{"uid":"cap_NIoQ-0EJwSeFSqSkL_ilD","slug":"api-x402node-dev-f4fce5e7","name":"NPM Package Safety Report","description":"Comprehensive NPM package safety report combining npm registry metadata, OSV vulnerability database, npms.io quality scores, and GitHub repo health. Returns risk_summary (low/medium/high/critical), CVE breakdown by severity, maintainer info, dependency counts, last-commit recency, archival status. Use ?package=react or ?package=react and version=18.2.0. Built for AI code-review agents and supply-chain auditors. Accepts payment on Base or Solana — either network works.","url":"https://api.x402node.dev/npm/safety","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{"version":{"type":"string","description":"Version (optional)"}}}},"additionalProperties":false}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_bjRiQX1_lhOC0PVcAHGxD","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a comprehensive safety and quality report for an NPM package, combining vulnerability data, maintainer health, dependency counts, and GitHub repo signals into a risk summary.","exampleAgentPrompt":"Can you pull a full safety report for the npm package 'lodash' version 4.17.21 — I need to know the risk level, any CVEs, whether it's still actively maintained, and if the GitHub repo is archived?","exampleUseCases":null,"resultDescription":"Returns a structured report with: risk_summary (low/medium/high/critical), CVE breakdown by severity level, maintainer information, dependency counts, last-commit recency, GitHub repo archival status, and npms.io quality scores.","failureModes":["Package not found on npm registry — returns 404 or error indicating unknown package","Invalid package name format — returns validation error","Specified version does not exist — returns version not found error","Upstream OSV or GitHub API unavailable — may return partial data or timeout","Rate limiting or payment failure — returns 402 or 429 error"],"whenToPreferThis":"Use this endpoint when an AI code-review agent or supply-chain auditor needs a single consolidated safety verdict on an npm package, combining vulnerability databases, maintainer signals, and repo health in one call — rather than querying npm, OSV, and GitHub separately.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T00:57:04.549Z","isFirstParty":false}