Skip to main content
Glama

NPM MCP Banner

NPM MCP

Model Context Protocol server for npm registry

Search packages, check security, compare versions, and validate compatibility. Use it from Cursor AI or Claude Desktop.

Note: This is an unofficial, community-driven MCP server and is not affiliated with or endorsed by npm, Inc.

Features

  • Auto-Security — AI automatically checks packages before suggesting install (no user action!)

  • Capabilities Analysis — ESM/CJS, TypeScript, Platform support (Node/Browser/Deno), Build tools

  • Quick Start Generator — Ready-to-use code examples for any package

  • Package Comparison — Compare alternatives side-by-side (features, size, popularity)

  • Bundle Size Analysis — Minified/gzipped sizes, tree-shaking, impact on your bundle

  • Similar Packages — Find alternatives and similar packages

  • Search — Find packages with ranking and scores

  • Details — Versions, dependencies, download stats, deprecation status

  • Security — Vulnerability check and safe version tips

  • Compatibility — Peer dependency and version conflicts

  • Quality — Maintenance and community metrics

  • Version compare — Breaking changes and semver

  • NPX check — Validate npx commands before running

Related MCP server: NPM Sentinel MCP

Install & use

No global install. Add to Cursor or Claude config:

Cursor~/.cursor/mcp.json:

{
  "mcpServers": {
    "npm-registry-mcp": {
      "command": "npx",
      "args": ["@alisaitteke/npm-mcp"]
    }
  }
}

Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.json (macOS):

{
  "mcpServers": {
    "npm-registry-mcp": {
      "command": "npx",
      "args": ["@alisaitteke/npm-mcp"]
    }
  }
}

Global install (optional)

npm install -g @alisaitteke/npm-mcp

Then use "command": "npm-mcp" (no args) in the config above.

What you can ask

Once the server is connected, you can ask things like:

  • “Search for React state management libraries”

  • “Security audit for express@4.18

  • “Is lodash@4.17 compatible with my current deps?”

  • “Compare React 17 and 18”

  • “Quality check for date-fns”

  • “Is it safe to run npx create-next-app?”

License

MIT

Contributors

Thanks to everyone who helps improve this project!

Contributors

A
license - permissive license
-
quality - not tested
D
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Related MCP Servers

  • A
    license
    D
    quality
    D
    maintenance
    A Model Context Protocol server that allows AI models to fetch detailed information about npm packages and discover popular packages in the npm ecosystem.
    1
    7
    1
    ISC
  • A
    license
    A
    quality
    A
    maintenance
    A Model Context Protocol server that enables AI-powered analysis of NPM packages through multiple tools for security vulnerability scanning, dependency analysis, package comparison, and quality assessment.
    12
    19
    1,419
    18
    TypeScript
    MIT
  • A
    license
    -
    quality
    D
    maintenance
    A Model Context Protocol server that enables language models to interact with npm services securely, providing tools for package management, project initialization, script execution, and security auditing.
    7
    MIT

View all related MCP servers

Related MCP Connectors

  • A Model Context Protocol server for Wix AI tools

  • MCP server for hex.pm and hexdocs.pm: search, inspect, compare, and audit Elixir packages

  • MCP Spec Compliance MCP — audits any MCP server.json against the official Model Context Protocol

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/alisaitteke/npm-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server