UpgradeLens MCP server
npm/PyPI/Django dependency upgrades: security, runtime compatibility, migration, package ranking.
Little public usage data yet
Reviews
Write oneNobody has reviewed UpgradeLens yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
UpgradeLens tools (4)
write = sends, deletes, buys or postscheck_dependency_upgradeFreeUse when a coding agent needs a cited go/no-go risk decision without steps before changing an existing npm or PyPI dependency between two exact versions. Returns action_allowed, vulnerability delta, compatibility, EOL, and breaking-change evidence. Use plan_dependency_upgrade instead for ordered migration work. Do not use to choose a target, install a new package, search general docs, or analyze another ecosystem. Read-only and safe to retry.
find_safe_upgrade_targetFreeUse only when an existing npm or PyPI dependency has an exact current version but no chosen target. Ranks candidates; candidates are not declared safe and require check_dependency_upgrade or plan_dependency_upgrade. Do not use when a target is stated, for a new install, or as authorization to edit files. Read-only and safe to retry.
plan_dependency_upgradeFreeUse when a coding agent needs a migration checklist, refactor actions, ordered review actions, changelog links, or test steps for exact current and target npm/PyPI versions. Use check_dependency_upgrade instead for a go/no-go without steps. Do not use to choose a target, install a package, or provide a general tutorial. Read-only and safe to retry.
review_dependency_upgradeFreeUse when an agent reviews a Dependabot, Renovate, npm, or PyPI version change before merge. One cited result combines security delta, runtime compatibility, breaking changes, go/no-go risk, and ordered migration actions for exact current and target versions. Do not use for new installs, unknown versions, general documentation, or other ecosystems. Read-only and safe to retry.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 544ms20/20
- Tool poisoning4 tool descriptions checked15/15
- Auth qualityopen endpoint, read-only tools10/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityno repository or website to verify2/10
Install directly
claude mcp add --transport http upgradelens https://upgradelens.mattpicone.workers.dev/mcp
UpgradeLens: common questions
- Is UpgradeLens MCP server safe?
- With care: it is graded C, so read the findings first (67/100). Read the UpgradeLens safety report
- How do I install UpgradeLens?
- It runs remotely at upgradelens.mattpicone.workers.dev. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does UpgradeLens need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is UpgradeLens maintained?
- The latest release is v0.4.4.
- Is UpgradeLens up?
- 100% of our last 1 checks got an answer. We check remote servers about four times a day.
- What can I use instead of UpgradeLens?
- Servers from other publishers that do the same job: npm Registry MCP Server, Dependency Vulnerability Tracker — package security advisories ($0.01/query) MCP server and Fedramp Oscal Ssp Lint MCP server. Compare all UpgradeLens alternatives.
Alternatives to UpgradeLens
Same job from other publishers: the closest match first, then the best rated.
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB
- Dependency Vulnerability Tracker — package security advisories ($0.01/query)Dependency vulns & malicious-package advisories. Register in-session — free testnet funds.not reviewedNewC
- Fedramp Oscal Ssp Lint16 checks on a system-security-plan JSON, in your editor, before a validator returns the packagenot reviewedNewA
- RuntimeSelf-hosted MCP server: 26 deterministic dev, security, and EVM tools.not reviewedNewC
- Reversecore MCPSecurity-first MCP server for reverse engineering, malware analysis, forensics, and SAST.not reviewedEstablishedB