{"uid":"cap_MMdFTpnuZB2AJAw1q4Xgw","slug":"pkgpulse-package-health-852d4e53","name":"pkgpulse Package Health","description":"Dependency intelligence for AI coding agents, paid per-call via x402 (USDC on Base): npm package health scores with a disclosed rubric, typosquat checks, dependency audits. Free index at /, free sample at /api/sample.","url":"https://pkgpulse.letom1176.workers.dev/api/package-health","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["name"],"properties":{"name":{"type":"string","description":"npm package name, e.g. express or @babel/core"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"name":"express","flags":[],"score":86,"signals":{"license":"MIT","weekly_downloads":30000000,"last_publish_days":40,"has_install_scripts":false},"verdict":"healthy","one_liner":"express: healthy (86/100), 30,000,000/wk, published 40d ago.","components":{"adoption":25,"integrity":25,"maintenance":36}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_-KSZfHQ0O64F7_qg0R3eO","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a health score (0–100) with adoption, integrity, and maintenance sub-scores for any npm package, plus typosquat flags and a verdict.","exampleAgentPrompt":"Can you check the health score for the npm package 'lodash' — I want to know if it's safe to add as a dependency, including its license, weekly downloads, and whether it has any install scripts?","exampleUseCases":[{"title":"Pre-install dependency vetting","prompt":"Before I add 'axios' to my project, can you pull its pkgpulse health score and tell me if it's healthy, what license it's under, and whether there are any typosquatting flags I should worry about?"},{"title":"Supply chain audit for new project","prompt":"I'm setting up a new Node.js project and want to audit a few packages. Can you check the health scores for 'express', 'dotenv', and 'helmet' on pkgpulse and flag any that score below 70 or have integrity issues?"},{"title":"Catching typosquatted packages","prompt":"I think the package 'expres' might be a typosquat — can you run it through pkgpulse and tell me if it gets flagged as suspicious and what its health verdict is?"}],"resultDescription":"A JSON object containing the package name, an overall health score (0–100), a verdict (e.g. 'healthy'), component scores for adoption, integrity, and maintenance, key signals (license, weekly downloads, days since last publish, presence of install scripts), any typosquat or risk flags, and a human-readable one-liner summary.","failureModes":["Package not found on npm registry — returns error or low score with missing signal data","Misspelled or malformed package name returns no results","Rate limiting or payment failure (x402) blocks the request","Scoped package names (e.g. @babel/core) must be passed correctly URL-encoded","Freshness lag: package metadata may not reflect very recent publishes"],"whenToPreferThis":"Use this endpoint when an AI coding agent needs a quick, scored, rubric-based health assessment of an npm package before recommending or installing it — especially when typosquat detection, license verification, and maintenance signals all matter in one call. Prefer over raw npm registry lookups when you need a structured verdict rather than raw metadata.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T00:33:03.118Z","isFirstParty":false}