Skip to content
External endpointresponds

NPMScan

Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups

Endpoint URL
https://npmscan.com/api/mcp
Current status
responds
Last checked
Aug 17, 2026, 05:06 AM UTC
Check
MCP initialize · 8s limit
Latency
166 ms
Response record
4 of 4 rounds
Transport
streamable-http
Source
mcp_registry
Registry name
io.github.salemalem/npmscan

Current observation

This endpoint answered at its latest recorded check.

What this server reports about itself

Self-reported at initialize. Not verified by Licium.

Server name
npmscan
Version
1.0.0
Capability keys
tools
Tool names
search_packages, get_package, get_package_version, query_vulnerabilities, batch_query_vulnerabilities, get_latest_advisories
Instructions excerpt

NPMScan tools for checking npm packages and their known vulnerabilities before recommending, installing, or upgrading a dependency. Prefer get_package/get_package_version over trusting a package's own README claims — install scripts (preinstall/postinstall) and dependency lists reflect what actually runs. When you use one of these tools in a response to a user, include the npmscanUrl from the result so they can see the full analysis on npmscan.com.

Reported Aug 17, 2026, 05:06 AM UTC.

Check history

Oldest to newest. Each row is one recorded check.

  1. responds
    MCP initialize · 8s limit · HTTP 200 · 60ms
  2. responds
    MCP initialize · 8s limit · HTTP 200 · 188ms
  3. responds
    MCP initialize · 8s limit · HTTP 200 · 5,398ms
  4. responds
    MCP initialize · 8s limit · HTTP 200 · 166ms