# GET /dependency/report: $0.08 per call

Premium "should I use this dependency?" report: package safety (vulnerabilities, malware, typosquats, deprecation), GitHub repository health, licence compatibility with YOUR project and usage, the most popular alternatives each safety-checked, and an AI comparison with a clear use / use-with-care / avoid decision. ?name=moment&project=MIT

- **Price:** $0.08 in USDC, the same on Base, Solana, Polygon, Arbitrum. Failed calls are never charged.
- **Free trial:** no, paid only (it uses a paid AI model or data source, or costs more than the trial covers). Other ways to pay: x402 or [prepaid credits](/credits).
- **Tier:** deep
- **Answers cached for:** 6 hour(s)
- **Data sources:** deps.dev, OSV.dev, npm/PyPI/crates.io registries (free); GitHub REST (free); npm and crates.io search for alternatives (free); Workers AI (metered)
- **Lane:** AI coding agents ([OpenAPI](/openapi/coding.json))
- **Live health:** [status page](/status)

## Free sample

See an answer for the demo input first, free (no payment, 10 a minute): [https://aayatai.com/sample/dependency-report](/sample/dependency-report). It is a stored real answer when we have one, otherwise an example marked `"kind": "illustrative"`.

```bash
curl "https://aayatai.com/sample/dependency-report"
```

## 1. See the price (free)

Call it without paying: you get `402 Payment Required` and a `PAYMENT-REQUIRED` header with the exact price and where to pay.

```bash
curl -i "https://aayatai.com/dependency/report?ecosystem=npm&name=express&project=proprietary&usage=saas"
```

## 2. Pay and call (TypeScript)

```bash
npm install @x402/fetch @x402/evm viem
```

```ts
import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

// A wallet used only by your agent, holding a little USDC on Base.
const account = privateKeyToAccount(process.env.WALLET_PRIVATE_KEY as `0x${string}`);
const pay = wrapFetchWithPaymentFromConfig(fetch, {
  schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(account) }],
});

const res = await pay("https://aayatai.com/dependency/report?ecosystem=npm&name=express&project=proprietary&usage=saas");
console.log(await res.json());
```

## 3. Or as an MCP tool

```ts
// MCP server: https://aayatai.com/mcp (Streamable HTTP). With the x402 MCP client (see /start):
const result = await client.callTool("dependency-report", {"ecosystem":"npm","name":"express","project":"proprietary","usage":"saas"});
```

## Inputs

- `ecosystem` (string; one of `npm`, `pypi`, `crates`, `go`; default `npm`): Package ecosystem: npm, pypi, crates (Rust) or go (Go modules).
- `name` **(required)** (string): Package name, e.g. express, requests, serde or github.com/gin-gonic/gin.
- `version` (string): Exact version to check (default: the latest release).
- `project` (string; default `proprietary`): Your project's licence (SPDX id, e.g. MIT) or proprietary.
- `usage` (string; one of `distributed`, `saas`, `internal`; default `distributed`): How your project is used: distributed, saas or internal.

Bad inputs are rejected with HTTP 400 before any payment is asked for.

## Example answer

```json
{
  "ecosystem": "npm",
  "name": "express",
  "version": "5.1.0",
  "decision": "use",
  "reasons": [
    "No known vulnerabilities, maintained, permissive licence."
  ],
  "licence": {
    "licence": "MIT",
    "family": "permissive",
    "status": "ok",
    "reason": "Permissive: keep its copyright and licence notice."
  },
  "report": "## Recommendation\nUse express 5.1.0 ...\n\n## Alternatives\n- fastify: faster, also MIT ...",
  "package": {
    "name": "express",
    "verdict": "ok",
    "score": 100
  },
  "repository": {
    "repo": "expressjs/express",
    "verdict": "healthy"
  },
  "alternatives": {
    "keywords": [
      "framework",
      "router"
    ],
    "checked": [
      {
        "name": "fastify",
        "verdict": "ok",
        "score": 100,
        "weeklyDownloads": 5000000,
        "licence": "MIT",
        "licenceStatus": "ok"
      }
    ],
    "note": null
  },
  "disclaimer": "Automated guidance from licence texts and common compatibility rules, not legal advice.",
  "checkedAt": "2026-09-28T12:00:00.000Z"
}
```

## Related

- [GET /docs/find](/services/docs-find) ($0.003): Find the AI-ready docs for any library or API: checks the project's docs site (from its npm, PyPI, crates or Go metadata) or any company domain (docs., develope
- [GET /docs/lib](/services/docs-lib) ($0.005): Up-to-date docs for any npm, PyPI, crates or Go library, trimmed for a coding agent's context: finds the project's own llms.txt and docs pages (or the latest re
- [POST /docs/answer](/services/docs-answer) ($0.02): Ask a coding question about any npm, PyPI, crates or Go library and get an answer written only from its current docs (project llms.txt, docs pages or latest REA
- [GET /openapi](/services/openapi) ($0.005): Understand any public API fast: give its OpenAPI/Swagger spec URL, its docs or base URL, or a name from the APIs.guru directory (?api=stripe.com); we find the s
- [GET /library/research](/services/library-research) ($0.10): Premium research report on a library or API for coding agents: reads its current docs for your goal, checks version, safety and repository health, gathers what 
- [GET /package/check](/services/package-check) ($0.005): Should a coding agent install this package?
- [GET /dependency/verdict](/services/dependency-verdict) ($0.03): "Should I use this dependency?" in one call for npm, PyPI, crates or Go: full package safety check (vulnerabilities, malware, typosquats, deprecation, licence, 
- [GET /package/changes](/services/package-changes) ($0.005): What changed between two versions of an npm, PyPI, crates or Go package: every release's notes from GitHub releases (or the CHANGELOG), newest first, with lines

New here? [Getting started in 60 seconds](/start). All services: [Aayat AI](/).