npm Plus runs on your own machine — the client starts it, so there is no endpoint to ping. 47 installs a week from npm. Last commit 10 Mar 2026.
npm MCP — search packages, bundle sizes, vulnerabilities, compare downloads.
Today is the operative word: we check npm Plus every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add npm-plus -- npx -y mcp-server-npm-plus
{
"mcpServers": {
"npm-plus": {
"args": [
"-y",
"mcp-server-npm-plus"
],
"command": "npx"
}
}
}
[mcp_servers.npm-plus]
command = "npx"
args = ["-y", "mcp-server-npm-plus"]
{
"mcpServers": {
"npm-plus": {
"args": [
"-y",
"mcp-server-npm-plus"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"npm-plus": {
"args": [
"-y",
"mcp-server-npm-plus"
],
"command": "npx"
}
}
}
OSV.dev (Open Source Vulnerabilities) MCP.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Vanta compliance MCP server: vulnerabilities, tests, controls, evidence, people, vendors, docs
Vulnerability management: scan projects, search sealed packages, manage sealing rules and reports.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
Analyzes code for bugs, security vulnerabilities, and code smells
Real-time Python package and vulnerability data for AI coding agents.
Answers built from our own checks of this server.