google-analytics-mcp-server
npm
v1.1.1
Published by nitaiaharoni1 — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
Model Context Protocol server for Google Analytics - query reports, manage properties, configure data filters, and analyze website performance
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 1.2 = 99. What the published surface and source actually contain:
| Points | What was found | Category |
|---|---|---|
| −1.2 | Package runs install-time scripts MTC-SUP-010 | supply-chain |
2. Client adoption risk — 99 − 4 = 95. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −3 | capability blast radius (moderate) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
"google-analytics-mcp-server" executes postinstall script(s) at install time. An install hook runs at install time; most are routine build/setup, but review what it does before trusting it.
Evidence: echo '
🎉 Google Analytics MCP Server installed successfully!
📖 Quick Start with NPX (Recommended):
npx mcp-google-analytics auth
npx mcp-google-analyti
Fix: Review the scripts; install with --ignore-scripts where possible and vet what they do.
Location: package google-analytics-mcp-server
Each tool and what it can reach — statically extracted from the published source.
delete_measurement_protocol_secretreads sensitive dataget_measurement_protocol_secretreads sensitive dataarchive_audienceno sensitive capabilityarchive_custom_dimensionno sensitive capabilityarchive_custom_metricno sensitive capabilityarchive_key_eventno sensitive capabilitybatch_run_reportsno sensitive capabilitycheck_compatibilityno sensitive capabilitycreate_audienceno sensitive capabilitycreate_conversion_eventno sensitive capabilitycreate_custom_dimensionno sensitive capabilitycreate_custom_metricno sensitive capabilitycreate_firebase_linkno sensitive capabilitycreate_key_eventno sensitive capabilitycreate_measurement_protocol_secretno sensitive capabilitycreate_propertyno sensitive capabilitydelete_conversion_eventno sensitive capabilitydelete_firebase_linkno sensitive capabilitydelete_propertyno sensitive capabilityget_accountno sensitive capabilityget_account_summariesno sensitive capabilityget_adsense_linkno sensitive capabilityget_audienceno sensitive capabilityget_bigquery_linkno sensitive capabilityget_conversion_eventno sensitive capabilityget_custom_dimensions_and_metricsno sensitive capabilityget_data_streamno sensitive capabilityget_firebase_linkno sensitive capabilityget_key_eventno sensitive capabilityget_metadatano sensitive capabilityget_property_detailsno sensitive capabilitygoogle-analytics-mcp-serverno sensitive capabilitylist_accountsno sensitive capabilitylist_adsense_linksno sensitive capabilitylist_audiencesno sensitive capabilitylist_bigquery_linksno sensitive capabilitylist_conversion_eventsno sensitive capabilitylist_data_streamsno sensitive capabilitylist_firebase_linksno sensitive capabilitylist_google_ads_linksno sensitive capabilitylist_key_eventsno sensitive capabilitylist_measurement_protocol_secretsno sensitive capabilitylist_propertiesno sensitive capabilityrun_pivot_reportno sensitive capabilityrun_realtime_reportno sensitive capabilityrun_reportno sensitive capabilityupdate_custom_dimensionno sensitive capabilityupdate_custom_metricno sensitive capabilityupdate_key_eventno sensitive capabilityupdate_propertyno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.1.1 latest |
A 95/100 | 1 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan google-analytics-mcp-server --online
Independent packages implementing the same tool, scanned with the same engine. Compare all 6 side by side →
MCP server for Google Analytics Data API and Measurement Protocol - Read reports and send events
MCP server for Google Analytics Data API
Google Analytics MCP Pack
Google Analytics MCP server for accessing web analytics data
Model Context Protocol for Google Analytics 4 (Data API) allowing autonomous agents to query dimensions and metrics. Gives agents analysis-ready GA4 access with schema discovery, server-side aggregation, and smart defaults.
Official Abyssfall game info, newsletter double opt-in, and merch reservation tools.
AdCritter ads platform: docs, API reference, app scaffolding, and white-label integration.
Google AdSense MCP Server - Monitor earnings, reports, and account health via Claude/AI
Operational empathy for technical founders + PE/VC operators navigating high-stakes B2B interactions. 28 MCP tools + CLI: ICP scoring, persona simulation, battlecards, deal classification, prospect discovery, investor matching, founder wellness, plus mark
MCP server for Bing Webmaster Tools — SEO site management, URL submission, sitemaps, stats, keywords
MCP (Model Context Protocol) server that helps AI agents use Primer Brand (@primer/react-brand) correctly when building GitHub marketing and landing pages.