Developer · Remote MCP server
NPMScan
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.salemalem/npmscan- Version
- 1.0.0
- Status
- Active
- Category
- developer
- Transport
- Streamable HTTP
- Published
- 2026-08-01
- Updated
- 2026-08-01
- Publisher
- salemalem (GitHub)
- Listed under
- GitHub MCP servers
- Repository
- github.com/salemalem/npmscan
- Source
- Registry API entry
Remote endpoints
| Transport | URL | Headers declared |
|---|---|---|
| Streamable HTTP | https://npmscan.com/api/mcp | None |
How to connect NPMScan
NPMScan is a remote MCP server: there is nothing to install. Its endpoint is https://npmscan.com/api/mcp, served over Streamable HTTP. In an assistant that accepts remote MCP servers (often under a setting named connectors, integrations or tools), add a new server and give it this URL; in a client configured by file, add it as a remote (HTTP) server with the same URL.
No headers are declared in the registry entry. If the server needs you to sign in, a client that supports MCP authorization opens the service's own sign-in page when it first connects.
Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More developer servers
| Server | Runs |
|---|---|
| npm Trends APINpm package download trends and adoption growth over time. Free key at trendsapi.ai. | Remote · HTTP |
| npm Trends MCPNpm package trends and weekly downloads over time. Free key at trendsmcp.ai. | Remote · HTTP |
| Npm Trusted Publish LintFinds the credential in your release workflow that expires before your next release. | Local · stdio |
| Npms MCPKeyless MCP server for npms.io: npm package quality, popularity and maintenance scores plus search. | Local · stdio |
| Nps MCPMCP server for U.S. National Parks: parks, alerts, campgrounds. Free key. | Local · stdio |
| npx-vibeRead-only npm package and project dependency preflight tools for AI applications. | Local · stdio |
| Nr MCPMCP server for Node-RED — safe deploy, optimistic locking, search, 13 tools. | Local · stdio |
| NrelNREL MCP — wraps the US National Renewable Energy Laboratory developer API. | Remote · HTTP |