mcp-server-npm-plus
# mcp-server-npm-plus
[](https://www.npmjs.com/package/mcp-server-npm-plus)
[](https://www.npmjs.com/package/mcp-server-npm-plus)
[](https://github.com/ofershap/mcp-server-npm-plus/actions/workflows/ci.yml)
[](https://www.typescriptlang.org/)
[](https://opensource.org/licenses/MIT)
npm package research from your AI assistant. Search packages, check bundle sizes, scan for vulnerabilities, compare download counts, and inspect dependency trees. No API keys needed.
```bash
npx mcp-server-npm-plus
```
> Works with Claude Desktop, Cursor, VS Code Copilot, and any MCP client. Uses public npm registry APIs.

<sub>Demo built with <a href="https://github.com/ofershap/remotion-readme-kit">remotion-readme-kit</a></sub>
## Why
Choosing between npm packages usually means opening a bunch of browser tabs: npm for package info, Bundlephobia for size, Snyk for vulnerabilities, npm trends for download comparisons. This server puts all of that in one place, accessible through your AI assistant. Ask "compare zustand vs jotai vs valtio" and get download numbers, bundle sizes, and dependency counts side by side. Ask "are there any known vulnerabilities in express?" and get the answer without leaving your editor. It uses only public npm APIs, so there's nothing to sign up for.
## Tools
| Tool | Description |
| ------------------- | ----------------------------------------------------------- |
| `search` | Search npm packages by query |
| `package_info` | Get detailed info: description, license, repo, dependencies |
| `downloads` | Get download stats for a package |
| `compare_downloads` | Compare download counts across multiple packages |
| `bundle_size` | Get bundle size (minified + gzip) via Bundlephobia |
| `vulnerabilities` | Get vulnerability info and advisory links |
| `dependency_tree` | Show direct dependencies as a tree |
| `download_trends` | Daily breakdown with sparkline |
## Quick Start
### Cursor
Add to `.cursor/mcp.json`:
```json
{
"mcpServers": {
"npm-plus": {
"command": "npx",
"args": ["mcp-server-npm-plus"]
}
}
}
```
### Claude Desktop
Add to `claude_desktop_config.json`:
```json
{
"mcpServers": {
"npm-plus": {
"command": "npx",
"args": ["mcp-server-npm-plus"]
}
}
}
```
### VS Code
Use the MCP extension and configure the server with `npx mcp-server-npm-plus`.
## Example Prompts
- "Search npm for React state management libraries"
- "What's the bundle size of lodash?"
- "Compare downloads of zustand vs jotai vs valtio"
- "Check for vulnerabilities in express"
- "Show me the dependency tree for next"
- "What are the download trends for typescript this month?"
## Development
```bash
npm install
npm run typecheck
npm run build
npm test
npm run lint
npm run format
```
## See also
More MCP servers and developer tools on my [portfolio](https://gitshow.dev/ofershap).
## Author
[](https://gitshow.dev/ofershap)
[](https://linkedin.com/in/ofershap)
[](https://github.com/ofershap)
---
<sub>README built with [README Builder](https://ofershap.github.io/readme-builder/)</sub>
## License
MIT © 2026 Ofer Shapira
TDQS
Scored across 8 tools
Each tool has a clearly distinct purpose targeting specific aspects of npm package analysis, such as bundle size, downloads, dependencies, vulnerabilities, and search. There is no overlap in functionality, making it easy for an agent to select the right tool for each task.
Most tools follow a consistent snake_case naming pattern with clear verbs and nouns, like 'bundle_size', 'downloads', and 'package_info'. However, 'dependency_tree' uses a compound noun without a verb, which is a minor deviation from the otherwise uniform style.
With 8 tools, the server is well-scoped for npm package analysis, covering key areas like size, downloads, dependencies, info, search, and vulnerabilities. Each tool earns its place without feeling excessive or insufficient for the domain.
The tool set provides comprehensive coverage for npm package analysis, including info retrieval, dependency inspection, download trends, and vulnerability checks. A minor gap exists in direct package management actions like install or update, but core analysis workflows are fully supported.