npm registry
npm package license, deprecation, and download metadata
This Actor looks up npm packages (or a searchTerm) on the public registry and emits license, deprecation, and optional download rows. It is registry metadata, not an OSV vulnerability matcher.
Not OSV/CVE matching (use OSS Vulnerability Monitor). Not a transitive license-policy tree (use npm Dependency Tree & License Scraper). Not malware scanning.
from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.00005 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
Open npm License & Deprecation Checker on Apify
npm License & Deprecation Checker, not a neighboring Actor
Use this page for this Actor’s job. Use OSS Vulnerability Monitor for OSV/GitHub advisories; Use npm Dependency Tree & License Scraper for npm license trees; Use GitHub Release & Tag Scraper for Release/tag diffs.
| This Actor | OSS Vulnerability Monitor | npm Dependency Tree & License Scraper | GitHub Release & Tag Scraper | |
|---|---|---|---|---|
| Intent | npm License & Deprecation Checker | OSV/GitHub advisories | npm license trees | Release/tag diffs |
| Primary input | see schema | packages | packages + licensePolicy | repositories |
| What it reads | Public sources listed on the Store page | OSV + GitHub Advisories | npm registry tree | GitHub releases |
| Primary output | Dataset rows billed per live PPE | vuln rows | license/dep rows | release rows |
| Not this job | Not OSV/CVE matching (use OSS Vulnerability Monitor). Not a transitive license-policy tree (use npm Dependency Tree & License Scraper). Not malware scanning. | Not license-policy trees | Not OSV CVEs | Not npm/PyPI package metadata |
Store ID: taroyamada/npm-package-intelligence. Respect source terms, robots.txt, and rate limits.
Use cases
- Named-package license/deprecation audits
- searchTerm discovery plus includeDownloads
- Scheduled registry health checks
How is npm License & Deprecation Checker different from OSS Vulnerability Monitor and npm Dependency Tree & License Scraper?
npm License & Deprecation Checker (taroyamada/npm-package-intelligence): This Actor looks up npm packages (or a searchTerm) on the public registry and emits license, deprecation, and optional download rows. It is registry metadata, not an OSV vulnerability matcher. Not OSV/CVE matching (use OSS Vulnerability Monitor). Not a transitive license-policy tree (use npm Dependency Tree & License Scraper). Not malware scanning. OSS Vulnerability Monitor is for OSV/GitHub advisories (input packages; OSV + GitHub Advisories; vuln rows). Not license-policy trees. npm Dependency Tree & License Scraper is for npm license trees (input packages + licensePolicy; npm registry tree; license/dep rows). Not OSV CVEs. GitHub Release & Tag Scraper is for Release/tag diffs (input repositories; GitHub releases; release rows). Not npm/PyPI package metadata.
What input is required?
Live required fields: none listed (see live fields). Published exampleRunInput is shown below. Gather npm package info, downloads, dependencies, maintainers, and release cadence
| Field | Type | Default | Notes |
|---|---|---|---|
packages |
any[] | empty |
Package Names. npm package names to look up (max 100). Scoped packages supported (e.g. @scope/name). |
searchTerm |
string | empty |
Search Term. Optional keyword to search the npm registry (registry.npmjs.org/-/v1/search). Leave blank to skip search. |
searchSize |
integer | 20 |
Search Result Limit. Maximum number of search results to return (1–250). min=1 max=250 |
includeDownloads |
boolean | true |
Include Downloads. Include download statistics (last-day, last-week, last-month) from api.npmjs.org. |
concurrency |
integer | 5 |
Concurrency. Number of parallel package requests. min=1 max=10 |
timeoutMs |
integer | 15000 |
Timeout (ms). Request timeout in milliseconds. min=1000 max=30000 |
delivery |
string enum | dataset |
Delivery. Where to send results: Apify dataset or webhook URL. enum: dataset, webhook |
webhookUrl |
string | empty |
Webhook URL. Webhook URL to POST results to (only used when delivery=webhook). |
dryRun |
boolean | false |
Dry Run. Parse input and fetch data but do not push to dataset or call webhook. |
Published Store example run input (omitted fields take schema defaults):
{
"packages": [
"express",
"react"
],
"includeDownloads": true,
"concurrency": 5,
"delivery": "dataset",
"dryRun": false
}
Run npm License & Deprecation Checker on Apify
How do dataset, webhook, and dry-run delivery work?
delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
What does a result contain?
Published README Output Example / Sample Output JSON. Treat README samples as illustrations, not a live coverage guarantee. There is no published output JSON schema on the Store page.
How is npm License & Deprecation Checker priced?
Billing is pay per event. The live Store card is from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.00005 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE. Current PPE:
| Event | Price | Emitted when |
|---|---|---|
apify-default-dataset-item (result) |
$0.008 | Single result in the default dataset. |
apify-actor-start (Actor Start) |
$0.00005 | Charged when the Actor starts running. Number of events charged depends on Actor memory (one event per GB, minimum one event). |
from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.00005 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
See npm License & Deprecation Checker pricing on Apify
Limits to keep in mind
- packages or searchTerm on the live schema
- Public npm registry
- concurrency / timeoutMs caps
- Not OSV CVEs
- Respect source terms, robots.txt, and rate limits.
Open npm License & Deprecation Checker on Apify
Related pages
- OSS Vulnerability Monitor — OSV/GitHub advisories, not license text.
- npm Dependency Tree & License Scraper — Transitive trees + license policy.
- GitHub Release & Tag Scraper — GitHub releases, not npm registry.
- PyPI & npm Dependency Risk Report — npm+PyPI upgrade alerts.
- Tools