PkgRadar

PyPI · pypi.org

assemblyai

Py Install Time Eval Exec: Python eval()/exec() called on a string.

Why PkgRadar flagged 0.64.4

SeveritySignalEvidence
mediumPy Install Time Eval ExecPython eval()/exec() called on a string. · assemblyai-0.64.4/setup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.64.21Low risk02026-06-16
0.64.20Low risk02026-06-15
0.64.16Low risk02026-06-11
0.64.11Low risk02026-06-10
0.64.9Low risk02026-06-09
0.64.4Review222026-05-28

Block this in CI

PkgRadar gates assemblyai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi assemblyai==0.64.4