npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

installed-version-mcp

v0.1.0

Published

MCP server that grounds coding agents on the dependency versions ACTUALLY installed in the current project — read from the lockfile and node_modules — so they stop coding against a blend of every version.

Readme

installed-version-mcp

Ground your coding agent on the versions it actually has, not the blend of every version it was trained on.

An MCP server that tells Claude, Cursor, and any MCP client the exact version of each dependency installed in the current project — read from node_modules and the lockfile, fully offline. Studies put AI-generated deprecated-API usage at 25–38%; the root cause is that the model doesn't know which version is on disk. This fixes that.

Why this exists

Ask an agent to use a library and it writes code against a smear of every version it ever saw — calling methods that were renamed, passing options that were removed. The truth is sitting in your node_modules. This server reads it and pins the agent to the real number before it writes the call. It complements pkg-api-mcp (what the API is) and breaking-changes-mcp (what changed between versions).

Tools

| Tool | What it does | |------|--------------| | installed_version | Exact installed version of one package (from node_modules, else lockfile) + declared range + drift vs npm latest. | | resolve_imports | Pass the packages you're about to import; get each one's installed version in a single grounding call. | | project_versions | Every dependency's installed version from the lockfile — whole tree or direct-only, with a substring filter. |

Core resolution is 100% local. Only the optional latest drift check touches the network.

Quick start

npx installed-version-mcp

Claude Code

# point it at the project you're working in
claude mcp add installed-version -e INSTALLED_VERSION_PROJECT="$(pwd)" -- npx -y installed-version-mcp

Claude Desktop / Cursor / Windsurf / any MCP client

{
  "mcpServers": {
    "installed-version": {
      "command": "npx",
      "args": ["-y", "installed-version-mcp"],
      "env": { "INSTALLED_VERSION_PROJECT": "/abs/path/to/your/project" }
    }
  }
}

Or skip the env var and pass projectDir on each call.

Example prompts

  • "Before you touch the router code, check the installed version of react-router-dom with installed-version."
  • "What version of zod is actually installed here, and is it behind latest?"
  • "Resolve the installed versions of everything I'm importing in this file first."

Config

| Env var | Default | Purpose | |---------|---------|---------| | INSTALLED_VERSION_PROJECT | server cwd | Default project root (folder with package.json). Overridable per call via projectDir. | | NPM_REGISTRY | https://registry.npmjs.org | Registry for the optional latest-version drift check. |

How it works

package name + projectDir
   │
   ├─ node_modules/<pkg>/package.json  ── authoritative installed version
   │      └─ else package-lock.json (v2/v3 packages map, or v1 tree)
   ├─ package.json  ── declared range
   └─ (optional) registry /latest  ── drift

Develop

npm install
npm run build
node dist/index.js

Caveats

  • installed_version works from node_modules alone; project_versions needs an npm package-lock.json. Yarn/pnpm lockfiles aren't parsed yet (PRs welcome) — but node_modules lookups still work under any package manager.
  • Transitive dependencies show source: lockfile and no declared range — that's expected.

License

MIT © Anicodeth