NPM MCP
Search and analyze npm packages, check security vulnerabilities, compare versions, validate compatibility, and get quality metrics from the npm registry.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@NPM MCPSecurity audit for express@4.18"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.

NPM MCP
Model Context Protocol server for npm registry
Search packages, check security, compare versions, and validate compatibility. Use it from Cursor AI or Claude Desktop.
Note: This is an unofficial, community-driven MCP server and is not affiliated with or endorsed by npm, Inc.
Features
Auto-Security — AI automatically checks packages before suggesting install (no user action!)
Capabilities Analysis — ESM/CJS, TypeScript, Platform support (Node/Browser/Deno), Build tools
Quick Start Generator — Ready-to-use code examples for any package
Package Comparison — Compare alternatives side-by-side (features, size, popularity)
Bundle Size Analysis — Minified/gzipped sizes, tree-shaking, impact on your bundle
Similar Packages — Find alternatives and similar packages
Search — Find packages with ranking and scores
Details — Versions, dependencies, download stats, deprecation status
Security — Vulnerability check and safe version tips
Compatibility — Peer dependency and version conflicts
Quality — Maintenance and community metrics
Version compare — Breaking changes and semver
NPX check — Validate npx commands before running
Related MCP server: NPM Sentinel MCP
Install & use
With npx (recommended)
No global install. Add to Cursor or Claude config:
Cursor — ~/.cursor/mcp.json:
{
"mcpServers": {
"npm-registry-mcp": {
"command": "npx",
"args": ["@alisaitteke/npm-mcp"]
}
}
}Claude Desktop — ~/Library/Application Support/Claude/claude_desktop_config.json (macOS):
{
"mcpServers": {
"npm-registry-mcp": {
"command": "npx",
"args": ["@alisaitteke/npm-mcp"]
}
}
}Global install (optional)
npm install -g @alisaitteke/npm-mcpThen use "command": "npm-mcp" (no args) in the config above.
What you can ask
Once the server is connected, you can ask things like:
“Search for React state management libraries”
“Security audit for express@4.18”
“Is lodash@4.17 compatible with my current deps?”
“Compare React 17 and 18”
“Quality check for date-fns”
“Is it safe to run npx create-next-app?”
License
MIT
Contributors
Thanks to everyone who helps improve this project!
This server cannot be installed
Maintenance
Related MCP Servers
- AlicenseDqualityDmaintenanceA Model Context Protocol server that allows AI models to fetch detailed information about npm packages and discover popular packages in the npm ecosystem.171ISC
- AlicenseAqualityAmaintenanceA Model Context Protocol server that enables AI-powered analysis of NPM packages through multiple tools for security vulnerability scanning, dependency analysis, package comparison, and quality assessment.12191,41918TypeScriptMIT
- Alicense-qualityDmaintenanceA Model Context Protocol server that enables language models to interact with npm services securely, providing tools for package management, project initialization, script execution, and security auditing.7MIT
- Alicense-qualityCmaintenanceModel Context Protocol server for the JSR (JavaScript Registry)3MIT
Related MCP Connectors
A Model Context Protocol server for Wix AI tools
MCP server for hex.pm and hexdocs.pm: search, inspect, compare, and audit Elixir packages
MCP Spec Compliance MCP — audits any MCP server.json against the official Model Context Protocol
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/alisaitteke/npm-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server