npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

paymcp-security

v0.1.0

Published

PayMCP — an MCP server that helps AI coding agents add, audit, test, and debug payment integrations (V0.1: Razorpay + Next.js). Step 1: MCP foundation + secure read-only workspace layer.

Readme

PayMCP

PayMCP is a local MCP server that statically audits Razorpay payment integrations in Next.js App Router projects written in TypeScript. It is verification-first: it reads a project within a confined workspace, identifies common payment-integration mistakes, returns redacted evidence, calculates a deterministic engineering score, and produces a Test Mode readiness checklist.

V0.1 scope

Supported: Razorpay, Next.js App Router, TypeScript, static read-only analysis, plus a deliberately constrained Test Mode runtime order check.

Not included: payment processing, storage of credentials, live Test Mode transactions, generated source files, dashboards, hosted credential management, or other providers. A static PASS is not a payment, compliance, or production certification.

Installation

Recommended — npm

Once published to npm:

npx paymcp-security

or:

npm install -g paymcp-security
paymcp-security

Note: These commands require the paymcp-security package to be published on npm.

Development / GitHub

For contributors or pre-publication use:

git clone https://github.com/SKSAMIMGOOD/PayMCP.git
cd PayMCP
npm install
npm run build
node dist/index.js

MCP client configuration

Register PayMCP as a stdio MCP server in your MCP client. Every filesystem tool requires an explicit projectRoot; PayMCP does not default to a broad directory.

Using npx (after npm publication)

{
  "mcpServers": {
    "paymcp": {
      "command": "npx",
      "args": ["-y", "paymcp-security"]
    }
  }
}

Using global install

{
  "mcpServers": {
    "paymcp": {
      "command": "paymcp-security"
    }
  }
}

Using local build

{
  "mcpServers": {
    "paymcp": {
      "command": "node",
      "args": ["/absolute/path/to/PayMCP/dist/index.js"]
    }
  }
}

The exact configuration syntax may vary between MCP clients. Consult your client's documentation for the precise format.

MCP tools

  • list_payment_providers — supported providers and stacks.
  • get_payment_requirements — secure Razorpay + Next.js requirements.
  • audit_payment_integration — static findings, score, evidence, and caveats.
  • test_payment_integration — static architecture/readiness checklist; it does not contact Razorpay or an application.
  • test_payment_transaction — controlled Test Mode runtime validation against an already-running app. It requires an explicit base URL and secure host-environment credentials, never accepts secrets as arguments, never starts project commands, and stops for manual checkout.
  • generate_payment_integration — deterministic, self-audited dry-run file plan; it never writes or overwrites project files.
  • debug_payment — deterministic static explanation of audit findings; it never modifies files or contacts Razorpay.
  • suggest_payment_fix — read-only, evidence-based plan for an AI coding agent to apply manually.

Security model

Project file reads are constrained to the supplied root. Traversal and symlink escapes are rejected; .env files are not read; dependency/build folders and binaries are skipped; individual reads are capped at 1 MB. Evidence is redacted before it is emitted over MCP. Do not put secrets in source code even when using PayMCP.

Development

npm run typecheck
npm test
npm run build

The P0 static rules cover client-visible secrets, hardcoded key literals, client-controlled amounts, missing payment/webhook verification, raw webhook-body misuse, webhook secret configuration, client or pre-verification fulfillment, idempotency, capture confirmation, environment mixing, and refund authorization. Findings include confidence levels because source inspection cannot prove runtime behavior.

For AI coding agents, follow the agent audit workflow. Audit output is structured JSON with deterministic finding order and a supplemental humanReadable report; it is static-only and never modifies the project or calls Razorpay.

The controlled generator is documented in generator.md.

Runtime validation is documented in runtime-testing.md. A static PASS and runtime result remain separate evidence.

License

MIT