Is io.github.salemalem/npmscan up? Live MCP status
Not checked just now. The live check did not run for this request (more than 120 status pages asked for a fresh check in the last minute). Reload in a minute; the monthly census result is below.
| Endpoint | https://npmscan.com/api/mcp |
|---|---|
| Page built |
One MCP handshake with the listed endpoint (server/discover at 2026-07-28, then initialize for a server on the older revision), with no credential and no retry, identifying itself as agentwares-mcp-liveness/0.1 (+https://agentwares-agentcheck.vercel.app/bot). It runs when this page is requested and the result is reused for 10 minutes, so the time above is when it was taken.
Live status every few hours: Wellknown
Email me when this server changes
That was one look. To hear when it stops answering or its tools change, leave an address.
Free, no password or GitHub: one confirmation email first, then a check every hour and an email when it stops answering or its tools change. Every email has a link to stop. More about it.
Monthly census, 6 October 2026
The census sends the same request to every remote listing in the official registry once a month. On 6 October 2026 this one answered a stock client with no credential. Every listing’s result: index.ndjson (what the files hold: index.meta.json).
Agent discovery documents at this origin
| A2A agent card | Not published (HTTP 404)./.well-known/agent-card.json |
|---|---|
| MCP server card (SEP-2127) | Not published (HTTP 404).https://npmscan.com/api/mcp/server-card |
| MCP server card (SEP-1649 location) | Not published (HTTP 404)./.well-known/mcp/server-card.json — SEP-1649, a draft superseded by SEP-2127 on 21 January 2026 |
| Web Bot Auth key directory | Not published (HTTP 404)./.well-known/http-message-signatures-directory |
Read at https://npmscan.com with the monthly census on 9 October 2026: one GET each, no credential, never a signed request. A2A against v1.0.1, the server card against the MCP Server Card schema (SEP-2127), the card at SEP-1649’s location against the shape it has, the key directory against the Web Bot Auth draft of 1 September 2026. Who publishes them.
Tool changes between snapshots
In the 2026-10 snapshot it listed 23 tools: analyze_install_script, analyze_transitive_dependencies, audit_github_repository, batch_query_vulnerabilities, check_license_compliance, check_maintainer_blast_radius, check_maintainer_changes, check_package_provenance, compare_packages, diff_dependencies, enrich_npm_audit, generate_sbom, get_cve, get_latest_advisories, get_maintainer_profile, get_package, get_package_version, get_remediation_playbook, prioritize_remediation, query_vulnerabilities, search_packages, simulate_dependency_upgrade, suggest_alternative.
Its tools changed between 2026-09 and 2026-10:
analyze_transitive_dependencies: description, output schema changedaudit_github_repository: description, input schema, output schema changedbatch_query_vulnerabilities: description, input schema, output schema changedcheck_maintainer_blast_radius: description, input schema, output schema changedcheck_maintainer_changes: description changedcompare_packages: description, input schema, output schema changeddiff_dependencies: description, output schema changedenrich_npm_audit: description, output schema changedgenerate_sbom: description, input schema changedget_cve: description, output schema changedget_latest_advisories: description, output schema changedget_maintainer_profile: description, input schema, output schema changedget_package: description, output schema changedget_package_version: description, input schema, output schema changedprioritize_remediation: description, input schema, output schema changedquery_vulnerabilities: description, input schema, output schema changedsimulate_dependency_upgrade: description, input schema, output schema changedsuggest_alternative: description, output schema changed
Which tools were added or removed, and whose description or schemas changed, from content hashes in the monthly snapshots. Per tool, as JSON: /v1/drift.
The listing
| Registry name | io.github.salemalem/npmscan |
|---|---|
| Endpoint | https://npmscan.com/api/mcp |
| Publisher repository | not known: the registry did not return this listing within 4 seconds |
Also
The full check by name, as JSON (on a 401 it also follows the OAuth discovery chain) · Watch it · Check another server · llms.txt