The MCP ecosystem often has several independent packages implementing the same tool — and "Security Scanner" currently has 8. Every one of them was scanned with the same deterministic engine, so the numbers below are directly comparable: the Trust Score (A–F), the capability blast radius, and how much of the package the scan could actually inspect. They are ranked by score; ties break toward unscoped, longer-established packages.
| Implementation | Package | Trust | Capability | Coverage | Findings | Scanned |
|---|---|---|---|---|---|---|
| Security Scannerbest by buildbench | @buildbench/mcp-security-scanner
npm |
A 100/100 | High | Source | 2 | 2026-07-22 |
| Security Scanner by proofxhq | @proofxhq/mcp-security-scanner
npm |
A 100/100 | Moderate | Source | 1 | 2026-07-22 |
| Security Scanner by rupeshpanwar | @rupeshpanwar/security-scanner-mcp
npm |
A 100/100 | Minimal | Source | 0 | 2026-07-22 |
| Security Scanner by supernova123 | @supernova123/security-scanner-mcp-server
npm |
A 100/100 | High | Source | 1 | 2026-07-22 |
| Security Scanner by jonsoku2 | @jonsoku2/mcp-security-scanner
npm |
A 98/100 | High | Source | 4 | 2026-07-22 |
| Security Scanner by badchars | mcp-security-scanner
npm |
B 85/100 | High | Source | 10 | 2026-07-22 |
| Security Scanner by ongjin | security-scanner-mcp
npm |
C 78/100 | High | Source | 10 | 2026-07-22 |
| Security Scanner by PyPI | mcp-security-scanner
PyPI |
C 76/100 | High | Source | 4 | 2026-07-22 |
A higher-ranked implementation is not "the official one" — ranking reflects only what the deterministic scan found in each published package. Open an implementation to read its individual findings with evidence, its scan history per version, and to grab an embeddable badge. Scores are automated opinions, recomputed on every rescan.