npm and PyPI Package Vulnerability and License Check
Package Health Check answers five short questions about an npm or PyPI package, from public sources, before you depend on it. Last checked 2026-10-01.
is lodash 4.17.15 vulnerable
check_package lists the known vulnerabilities of the exact npm or PyPI version you name, with the severity of each and the version that fixes it.
Advisories come from OSV.dev. If you name no version, the latest one is checked. A package with no known advisory can still be vulnerable. Tool: check_package on https://packages.openkrill.app/mcp.
is the npm package request still maintained
check_package shows any deprecation notice, the last release date and how many releases came out in the last year.
It also shows how many packages depend on the package, and its weekly downloads for npm. A recent release date is not a security guarantee. Tool: check_package on https://packages.openkrill.app/mcp.
npm package license check
check_package returns the license that the npm registry or the PyPI JSON API lists for the package.
The license comes with the same call that returns the advisories, so one request covers the license, the vulnerabilities and the upkeep facts. Tool: check_package on https://packages.openkrill.app/mcp.
check package.json for known vulnerabilities
check_package_json reads up to 150 npm dependencies from a pasted package.json and returns the vulnerable ones, most severe first, with the fixed version.
Only dependency names and versions are read, and nothing is stored. A version range is checked at its lowest version, and a dependency with no exact version is listed as skipped. Tool: check_package_json on https://packages.openkrill.app/mcp.
safer alternative to a deprecated npm package
Package Health Check does not pick an alternative itself: your assistant suggests candidates and check_package checks each one.
Run check_package on each candidate and compare advisories, license, last release date and dependents before you switch. Tool: check_package on https://packages.openkrill.app/mcp.
Run it yourself
This page does not return live data. Call the tool on the server to get it. The server is Package Health Check at https://packages.openkrill.app/mcp, with no key. Install steps: ChatGPT, Claude, Cursor, Pi. A call to check_package was posted to the live server on 2026-10-01, and the install pages show it. The full tool list is in the MCP install guides directory.