# GET /package/check: $0.005 per call

Should a coding agent install this package? Checks one npm, PyPI, crates or Go package version for known vulnerabilities and malware (OSV.dev), deprecation, typosquat look-alike names, install scripts, licence, downloads, release activity and OpenSSF Scorecard, then gives a verdict (ok/caution/avoid), a 0-100 score and every reason. Pass ?ecosystem=npm&name=express.

- **Price:** $0.005 in USDC, the same on Base, Solana, Polygon, Arbitrum. Failed calls are never charged.
- **Free trial:** yes, 20 free calls a day from Claude, Cursor or any MCP client ([set-up](/mcp/setup)).
- **Tier:** live
- **Answers cached for:** 1 hour(s)
- **Data sources:** deps.dev (free); OSV.dev (free); npm/PyPI/crates.io registries (free)
- **Lane:** AI coding agents ([OpenAPI](/openapi/coding.json))
- **Live health:** [status page](/status)

## Free sample

See an answer for the demo input first, free (no payment, 10 a minute): [https://aayatai.com/sample/package-check](/sample/package-check). It is a stored real answer when we have one, otherwise an example marked `"kind": "illustrative"`.

```bash
curl "https://aayatai.com/sample/package-check"
```

## 1. See the price (free)

Call it without paying: you get `402 Payment Required` and a `PAYMENT-REQUIRED` header with the exact price and where to pay.

```bash
curl -i "https://aayatai.com/package/check?ecosystem=npm&name=express&version=4.21.2"
```

## 2. Pay and call (TypeScript)

```bash
npm install @x402/fetch @x402/evm viem
```

```ts
import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

// A wallet used only by your agent, holding a little USDC on Base.
const account = privateKeyToAccount(process.env.WALLET_PRIVATE_KEY as `0x${string}`);
const pay = wrapFetchWithPaymentFromConfig(fetch, {
  schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(account) }],
});

const res = await pay("https://aayatai.com/package/check?ecosystem=npm&name=express&version=4.21.2");
console.log(await res.json());
```

## 3. Or as an MCP tool

```ts
// MCP server: https://aayatai.com/mcp (Streamable HTTP). With the x402 MCP client (see /start):
const result = await client.callTool("package-check", {"ecosystem":"npm","name":"express","version":"4.21.2"});
```

## Inputs

- `ecosystem` (string; one of `npm`, `pypi`, `crates`, `go`; default `npm`): Package ecosystem: npm, pypi, crates (Rust) or go (Go modules).
- `name` **(required)** (string): Package name, e.g. express, requests, serde or github.com/gin-gonic/gin.
- `version` (string): Exact version to check (default: the latest release).

Bad inputs are rejected with HTTP 400 before any payment is asked for.

## Example answer

```json
{
  "ecosystem": "npm",
  "name": "express",
  "version": "4.21.2",
  "latestVersion": "5.1.0",
  "isLatest": false,
  "verdict": "ok",
  "score": 100,
  "flags": [
    {
      "level": "info",
      "code": "not-latest",
      "message": "A newer version exists: 5.1.0."
    }
  ],
  "vulnerabilities": [],
  "vulnerabilityCounts": {
    "critical": 0,
    "high": 0,
    "moderate": 0,
    "low": 0,
    "unknown": 0
  },
  "licences": [
    "MIT"
  ],
  "licenceKind": "permissive",
  "deprecated": null,
  "weeklyDownloads": 41000000,
  "maintainers": 5,
  "installScripts": [],
  "releases": {
    "latest": "5.1.0",
    "latestPublishedAt": "2026-03-31T14:00:00Z",
    "firstPublishedAt": "2010-12-29T19:38:25Z",
    "versions": 280,
    "releasesLast365Days": 6
  },
  "repository": "https://github.com/expressjs/express",
  "repo": {
    "stars": 66000,
    "forks": 16000,
    "openIssues": 180,
    "scorecard": 8.1
  },
  "description": "Fast, unopinionated, minimalist web framework",
  "lookalikeOf": [],
  "sources": [
    "deps.dev",
    "OSV.dev",
    "npm registry"
  ],
  "checkedAt": "2026-09-28T12:00:00.000Z"
}
```

## Related

- [GET /docs/find](/services/docs-find) ($0.003): Find the AI-ready docs for any library or API: checks the project's docs site (from its npm, PyPI, crates or Go metadata) or any company domain (docs., develope
- [GET /docs/lib](/services/docs-lib) ($0.005): Up-to-date docs for any npm, PyPI, crates or Go library, trimmed for a coding agent's context: finds the project's own llms.txt and docs pages (or the latest re
- [POST /docs/answer](/services/docs-answer) ($0.02): Ask a coding question about any npm, PyPI, crates or Go library and get an answer written only from its current docs (project llms.txt, docs pages or latest REA
- [GET /openapi](/services/openapi) ($0.005): Understand any public API fast: give its OpenAPI/Swagger spec URL, its docs or base URL, or a name from the APIs.guru directory (?api=stripe.com); we find the s
- [GET /library/research](/services/library-research) ($0.10): Premium research report on a library or API for coding agents: reads its current docs for your goal, checks version, safety and repository health, gathers what 
- [GET /dependency/verdict](/services/dependency-verdict) ($0.03): "Should I use this dependency?" in one call for npm, PyPI, crates or Go: full package safety check (vulnerabilities, malware, typosquats, deprecation, licence, 
- [GET /dependency/report](/services/dependency-report) ($0.08): Premium "should I use this dependency?" report: package safety (vulnerabilities, malware, typosquats, deprecation), GitHub repository health, licence compatibil
- [GET /package/changes](/services/package-changes) ($0.005): What changed between two versions of an npm, PyPI, crates or Go package: every release's notes from GitHub releases (or the CHANGELOG), newest first, with lines

New here? [Getting started in 60 seconds](/start). All services: [Aayat AI](/).