{"uid":"cap_I4YXUL0BmCJhfvCQxogZG","slug":"aayat-ai-dependency-verdict-49c98e7e","name":"Aayat AI Dependency Verdict","description":"\"Should I use this dependency?\" in one call for npm, PyPI, crates or Go: full package safety check (vulnerabilities, malware, typosquats, deprecation, licence, downloads) plus its GitHub repository health (activity, bus factor, releases, Scorecard), a clear decision (use / use-with-care / avoid) with reasons, and plain-English advice. ?ecosystem=npm&name=express","url":"https://aayatai.com/dependency/verdict?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["name"],"properties":{"name":{"type":"string","maxLength":214,"minLength":1,"description":"Package name, e.g. express, requests, serde or github.com/gin-gonic/gin."},"version":{"type":"string","maxLength":64,"description":"Exact version to check (default: the latest release)."},"ecosystem":{"enum":["npm","pypi","crates","go"],"type":"string","default":"npm","description":"Package ecosystem: npm, pypi, crates (Rust) or go (Go modules)."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"name":"express","advice":"Express is safe to use: no known vulnerabilities in 5.1.0, active maintenance and an MIT licence.","package":{"name":"express","repo":{"forks":16000,"stars":66000,"scorecard":8.1,"openIssues":180},"flags":[{"code":"not-latest","level":"info","message":"A newer version exists: 5.1.0."}],"score":100,"sources":["deps.dev","OSV.dev","npm registry"],"verdict":"ok","version":"4.21.2","isLatest":false,"licences":["MIT"],"releases":{"latest":"5.1.0","versions":280,"firstPublishedAt":"2010-12-29T19:38:25Z","latestPublishedAt":"2026-03-31T14:00:00Z","releasesLast365Days":6},"checkedAt":"2026-09-28T12:00:00.000Z","ecosystem":"npm","deprecated":null,"repository":"https://github.com/expressjs/express","description":"Fast, unopinionated, minimalist web framework","licenceKind":"permissive","lookalikeOf":[],"maintainers":5,"latestVersion":"5.1.0","installScripts":[],"vulnerabilities":[],"weeklyDownloads":41000000,"vulnerabilityCounts":{"low":0,"high":0,"unknown":0,"critical":0,"moderate":0}},"reasons":["No known vulnerabilities, maintained, permissive licence."],"version":"5.1.0","decision":"use","checkedAt":"2026-09-28T12:00:00.000Z","ecosystem":"npm","repository":{"url":"https://github.com/honojs/hono","repo":"honojs/hono","flags":[],"forks":1346,"score":100,"stars":32361,"isFork":false,"licence":"MIT","partial":false,"sources":["GitHub REST API","deps.dev (OpenSSF Scorecard)"],"verdict":"healthy","archived":false,"checkedAt":"2026-09-28T12:00:00.000Z","createdAt":"2021-12-14T20:05:30Z","scorecard":{"date":"2026-09-22","score":7.4,"checks":[{"name":"Maintained","score":10}]},"lastPushAt":"2026-09-27T03:11:53Z","openIssues":391,"description":"Web framework built on Web Standards","defaultBranch":"main","latestRelease":{"tag":"v4.13.9","publishedAt":"2026-09-24T01:32:14Z"},"releasesLastYear":30,"commitsLast90Days":100,"communityHealthPercent":87,"activeCommittersLast90Days":24}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_PBkvB1cZb1KmXpBJirxeg","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a comprehensive safety and health check on an npm, PyPI, crates, or Go package and returns a clear use/use-with-care/avoid decision with plain-English advice.","exampleAgentPrompt":"Can you check whether it's safe to use the 'express' npm package — I need to know if it has any vulnerabilities, if it's actively maintained, what licence it uses, and whether I should go ahead and add it?","exampleUseCases":[{"title":"Pre-commit dependency safety gate","prompt":"Before I merge this PR, check whether the 'requests' PyPI package at version 2.31.0 is safe to use — flag any known CVEs, check if it's still maintained, and tell me if I should be worried."},{"title":"Rust crate evaluation for new project","prompt":"I'm starting a new Rust project and want to use 'serde'. Can you run a full safety and health check on it via crates and give me a verdict on whether it's a solid choice?"},{"title":"Suspicious package typosquat check","prompt":"I just noticed a dependency called 'expres' (without the final s) pulled into our node_modules — can you check if it's a typosquat or malware compared to the real 'express' npm package and tell me if we should avoid it?"}],"resultDescription":"A JSON object containing: the decision enum (use, use-with-care, or avoid), an array of human-readable reasons, a plain-English advice string, a full package report (vulnerabilities, licence, download counts, maintainer count, deprecation, install scripts, lookalike flags), and a GitHub repository health report (stars, forks, open issues, OpenSSF Scorecard score, commit activity, bus factor, latest release).","failureModes":["Package not found in the specified ecosystem — returns error indicating unknown package","Invalid or unsupported ecosystem value — schema validation error","Version string specified does not exist — falls back to latest or returns not-found","GitHub repository data unavailable — repository field returned as null","Rate limit or upstream registry timeout — transient 5xx error","Payment not received or insufficient — 402 Payment Required"],"whenToPreferThis":"Choose this endpoint when an AI agent needs a single-call, opinionated answer about whether to use a software dependency, combining vulnerability data, repo health, licence, and typosquat analysis into one structured verdict. Prefer it over raw OSV or deps.dev queries when you want pre-synthesized reasoning rather than raw data, and when you need coverage across npm, PyPI, crates, and Go in a unified interface.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T04:27:02.904Z","isFirstParty":false,"canonicalSlug":"aayat-ai-dependency-verdict-49c98e7e"}