Skip to main content
Glama
packagerating

packagerating MCP Server

Official

packagerating MCP Server

Give Claude (or any MCP-compatible client) live, on-demand access to packagerating.com package health/risk scores — right inside your coding session, not just in CI.

Three tools, each a thin mirror of the public REST API:

Tool

What it does

list_packages

List scored packages, sorted by composite score by default

get_package

Full score + dimension breakdown for one package by name. Transparently waits for a first-ever crawl to finish.

request_crawl

Pre-warm one or more packages for crawling without waiting on the result

A never-before-scored package can take up to ~60 seconds to return on first lookup via get_package (the server waits for the crawl to finish); every subsequent lookup is fast.

Setup

  1. Get a free API key at packagerating.com.

  2. Add this server to your MCP client config. For Claude Code, add to your MCP settings:

{
  "mcpServers": {
    "packagerating": {
      "command": "npx",
      "args": ["-y", "@packagerating/mcp-server"],
      "env": {
        "PACKAGERATING_API_KEY": "your-api-key-here"
      }
    }
  }
}

That's it — no local install, no build step. npx fetches the latest published version each time.

Related MCP server: PatternStack

Example

"Is left-pad safe to add as a dependency? What about lodash?"

Claude calls get_package for each name and can compare the results directly in conversation — liveness, community, security, dependency posture, versioning, and dependency-tree risk, plus the three composite scores (General, Automation, Risk).

Development

npm install
npm test          # unit tests, mocked HTTP — no live API calls
npm run typecheck
npm run build      # bundles to dist/index.js via @vercel/ncc
npm run smoke-test # exercises the real production API — requires a real PACKAGERATING_API_KEY
Install Server
F
license - not found
A
quality
A
maintenance

Maintenance

Maintainers
Response time
Release cycle
1Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Automatically scans project dependencies (npm, Composer) for security vulnerabilities using the OSV.dev database, providing real-time alerts and detailed remediation guidance directly in your IDE.
    1
    8
    1
    MIT
  • A
    license
    B
    quality
    D
    maintenance
    Provides crowdsourced package intelligence and security alerts for AI coding assistants by analyzing project dependencies and framework co-occurrence. It enables automated project scans, package alternative discovery, and data-driven recommendations across multiple programming ecosystems.
    10
    32
    MIT
  • A
    license
    -
    quality
    B
    maintenance
    Enables users to scan software packages for data exfiltration and security threats directly within their IDE across npm, PyPI, Cargo, and Maven ecosystems. This tool helps ensure the safety of project dependencies by identifying potential risks before they are integrated.
    MIT

View all related MCP servers

Related MCP Connectors

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/packagerating/mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server