# GET /dependency/verdict: $0.03 per call

"Should I use this dependency?" in one call for npm, PyPI, crates or Go: full package safety check (vulnerabilities, malware, typosquats, deprecation, licence, downloads) plus its GitHub repository health (activity, bus factor, releases, Scorecard), a clear decision (use / use-with-care / avoid) with reasons, and plain-English advice. ?ecosystem=npm&name=express

- **Price:** $0.03 in USDC, the same on Base, Solana, Polygon, Arbitrum. Failed calls are never charged.
- **Free trial:** yes, 20 free calls a day from Claude, Cursor or any MCP client ([set-up](/mcp/setup)).
- **Tier:** deep
- **Answers cached for:** 1 hour(s)
- **Data sources:** deps.dev (free); OSV.dev (free); npm/PyPI/crates.io registries (free); GitHub REST API (free); Workers AI (metered)
- **Lane:** AI coding agents ([OpenAPI](/openapi/coding.json))
- **Live health:** [status page](/status)

## Free sample

See an answer for the demo input first, free (no payment, 10 a minute): [https://aayatai.com/sample/dependency-verdict](/sample/dependency-verdict). It is a stored real answer when we have one, otherwise an example marked `"kind": "illustrative"`.

```bash
curl "https://aayatai.com/sample/dependency-verdict"
```

## 1. See the price (free)

Call it without paying: you get `402 Payment Required` and a `PAYMENT-REQUIRED` header with the exact price and where to pay.

```bash
curl -i "https://aayatai.com/dependency/verdict?ecosystem=npm&name=express"
```

## 2. Pay and call (TypeScript)

```bash
npm install @x402/fetch @x402/evm viem
```

```ts
import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

// A wallet used only by your agent, holding a little USDC on Base.
const account = privateKeyToAccount(process.env.WALLET_PRIVATE_KEY as `0x${string}`);
const pay = wrapFetchWithPaymentFromConfig(fetch, {
  schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(account) }],
});

const res = await pay("https://aayatai.com/dependency/verdict?ecosystem=npm&name=express");
console.log(await res.json());
```

## 3. Or as an MCP tool

```ts
// MCP server: https://aayatai.com/mcp (Streamable HTTP). With the x402 MCP client (see /start):
const result = await client.callTool("dependency-verdict", {"ecosystem":"npm","name":"express"});
```

## Inputs

- `ecosystem` (string; one of `npm`, `pypi`, `crates`, `go`; default `npm`): Package ecosystem: npm, pypi, crates (Rust) or go (Go modules).
- `name` **(required)** (string): Package name, e.g. express, requests, serde or github.com/gin-gonic/gin.
- `version` (string): Exact version to check (default: the latest release).

Bad inputs are rejected with HTTP 400 before any payment is asked for.

## Example answer

```json
{
  "ecosystem": "npm",
  "name": "express",
  "version": "5.1.0",
  "decision": "use",
  "reasons": [
    "No known vulnerabilities, maintained, permissive licence."
  ],
  "advice": "Express is safe to use: no known vulnerabilities in 5.1.0, active maintenance and an MIT licence.",
  "package": {
    "ecosystem": "npm",
    "name": "express",
    "version": "4.21.2",
    "latestVersion": "5.1.0",
    "isLatest": false,
    "verdict": "ok",
    "score": 100,
    "flags": [
      {
        "level": "info",
        "code": "not-latest",
        "message": "A newer version exists: 5.1.0."
      }
    ],
    "vulnerabilities": [],
    "vulnerabilityCounts": {
      "critical": 0,
      "high": 0,
      "moderate": 0,
      "low": 0,
      "unknown": 0
    },
    "licences": [
      "MIT"
    ],
    "licenceKind": "permissive",
    "deprecated": null,
    "weeklyDownloads": 41000000,
    "maintainers": 5,
    "installScripts": [],
    "releases": {
      "latest": "5.1.0",
      "latestPublishedAt": "2026-03-31T14:00:00Z",
      "firstPublishedAt": "2010-12-29T19:38:25Z",
      "versions": 280,
      "releasesLast365Days": 6
    },
    "repository": "https://github.com/expressjs/express",
    "repo": {
      "stars": 66000,
      "forks": 16000,
      "openIssues": 180,
      "scorecard": 8.1
    },
    "description": "Fast, unopinionated, minimalist web framework",
    "lookalikeOf": [],
    "sources": [
      "deps.dev",
      "OSV.dev",
      "npm registry"
    ],
    "checkedAt": "2026-09-28T12:00:00.000Z"
  },
  "repository": {
    "repo": "honojs/hono",
    "url": "https://github.com/honojs/hono",
    "description": "Web framework built on Web Standards",
    "verdict": "healthy",
    "score": 100,
    "flags": [],
    "stars": 32361,
    "forks": 1346,
    "openIssues": 391,
    "archived": false,
    "isFork": false,
    "licence": "MIT",
    "defaultBranch": "main",
    "createdAt": "2021-12-14T20:05:30Z",
    "lastPushAt": "2026-09-27T03:11:53Z",
    "latestRelease": {
      "tag": "v4.13.9",
      "publishedAt": "2026-09-24T01:32:14Z"
    },
    "releasesLastYear": 30,
    "commitsLast90Days": 100,
    "activeCommittersLast90Days": 24,
    "communityHealthPercent": 87,
    "scorecard": {
      "score": 7.4,
      "date": "2026-09-22",
      "checks": [
        {
          "name": "Maintained",
          "score": 10
        }
      ]
    },
    "partial": false,
    "sources": [
      "GitHub REST API",
      "deps.dev (OpenSSF Scorecard)"
    ],
    "checkedAt": "2026-09-28T12:00:00.000Z"
  },
  "checkedAt": "2026-09-28T12:00:00.000Z"
}
```

## Related

- [GET /docs/find](/services/docs-find) ($0.003): Find the AI-ready docs for any library or API: checks the project's docs site (from its npm, PyPI, crates or Go metadata) or any company domain (docs., develope
- [GET /docs/lib](/services/docs-lib) ($0.005): Up-to-date docs for any npm, PyPI, crates or Go library, trimmed for a coding agent's context: finds the project's own llms.txt and docs pages (or the latest re
- [POST /docs/answer](/services/docs-answer) ($0.02): Ask a coding question about any npm, PyPI, crates or Go library and get an answer written only from its current docs (project llms.txt, docs pages or latest REA
- [GET /openapi](/services/openapi) ($0.005): Understand any public API fast: give its OpenAPI/Swagger spec URL, its docs or base URL, or a name from the APIs.guru directory (?api=stripe.com); we find the s
- [GET /library/research](/services/library-research) ($0.10): Premium research report on a library or API for coding agents: reads its current docs for your goal, checks version, safety and repository health, gathers what 
- [GET /package/check](/services/package-check) ($0.005): Should a coding agent install this package?
- [GET /dependency/report](/services/dependency-report) ($0.08): Premium "should I use this dependency?" report: package safety (vulnerabilities, malware, typosquats, deprecation), GitHub repository health, licence compatibil
- [GET /package/changes](/services/package-changes) ($0.005): What changed between two versions of an npm, PyPI, crates or Go package: every release's notes from GitHub releases (or the CHANGELOG), newest first, with lines

New here? [Getting started in 60 seconds](/start). All services: [Aayat AI](/).