express
npm package · declared by 106 of 2,343 sampled repositories · graph computed 2026-08-24
Counted from the runtime dependencies public repositories declare — not the resolved tree. A transitive dependency is a consequence; a declared one is a choice. Development dependencies are excluded because they repeat across every project in a language regardless of what is being built.
Declared with
ranked by association, not by count| Declared with | Repositories | vs chance |
|---|---|---|
| cors | 29 of 2,343 | 0.76 |
| express-rate-limit | 9 of 2,343 | 0.62 |
| compression | 10 of 2,343 | 0.61 |
| multer | 8 of 2,343 | 0.59 |
| helmet | 8 of 2,343 | 0.57 |
| dotenv | 33 of 2,343 | 0.55 |
| jsonwebtoken | 10 of 2,343 | 0.47 |
| ws | 18 of 2,343 | 0.43 |
| axios | 20 of 2,343 | 0.40 |
| @modelcontextprotocol/sdk | 20 of 2,343 | 0.36 |
| uuid | 12 of 2,343 | 0.35 |
| sharp | 10 of 2,343 | 0.34 |
| better-sqlite3 | 10 of 2,343 | 0.34 |
| js-yaml | 9 of 2,343 | 0.33 |
| zod | 29 of 2,343 | 0.32 |
| commander | 12 of 2,343 | 0.29 |
| react | 15 of 2,343 | 0.05 |
| react-dom | 14 of 2,343 | 0.05 |
Every pair above is counted from the same evidence: repo manifest.
Used instead
candidates · shares a neighbourhood and refuses to co-occurNo alternative measured. A pair qualifies only if it shares a neighbourhood and then fails to appear together against an expectation that it would — and almost everything that shares a neighbourhood does appear together. That is the test working, not a gap in the data: similarity alone would list this tool’s closest neighbours as alternatives, and most of them are things it is used with.