mcp-server-esa
npm
v1.1.0
Published by aliyun — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
ESA MCP Server - Modular Alibaba Cloud ESA tools for Edge Routine, Pages, and Site management
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 1 = 99. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Each tool and what it can reach — statically extracted from the published source.
apply_certificateno sensitive capabilitycreate_siteno sensitive capabilitycreate_site_a_or_aaaa_recordno sensitive capabilitycreate_site_cname_recordno sensitive capabilitycreate_site_mx_recordno sensitive capabilitycreate_site_ns_recordno sensitive capabilitycreate_site_txt_recordno sensitive capabilitydelete_certificateno sensitive capabilitydelete_recordno sensitive capabilitydeployment_deleteno sensitive capabilityer_record_createno sensitive capabilityer_record_deleteno sensitive capabilityer_record_listno sensitive capabilityfolder_deployno sensitive capabilityget_certificateno sensitive capabilityget_certificate_quotano sensitive capabilityget_ipv6no sensitive capabilityget_managed_transformno sensitive capabilityget_recordno sensitive capabilityget_site_pauseno sensitive capabilityhtml_deployno sensitive capabilitylist_certificatesno sensitive capabilitylist_recordsno sensitive capabilitylist_sitesno sensitive capabilityroute_createno sensitive capabilityroute_deleteno sensitive capabilityroute_getno sensitive capabilityroute_updateno sensitive capabilityroutine_code_commitno sensitive capabilityroutine_code_deployno sensitive capabilityroutine_createno sensitive capabilityroutine_deleteno sensitive capabilityroutine_getno sensitive capabilityroutine_listno sensitive capabilityroutine_route_listno sensitive capabilityset_certificateno sensitive capabilitysite_active_listno sensitive capabilitysite_matchno sensitive capabilitysite_record_listno sensitive capabilitysite_route_listno sensitive capabilityupdate_ipv6no sensitive capabilityupdate_managed_transformno sensitive capabilityupdate_recordno sensitive capabilityupdate_site_pauseno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.1.0 latest |
A 99/100 | 0 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan mcp-server-esa --online
Independent packages implementing the same tool, scanned with the same engine. Compare all 5 side by side →
[](https://github.com/koki-develop/esa-mcp-server/releases/latest) [](./LICENSE) [ server for [AniList](https://anilist.co) that gets your anime/manga taste - not just API calls.