@iflow-mcp/webflow-mcp-server
npm
v1.0.0
Published by @iflow-mcp — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.
A Node.js server implementing Model Context Protocol (MCP) for Webflow using the [Webflow JavaScript SDK](https://github.com/webflow/js-webflow-api). Enable AI agents to interact with Webflow APIs. Learn more about Webflow's Data API in the [developer doc
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 2 = 98. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −2 | publisher verification (unlinked) — no provenance/repo link, but the shipped source was fully read |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Each tool and what it can reach — statically extracted from the published source.
add_inline_site_scriptno sensitive capabilityask_webflow_aino sensitive capabilityasset_toolno sensitive capabilitycollection_fields_create_optionno sensitive capabilitycollection_fields_create_referenceno sensitive capabilitycollection_fields_create_staticno sensitive capabilitycollection_fields_updateno sensitive capabilitycollections_createno sensitive capabilitycollections_getno sensitive capabilitycollections_items_create_itemno sensitive capabilitycollections_items_create_item_liveno sensitive capabilitycollections_items_delete_itemno sensitive capabilitycollections_items_list_itemsno sensitive capabilitycollections_items_publish_itemsno sensitive capabilitycollections_items_update_itemsno sensitive capabilitycollections_items_update_items_liveno sensitive capabilitycollections_listno sensitive capabilitycomponents_get_contentno sensitive capabilitycomponents_get_propertiesno sensitive capabilitycomponents_listno sensitive capabilitycomponents_update_contentno sensitive capabilitycomponents_update_propertiesno sensitive capabilityde_component_toolno sensitive capabilityde_learn_more_about_stylesno sensitive capabilityde_page_toolno sensitive capabilitydelete_all_site_scriptsno sensitive capabilityelement_builderno sensitive capabilityelement_toolno sensitive capabilityget_designer_app_connection_infono sensitive capabilityget_image_previewno sensitive capabilitypages_get_contentno sensitive capabilitypages_get_metadatano sensitive capabilitypages_listno sensitive capabilitypages_update_page_settingsno sensitive capabilitypages_update_static_contentno sensitive capabilitysite_applied_scripts_listno sensitive capabilitysite_registered_scripts_listno sensitive capabilitysites_getno sensitive capabilitysites_listno sensitive capabilitysites_publishno sensitive capabilitystyle_toolno sensitive capabilityvariable_toolno sensitive capabilitywebflow_guide_toolno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.0.0 latest |
A 98/100 | 0 | 1.13.0 | 2026-09-06 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @iflow-mcp/webflow-mcp-server --online
Independent packages implementing the same tool, scanned with the same engine. Compare all 4 side by side →
Webflow MCP Pack
A Node.js server implementing Model Context Protocol (MCP) for Webflow using the [Webflow JavaScript SDK](https://github.com/webflow/js-webflow-api). Enable AI agents to interact with Webflow APIs. Learn more about Webflow's Data API in the [developer doc
WebFlow MCP MVP with local flow workspaces and MCP tool exposure
Apify MCP Server
Model Context Protocol (MCP) Server for the *@inkeep/agents-mcp* API.
Medicare spending, chronic conditions, hospital quality, readmissions, and enrollment
Public read-only MCP for products, frameworks, guides, methodology, and blog metadata.
Community-maintained MCP server for Atlassian Confluence Data Center. Not affiliated with Atlassian.
MCP server for Contentful Content Management API integration