Comprehensive NPM package safety report combining npm registry metadata, OSV vulnerability database, npms.ioGET /npm/safety · x402 API by x402node
Comprehensive NPM package safety report combining npm registry metadata, OSV vulnerability database, npms.io quality scores, and GitHub repo health. Returns risk_summary (low/medium/high/critical), CVE breakdown by severity, maintainer info, dependency counts, last-commit recency, archival status. Use ?package=react or ?package=react and version=18.2.0. Built for AI code-review agents and supply-chain auditors.
What does this x402 API do?
Comprehensive NPM package safety report combining npm registry metadata, OSV vulnerability database, npms.io. This is an x402-gated GET API resource from x402node. TOLL·402 confirmed a protocol-valid HTTP 402 quote on 2026-07-21. The listing records $0.02 USD-denominated per request on Base and Solana. No settled paid call has been verified.
- Published price
- $0.02 USD-denominated per request
- Networks
- Base · Solana
- Latest evidence
- TOLL·402 confirmed a protocol-valid HTTP 402 quote on 2026-07-21
- Resource ID
- 8e297da185f24ad0a1ebacf2
Start with a quote-only recipe. Payment signing stays in your project.
const response = await fetch("https://api.x402node.dev/npm/safety", {
method: "GET",
});
console.log(response.status);
console.log(Object.fromEntries(response.headers));
console.log((await response.text()).slice(0, 1000));
// A valid 402 is a quote, not a completed paid call.This sends no payment. Inspect the 402 response before adding a wallet-enabled client.
- Live 402 quote confirmed
GET returned a protocol-valid 402 quote (402). No payment was made.
- Origin reachable
HEAD https://api.x402node.dev/ returned 404.
- Observed in cdp-bazaar
The registry record was observed and retained with provenance.
- Observed in 402-index
Discovered through bazaar.
- Registry record checked
Registry health: healthy.
What evidence supports this listing?
Each record has an exact-route quote outcome. Unresolved templates and potentially mutating methods are labeled instead of being invoked without provider-specific test input. A quote is still separate from a settled paid call. Read the discovery and verification methodology →
Which networks and payment options does it accept?
The normalized listing price is $0.02 USD-denominated per request. Raw protocol requirements remain visible below for implementation and audit use.