அமைப்புகள்

செருகுநிரல்கள்

NPMScan

npm package & vuln lookups

பிளக்-இன்னை நிறுவுங்கள்

Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing; check an exact version pinned in a lockfile; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; browse the latest reviewed npm advisories, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.

செயலி

NPMScan

திறன்கள்

தகவல்

உருவாக்குநர்
SHYNGGYS SHYNBOLATOV
வகை
Developer Tools
வலைத்தளம்
பதிப்பு
2.0.0
தனியுரிமைக் கொள்கை
சேவை விதிமுறைகள்