gadicc · MCP server
JS API for Yahoo Finance
Not claimed by its maker. Is this yours? Prove it and answer the findings
From the README of yahoo-finance2 4.0.2
Receipt history: every signed receipt for every version of this listing, and what changed between them.
JS API for Yahoo Finance
Static scanned
Paste this into your client's MCP configuration.
{
"mcpServers": {
"yahoo-finance2": {
"command": "npx",
"args": [
"-y",
"-p",
"yahoo-finance2@4.0.2",
"yahoo-finance2"
]
}
}
}Or run it directly.
npx -y -p yahoo-finance2@4.0.2 yahoo-finance2Pinned to 4.0.2, which is the version the findings above were found in. Drop the version to take whatever is newest, and the report on this page stops describing what you installed.
2,698,474 installs last month · build provenance signed · no published advisories · version current · checked 2026-10-04
Built from source, attested
npm publishes a signed statement that this exact package was built from the repository below, at this commit. It is verifiable without taking our word for it.
It renders the current rung (static scanned) and links back here, where what that does and does not establish is one click away. It updates itself as the evidence deepens.
[](https://ooruby.com/market/yahoo-finance2)Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.
Your AI agent, fluent in Australian tax. MCP server with cited answers from 34,500+ ATO documents, the income tax and GST Acts and 4,900+ rulings, plus deduction, depreciation, BAS and audit-risk tool
Model Context Protocol server for Vanta's security compliance platform
Maintenance
MaintainedLast release 9 Aug 2026 (4.0.2), 52 days before this check on 1 Oct 2026.
Read from the npm registry's publish history, read by the nightly publisher check.
Release activity only: it says nothing about quality or safety, and a finished small package can be fine without releases. How it is measured