Your dependencies look fine.
Are they?

notavibe checks five maintenance signals — release cadence, response time, contributor breadth, security posture, and adoption — so your AI assistant recommends packages that are actually alive.

8,400+ npm packages · Free, no auth · Works with Claude, Cursor & VS Code

Full platform coming soon

How it works

Five signals, fully sourced, no black box

Every project shows five maintenance signals derived from public data — each with its source, fetch date, and a clear rating. No hidden formula.

Maintenance activity

Substantive releases and merged external PRs over the trailing 90 days. Active, steady, quiet, or dormant.

Responsiveness

Median time to first substantive maintainer response on issues and PRs. Days, weeks, or insufficient data.

Contributor breadth

How many distinct authors are merging code. Broad, narrowing, single-author, or insufficient data.

Security posture

OpenSSF Scorecard-style checks: security policy, CI in place, code review practice. Strong, partial, or none visible.

Get started

Install the MCP server

Give your AI coding assistant grounded, sourced knowledge about open-source project health. Works with Claude, Cursor, Windsurf, VS Code, and any MCP-compatible client.

One command — works with Claude Desktop, Cursor & more
npx @notavibe/mcp

This downloads and runs the notavibe MCP server. Your AI assistant will automatically detect it. No configuration file needed — just run and go.

View on GitHub npm package Free · no API key · rate-limited by IP

Why notavibe

Built for the questions your tooling doesn't answer

Transparent ratings, not opaque scores

Each signal shows its source, fetch date, and a clear rating like "steady" or "days." You see exactly what we see — no hidden formula.

Maintenance, not popularity

Stars and downloads are farmable. Release cadence, response times, and dependent-project counts are not. We measure what matters.

Agent-native from day one

Built as an MCP server so your coding assistant grounds dependency recommendations in sourced data — not training-set popularity bias.

Stay in the loop

The full platform is coming

Dependency discovery, team dashboards, and CI integration are next. Drop your email — we'll let you know when it ships.