{"uid":"cap_kkOUE2t11pj4PfxGzOW1U","slug":"sitesignal-public-npm-package-health-snapshot-c6ef9358","name":"SiteSignal Public npm Package Health Snapshot","description":"Inspect current public npm registry metadata for release freshness, deprecation, license, repository, dependencies, maintainers, integrity, and install lifecycle scripts.","url":"https://phases-prot-shine-royal.trycloudflare.com/x402/npm-package-health","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["package"],"properties":{"package":{"type":"string","description":"Public scoped or unscoped npm package name."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_5B57dqyMaWhKPBZI4pWh8","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches current npm registry metadata for a package, including release freshness, deprecation status, license, repository, dependencies, maintainers, integrity hashes, and install lifecycle scripts.","exampleAgentPrompt":"Can you pull the npm package health snapshot for 'lodash' — I want to know if it's deprecated, who maintains it, what license it uses, and whether it has any install lifecycle scripts?","exampleUseCases":[{"title":"Pre-install security audit of a dependency","prompt":"Before I add 'got' to my project, check its npm health snapshot — I want to see if it's deprecated, whether it has postinstall scripts I should worry about, and who the current maintainers are."},{"title":"License compliance check for open source review","prompt":"Pull the npm registry metadata for 'axios' so I can confirm the license type and make sure it's still actively released — our legal team needs this for an open source audit."},{"title":"Checking freshness of a rarely-updated package","prompt":"I haven't seen any updates to 'request' in a while — can you grab its npm package health info and tell me when the last release was and whether it's been officially deprecated?"}],"resultDescription":"Returns a structured snapshot of the package's current npm registry metadata, including: latest version and release date (freshness), deprecation flag and message if any, SPDX license identifier, linked repository URL, list of direct dependencies, maintainer usernames/emails, package integrity hash (shasum/integrity), and any pre/post install lifecycle script definitions.","failureModes":["Package name not found in npm registry — returns 404 or error indicating unknown package","Scoped package name malformed (e.g. missing @) — may return empty or error response","Private or restricted package not accessible via unauthenticated public registry — returns access denied","Transient npm registry downtime — endpoint may time out or return upstream error","Rate limiting from npm registry — may result in throttled or failed responses"],"whenToPreferThis":"Use this endpoint when you need a quick, structured snapshot of a public npm package's health and metadata without setting up full npm CLI tooling. It is ideal for dependency auditing, license compliance checks, supply chain security reviews, and verifying whether a package is actively maintained or deprecated. Prefer this over general web scraping for npm package data because it queries registry metadata directly and returns structured fields for release freshness, maintainers, integrity, and lifecycle scripts in a single call.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T11:27:43.378Z","isFirstParty":false}