ക്രമീകരണങ്ങൾ

പ്ലഗിനുകൾ

NPMScan

npm package & vuln lookups

പ്ലഗിൻ ഇൻസ്റ്റാൾ ചെയ്യുക

Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.

ആപ്പ്

NPMScan

സ്‌കില്ലുകൾ

വിവരങ്ങൾ

ഡെവലപ്പർ
SHYNGYS SHYNBOLATOV
വിഭാഗം
Developer Tools
വെബ്‌സൈറ്റ്
പതിപ്പ്
3.0.0
സ്വകാര്യതാ നയം
സേവന നിബന്ധനകൾ

NPMScan-ലേക്ക് കണക്റ്റ് ചെയ്യുമ്പോൾ, നിങ്ങളുടെ അഭ്യർത്ഥനകൾക്ക് അനുയോജ്യമായ പശ്ചാത്തലം നൽകാൻ ChatGPT പ്രസക്തമായ ചാറ്റുകളും മെമ്മറികളും ഈ ആപ്പുമായി പങ്കിട്ടേക്കാം. NPMScan ഈ ഡാറ്റ ഉപയോഗിക്കുന്നത് അവരുടെ നിബന്ധനകൾ, സ്വകാര്യതാ നയം എന്നിവയ്ക്ക് വിധേയമാണ്. മെമ്മറി പ്രവർത്തനക്ഷമമാക്കിയിട്ടുണ്ടെങ്കിൽ, സഹായകരമായ വിവരങ്ങളോ നിർദ്ദേശങ്ങളോ മുൻകൂട്ടി നൽകാൻ ആപ്പിൽ നിന്നുള്ള ഡാറ്റ ഉപയോഗിച്ചേക്കാം. കണക്റ്റ് ചെയ്ത ആപ്പുകളിൽ നിന്നുള്ള ഡാറ്റ ഉൾപ്പെടെ, നിങ്ങളുടെ പരിശീലന ഡാറ്റാ മുൻഗണനകൾ ChatGPT എപ്പോഴും മാനിക്കുന്നു. ആപ്പുകളുടെ ഉപയോഗത്തിൽ ഉയർന്ന അപകടസാധ്യത ഉണ്ടായേക്കാം. ക്രമീകരണങ്ങളിൽ എപ്പോൾ വേണമെങ്കിലും മുൻഗണനകൾ നിയന്ത്രിക്കുകയോ ആപ്പുകളിൽ നിന്ന് വിച്ഛേദിക്കുകയോ ചെയ്യാം. കൂടുതൽ അറിയുക