NPM MCP
<div align="center">

# NPM MCP
**Model Context Protocol server for npm registry**
Search packages, check security, compare versions, and validate compatibility. Use it from Cursor AI or Claude Desktop.
> **Note:** This is an unofficial, community-driven MCP server and is not affiliated with or endorsed by npm, Inc.
</div>
## Features
- **Auto-Security** — AI automatically checks packages before suggesting install (no user action!)
- **Capabilities Analysis** — ESM/CJS, TypeScript, Platform support (Node/Browser/Deno), Build tools
- **Quick Start Generator** — Ready-to-use code examples for any package
- **Package Comparison** — Compare alternatives side-by-side (features, size, popularity)
- **Bundle Size Analysis** — Minified/gzipped sizes, tree-shaking, impact on your bundle
- **Similar Packages** — Find alternatives and similar packages
- **Search** — Find packages with ranking and scores
- **Details** — Versions, dependencies, download stats, deprecation status
- **Security** — Vulnerability check and safe version tips
- **Compatibility** — Peer dependency and version conflicts
- **Quality** — Maintenance and community metrics
- **Version compare** — Breaking changes and semver
- **NPX check** — Validate npx commands before running
## Install & use
### With npx (recommended)
No global install. Add to Cursor or Claude config:
**Cursor** — `~/.cursor/mcp.json`:
```json
{
"mcpServers": {
"npm-registry-mcp": {
"command": "npx",
"args": ["@alisaitteke/npm-mcp"]
}
}
}
```
**Claude Desktop** — `~/Library/Application Support/Claude/claude_desktop_config.json` (macOS):
```json
{
"mcpServers": {
"npm-registry-mcp": {
"command": "npx",
"args": ["@alisaitteke/npm-mcp"]
}
}
}
```
### Global install (optional)
```bash
npm install -g @alisaitteke/npm-mcp
```
Then use `"command": "npm-mcp"` (no `args`) in the config above.
## What you can ask
Once the server is connected, you can ask things like:
- “Search for React state management libraries”
- “Security audit for express@4.18”
- “Is lodash@4.17 compatible with my current deps?”
- “Compare React 17 and 18”
- “Quality check for date-fns”
- “Is it safe to run npx create-next-app?”
## License
MIT
## Contributors
<table>
<tr>
<td align="center">
<a href="https://github.com/alisaitteke">
<img src="https://github.com/alisaitteke.png" width="100px;" alt="Ali Sait Teke"/>
<br />
<sub><b>Ali Sait Teke</b></sub>
</a>
<br />
<sub>Creator & Maintainer</sub>
</td>
</tr>
</table>
Thanks to everyone who helps improve this project!
[](https://github.com/alisaitteke/npm-mcp/graphs/contributors)
TDQS
Scored across 12 tools
Each tool targets a distinct aspect of npm package interaction: searching, comparing, analyzing security, quality, capabilities, bundle size, and generating code. Though some tools are related, their descriptions clearly differentiate purposes (e.g., search_packages finds packages by keyword, find_similar_packages finds alternatives to a given package). No two tools appear to do the same thing.
All tool names follow a consistent verb_noun pattern in snake_case (e.g., search_packages, analyze_quality, get_package_details). The verbs are descriptive and each noun is appropriate for the operation. This is a uniform, predictable naming convention.
With 12 tools, the server is well-scoped for its purpose of npm package analysis and discovery. Each tool covers a distinct need without bloat, fitting comfortably within the ideal 3-15 range. The count supports thorough functionality without overwhelming an agent.
The tool set covers the full spectrum of package evaluation: discovery, detailed inspection, version comparison, security audits, quality analysis, compatibility checking, bundle size analysis, and quick-start code generation. There are no obvious dead ends—after finding a package, an agent can analyze it in multiple ways and even get usage examples. The surface is complete for the intended domain.