audit`) to check for known vulnerabilities in your dependency tree.

Full analysis: Botocore Security Report

Botocore Across Platforms

Same developer/company in other registries:

aws-sdk-amplifybackend (gems, 68/100)aws-sdk-datazone (gems, 68/100)aws-sdk-sso (gems, 68/100)aws-sdk-iotroborunner (gems, 68/100)

How we calculated this score

Botocore's trust score of 80.8/100 (A-) is computed from PyPI registry, GitHub repository, NVD, OSV.dev, and OpenSSF Scorecard. The score reflects 5 independent dimensions: security (90/100), privacy (80/100), reliability (90/100), transparency (85/100), maintenance (60/100). Each dimension is weighted equally to produce the composite trust score.

Nerq analyzes over 7.5 million entities across 26 registries using the same methodology, enabling direct cross-entity comparison. Scores are updated continuously as new data becomes available.

This page was last reviewed on March 27, 2026. Data version: 1.0.

Full methodology documentation · Machine-readable data (JSON API)

Frequently Asked Questions

Is Botocore safe to use?
Yes, it is safe to use. botocore has a Nerq Trust Score of 80.8/100 (A-). Strongest signal: popularity (100/100). Score based on security (90/100), popularity (100/100).
What is Botocore's trust score?
botocore: 80.8/100 (A-). Score based on: security (90/100), popularity (100/100). Scores update as new data becomes available. API: GET nerq.ai/v1/preflight?target=botocore
What are safer alternatives to Botocore?
In the pypi category, more Python packages are being analyzed — check back soon. botocore scores 80.8/100.
Does Botocore have known vulnerabilities?
Nerq checks Botocore against NVD, OSV.dev, and registry-specific vulnerability databases. Current security score: 90/100. Run your package manager's audit command for the latest findings.
How actively maintained is Botocore?
Botocore has a trust score of 80.8/100 (A-). Meets Nerq Verified threshold.
API: /v1/preflight Trust Badge API Docs

Disclaimer: Nerq trust scores are automated assessments based on publicly available signals. They are not endorsements or guarantees. Always conduct your own due diligence.