NPMScan is answering right now. Last checked 1 min ago. It exposes 6 tools.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
The linked repository no longer exists on GitHub — it was deleted or made private.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 1 min ago.
claude mcp add npmscan --transport http https://npmscan.com/api/mcp
{
"mcpServers": {
"npmscan": {
"url": "https://npmscan.com/api/mcp"
}
}
}
[mcp_servers.npmscan]
url = "https://npmscan.com/api/mcp"
{
"mcpServers": {
"npmscan": {
"url": "https://npmscan.com/api/mcp"
}
}
}
{
"mcpServers": {
"npmscan": {
"url": "https://npmscan.com/api/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
get_package
get_package_version
batch_query_vulnerabilities
get_latest_advisories
search_packages
query_vulnerabilities
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://npmscan.com/api/mcp | streamable-http | answering | 314 ms | 1 min ago |
Answers built from our own checks of this server.