
Security News
CVE Volume Surges Past 48,000 in 2025 as WordPress Plugin Ecosystem Drives Growth
CVE disclosures hit a record 48,185 in 2025, driven largely by vulnerabilities in third-party WordPress plugins.
The official e18e MCP server for advising agents on modern and performant best practices
@e18e/mcp (STDIO)MCP server that flags inefficient or outdated npm packages and serves migration docs. It exposes tools for checking install commands or source files, a resource template with curated replacement guides, and a helper prompt for task-oriented workflows.
npm-i-checker: Input an install command (npm i, pnpm add, yarn add, bun i). Returns suggestions[] for packages that have better-native or better-maintained alternatives.code-checker: Input a full source file (JS/TS/JSX/TSX). Parses imports and returns suggestions[] when a listed module should be replaced.replacement-docs (template): URI e18e://docs/{slug}. Lists/reads text guides for migrating away from specific packages (auto-complete on slug; list returns all available docs).task: Returns a task-focused system prompt that reminds the model to run npm-i-checker for installs and code-checker on code before replying.Prereqs: Node.js ≥18 and npm/pnpm (build uses pnpm, runtime works via npx/pnpm dlx/bunx).
The local (or stdio) version of the MCP server is available via the @e18e/mcp npm package. You can either install it globally and then reference it in your configuration or run it with npx:
npx -y @e18e/mcp
Here's how to set it up in some common MCP clients:
To include the local MCP version in Claude Code, simply run the following command:
claude mcp add -t stdio -s [scope] e18e -- npx -y @e18e/mcp
The [scope] must be user, project or local.
In the Settings > Developer section, click on Edit Config. It will open the folder with a claude_desktop_config.json file in it. Edit the file to include the following configuration:
{
"mcpServers": {
"e18e": {
"command": "npx",
"args": ["-y", "@e18e/mcp"]
}
}
}
Add the following to your config.toml (which defaults to ~/.codex/config.toml, but refer to the configuration documentation for more advanced setups):
[mcp_servers.e18e]
command = "npx"
args = ["-y", "@e18e/mcp"]
To include the local MCP version in Gemini CLI, simply run the following command:
gemini mcp add -t stdio -s [scope] e18e npx -y @e18e/mcp
The [scope] must be user, project or local.
Run the command:
opencode mcp add
and follow the instructions, selecting 'Local' under the 'Select MCP server type' prompt:
opencode mcp add
┌ Add MCP server
│
◇ Enter MCP server name
│ e18e
│
◇ Select MCP server type
│ Local
│
◆ Enter command to run
│ npx -y @e18e/mcp
npx -y @e18e/mcp in the input and press Entere18eGlobal or Workspace MCP serverIt will open a file with your MCP servers where you can add the following configuration:
{
"mcpServers": {
"e18e": {
"command": "npx",
"args": ["-y", "@e18e/mcp"]
}
}
}
Model Context Protocol (MCP) ServersIt will open a popup with MCP server config where you can add the following configuration:
{
"e18e": {
"command": "npx",
"args": ["-y", "@e18e/mcp"]
}
}
If we didn't include the MCP client you are using, refer to their documentation for stdio servers and use npx as the command and -y @e18e/mcp as the arguments.
FAQs
The official e18e MCP server for advising agents on modern and performant best practices
We found that @e18e/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
CVE disclosures hit a record 48,185 in 2025, driven largely by vulnerabilities in third-party WordPress plugins.

Security News
Socket CEO Feross Aboukhadijeh joins Insecure Agents to discuss CVE remediation and why supply chain attacks require a different security approach.

Security News
Tailwind Labs laid off 75% of its engineering team after revenue dropped 80%, as LLMs redirect traffic away from documentation where developers discover paid products.