{"slug":"aayatai-com-package-check-6ee546","title":"Should a coding agent install this package?","host":"aayatai.com","method":"GET","resource":"https://aayatai.com/package/check","category":"other","description":"Should a coding agent install this package? Checks one npm, PyPI, crates or Go package version for known vulnerabilities and malware (OSV.dev), deprecation, typosquat look-alike names, install scripts, licence, downloads, release activity and OpenSSF Scorecard, then gives a verdict (ok/caution/avoid","price_listed":0.005,"price_asked":0.005,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":19,"reported_calls_30d":1,"reported_payers_30d":1,"networks":["eip155:137","eip155:42161","eip155:8453","solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"method":"GET","queryParams":{"ecosystem":"npm","name":"express","version":"4.21.2"},"type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET"],"type":"string"},"queryParams":{"properties":{"ecosystem":{"default":"npm","description":"Package ecosystem: npm, pypi, crates (Rust) or go (Go modules).","enum":["npm","pypi","crates","go"],"type":"string"},"name":{"description":"Package name, e.g. express, requests, serde or github.com/gin-gonic/gin.","maxLength":214,"minLength":1,"type":"string"},"version":{"description":"Exact version to check (default: the latest release).","maxLength":64,"type":"string"}},"required":["name"],"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"properties":{"checkedAt":{"type":"string"},"deprecated":{"type":["string","null"]},"description":{"type":["string","null"]},"ecosystem":{"type":"string"},"flags":{"description":"Every reason behind the verdict.","items":{"properties":{"code":{"type":"string"},"level":{"enum":["danger","warning","info"],"type":"string"},"message":{"type":"string"}},"type":"object"},"type":"array"},"installScripts":{"description":"npm install hooks that run code on install.","items":{"type":"string"},"type":"array"},"isLatest":{"type":"boolean"},"latestVersion":{"type":["string","null"]},"licenceKind":{"enum":["permissive","copyleft","unknown","none"],"type":"string"},"licences":{"items":{"type":"string"},"type":"array"},"lookalikeOf":{"description":"Popular packages this name resembles (typosquat check).","items":{"type":"string"},"type":"array"},"maintainers":{"type":["integer","null"]},"name":{"type":"string"},"releases":{"description":"latest, latestPublishedAt, firstPublishedAt, versions, releasesLast365Days.","type":"object"},"repo":{"description":"GitHub stars, forks, open issues and OpenSSF Scorecard (0-10).","type":["object","null"]},"repository":{"type":["string","null"]},"score":{"description":"0-100, higher is safer.","type":"integer"},"sources":{"items":{"type":"string"},"type":"array"},"verdict":{"enum":["ok","caution","avoid"],"type":"string"},"version":{"description":"Version checked.","type":"string"},"vulnerabilities":{"description":"Known vulnerabilities in this version (most severe first, up to 25).","items":{"properties":{"aliases":{"items":{"type":"string"},"type":"array"},"fixedIn":{"items":{"type":"string"},"type":"array"},"id":{"type":"string"},"published":{"type":["string","null"]},"severity":{"enum":["critical","high","moderate","low","unknown"],"type":"string"},"summary":{"type":"string"},"url":{"type":"string"}},"type":"object"},"type":"array"},"vulnerabilityCounts":{"type":"object"},"weeklyDownloads":{"type":["integer","null"]}},"required":["ecosystem","name","version","verdict","score","flags","vulnerabilities","licences"],"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-09-28","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.005,"price_match":true,"latency_ms":19,"error":null}],"description_full":"Should a coding agent install this package? Checks one npm, PyPI, crates or Go package version for known vulnerabilities and malware (OSV.dev), deprecation, typosquat look-alike names, install scripts, licence, downloads, release activity and OpenSSF Scorecard, then gives a verdict (ok/caution/avoid), a 0-100 score and every reason. Pass ?ecosystem=npm&name=express.","last_updated":"2026-09-28T10:46:47.763Z","schemes":["exact"]}