Check a package's health
check_packageUse this when the user asks whether an npm or PyPI package is vulnerable, maintained, deprecated or safe to use, or what license it has: "is lodash 4.17.15 vulnerable?", "is this npm package maintained?", "what license is this package?", "safer alternative to request". Pass the public package name, ecosystem (npm or pypi) and a version if the user gave one; otherwise the latest is checked. Returns the known vulnerabilities of that version with severity and fixed version, the license, any deprecation notice, last release date, releases in the last year, weekly downloads (npm) and dependents. It does not pick alternatives: for a deprecated or stale package, suggest candidates and check each one with this tool.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Public package name, such as "lodash", "@types/node" or "requests" | |
| version | No | Exact version, such as "4.17.15". Omit to check the latest. | |
| ecosystem | No | npm for JavaScript packages (the default), pypi for Python packages |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | ||
| status | Yes | ||
| message | No | ||
| version | No | The version that was checked | |
| licenses | No | ||
| ecosystem | Yes | ||
| dependents | No | Packages that depend on the latest version, directly or indirectly | |
| deprecated | No | Deprecation or withdrawal notice for the checked version | |
| maintenance | No | Release recency: active within a year, slow within two, stale beyond; deprecated when the latest version is | |
| unavailable | No | Parts of the answer that could not be read right now | |
| latestVersion | No | ||
| lastReleasedOn | No | Date of the most recent release, YYYY-MM-DD | |
| vulnerabilities | No | Known advisories (OSV) that affect the checked version, most severe first, at most 15 | |
| weeklyDownloads | No | npm only | |
| releasesLastYear | No | ||
| vulnerabilityCount | No |