wellworn
catalog entry

NPMScan

Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups

website github.comsource github.com
signals
stars
n/a
commits 3mo
n/a
last release
1.0.02026-08-01
status
active

Stars count attention, not fitness. The release date and the three-month commit count say more about whether anyone is still maintaining this.

No Wellworn verdict has been tested against NPMScan yet, so nothing on this page is a recommendation.

licence
not recorded
categories
mcp

All categories