Your AI suggests dead packages. We stop that.
npm audit says moment is clean. Its maintainers say don’t use it.
A newer version number isn’t the same as a living package. PatternStack catches the deprecated, abandoned, and replaced dependencies your AI doesn’t know about — and warns it before it writes the code.
See for yourself — check any package, no signup:
Works in 30 seconds. Free for 3 repos.
Works wherever your agent works — one MCP server, every surface
Claude Code
AnthropicCursor
Cursor IncWindsurf
CodeiumClaude Desktop
AnthropicWorks with any MCP-compatible client, agent, or automated workflow. View setup guides →
What you get
A watchman for your dependencies — inside your AI agent and your inbox. No context switching. No dashboard tab-hopping.
Deprecations, the moment you’re exposed
request, tslint, node-sass — your agent will still suggest them. Register a manifest and deprecated dependencies are flagged in the response, with the maintainer’s actual notice and the successor package.
Quiet decay, before it’s a CVE
No release in a year? Ecosystem moved to a fork? We track publish activity and lifecycle state (stable → stagnant → deprecated) for every package you depend on — the changes that never show up as a version bump in a Dependabot PR.
Deltas your agent can act on
One MCP call returns “what changed since you last looked”: worsened, improved, new, removed — with urgency. ~30ms. In our benchmark, a search-enabled agent burned ~34 tool calls to reconstruct the same facts.
A digest humans actually read
Weekly (or daily) email: what worsened in your stack, what needs attention, nothing else. No dashboard babysitting.
The failure isn’t wrong answers. It’s questions that never get asked.
Your agent, today
Answers from a training snapshot; searches only when it knows to ask
- styled-components went maintenance-mode → kept scaffolding it
- request deprecated since 2020 → still suggested in 2026
- Verifying one dependency question ≈ 34 searches, minutes of latency
- No way to learn about a change it didn’t think to search for
With PatternStack watching
State changes pushed into context at codegen time
- Deprecation and abandonment flagged the moment your manifest registers
- Lifecycle deltas on every project sync — unprompted
- One structured call, ~30ms, every MCP-capable tool
- Watching is push, not pull — the part search can’t do
We benchmarked a search-enabled agent against live registry data on 20 post-cutoff questions. It tied or won almost everything — when it knew what to ask. That result killed our original “smarter answers” pitch and built this product instead. Read the full eval →
Not Dependabot/Renovate — no version-bump PRs (they do that well). Not Socket/Snyk — not a security scanner (CVE data is an input, not the product). PatternStack is the layer for changes that have no version number.
Frequently Asked Questions
Common questions about MCP integration, pricing, and privacy.
When it knows to ask, mostly yes — our own benchmark says so (see /evals). But nobody searches for a change they don't know happened. Watching is push, not pull. Also: one structured call vs ~34 searches per question in our benchmark.
Dependabot tells you a new version exists. We tell you the package's life changed: deprecated, unmaintained, superseded, default-swapped — most of which never produce a version bump. You can be fully up to date on request (deprecated since 2020): green checkmarks, bad architecture.
Run `claude mcp add patternstack -- npx -y @patternstack/mcp` in your terminal. That's it — your agent can register your repo, sync your manifest, and pull lifecycle deltas.
Public registries (npm, PyPI, crates.io, RubyGems, Packagist, Go), OSV/CVE feeds, and repo metadata — refreshed continuously. 50,000+ packages tracked today; registering your manifest adds anything we don't already watch.
500 MCP requests per day, access to all MCP tools, CVE blocking, and framework-partitioned recommendations. Most individual developers never hit the limit.
Yes. MCP requests are authenticated, scoped to your account, and rate limited. We only access dependency metadata from your projects — never source code.
Any MCP-compatible agent: Claude Code, Cursor, Windsurf, and others. Install with one command and your agent gets the watch loop: register, sync, deltas, lifecycle state, and dependency health.
Find out what’s rotting in your stack — in one scan
Free for 3 repos. Your first scan flags every deprecated and stagnant dependency you’re shipping today.
Free tier included • Works with any MCP-compatible agent