mcpbeat Sign in

Pumpcheck MCP Server

answering

Pumpcheck is answering right now. Last checked 2 min ago. It exposes 1 tools.

Detect npm download-pumping before adding a dependency: real usage vs inflated counter.

Uptime history 45 hours of history · worst hour 0%
45 hours agonow
25.0%
Uptime 24h
23 of 92 checks
1
Tools
read from the server
849 ms
Response time
average over 24h
open, no key
Access
streamable-http

What changed 1

Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 17 September 2026. No other catalogue keeps this.

17 Sep a tool description was rewritten check_npm_download_trust

Pumpcheck does not always answer

Over the last week it answered 44.9% of our checks. We check every 15 minutes, so you hear about the next outage within the hour — not from your users.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 2 min ago.

run in your terminal
claude mcp add pumpcheck --transport http https://www.edgethirteen.com/api/mcp/pumpcheck
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "pumpcheck": {
      "url": "https://www.edgethirteen.com/api/mcp/pumpcheck"
    }
  }
}
~/.codex/config.toml
[mcp_servers.pumpcheck]
url = "https://www.edgethirteen.com/api/mcp/pumpcheck"
.cursor/mcp.json
{
  "mcpServers": {
    "pumpcheck": {
      "url": "https://www.edgethirteen.com/api/mcp/pumpcheck"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "pumpcheck": {
      "url": "https://www.edgethirteen.com/api/mcp/pumpcheck"
    }
  }
}

Available tools 1

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

npm
check_npm_download_trust
Check whether an npm package's public download count reflects real adoption. Detects 'download pumping' -- the documented supply-chain technique where a package is published in hundreds of rapid-fire versions so registry mirrors and security scanners inflate its download counter, making an unused or malicious package look popular. Returns npm's headline 30-day count, a spike-resistant estimate of sustained real usage, the share of the month falling on the busiest single day, recent version-flood bursts, and a verdict of clean, unreliable or inflated. Use before adding or recommending a dependency, especially a new or unfamiliar one. This free check does one package per call; auditing a whole package.json or package-lock.json in one pass is a separate $299 product at https://www.edgethirteen.com/tools/pumpcheck.

Endpoints

URLTransportStateLatencyChecked
https://www.edgethirteen.com/api/mcp/pumpcheck streamable-http answering 198 ms 2 min ago

Alternatives to Pumpcheck

same job, measured the same way
Safeprompt
by safeprompt

Detect prompt injection, jailbreaks, and code injection in untrusted text before it reaches an LLM.

37 installs/wk local only
Safe Upgrade
by white-hat-lab

Evidence-backed npm upgrade preflight and dependency audits for coding agents, paid via x402.

41 installs/wk local only
npx-vibe
by devrajsinh-jhala

Read-only npm package and project dependency preflight tools for AI applications.

128 installs/wk local only
I
pkg-oracle — Dependency Trust Oracle
by julian-martin89

Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.

1 tools answering
SendLetter
by sendletter

Send real, printed letters by post across Europe. Requires a free account; quote before sending.

answering
Package Intel
by adam121393

npm, PyPI & crates.io health, vulns and dependency graphs. Runs locally, no API key.

52 installs/wk local only
Package Version Check MCP
by mshekow

Returns the latest package / dependency / tool versions for Python, NPM, Go, Docker, Helm, etc.

725 installs/wk local only
Getdigitalcraft MCP Render
by gene12williams-design

Deterministic image rendering with exact typography. Pay per call in USDC, no account.

54 installs/wk local only

Pumpcheck — questions

Answers built from our own checks of this server.

What can Pumpcheck do?
It exposes 1 tools, read directly from the server on our last check. Among them: check_npm_download_trust. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is Pumpcheck working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 23 of 92 checks got a reply (25.0%), average response time 849 ms. The bar chart above shows every period we have measured.
How do I connect Pumpcheck?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does Pumpcheck need an API key?
No. Pumpcheck completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 1 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is Pumpcheck?
It answers our handshake in 849 ms on average, which is faster than 12% of all working MCP servers we measure. That is on the slow side — worth knowing if the tool sits inside an interactive loop. The comparison comes from our own checks across the whole registry, every 15 minutes.