@mikusnuz/umami-mcp
npm
v1.2.1
Published by @mikusnuz — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
Full-coverage MCP server for Umami Analytics API v2
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 4 = 96. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −3 | capability blast radius (moderate) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Each tool and what it can reach — statically extracted from the published source.
get_pageviewsingests untrusted inputadd_team_userno sensitive capabilityadd_team_websiteno sensitive capabilitybatch_eventsno sensitive capabilitycreate_reportno sensitive capabilitycreate_teamno sensitive capabilitycreate_userno sensitive capabilitycreate_websiteno sensitive capabilitydelete_reportno sensitive capabilitydelete_teamno sensitive capabilitydelete_userno sensitive capabilitydelete_websiteno sensitive capabilityget_active_visitorsno sensitive capabilityget_daterangeno sensitive capabilityget_event_data_eventsno sensitive capabilityget_event_data_fieldsno sensitive capabilityget_event_data_statsno sensitive capabilityget_event_data_valuesno sensitive capabilityget_event_seriesno sensitive capabilityget_event_valuesno sensitive capabilityget_eventsno sensitive capabilityget_meno sensitive capabilityget_metricsno sensitive capabilityget_my_teamsno sensitive capabilityget_my_websitesno sensitive capabilityget_realtimeno sensitive capabilityget_reportno sensitive capabilityget_sessionno sensitive capabilityget_session_activityno sensitive capabilityget_session_data_propertiesno sensitive capabilityget_session_data_valuesno sensitive capabilityget_session_propertiesno sensitive capabilityget_session_statsno sensitive capabilityget_sessionsno sensitive capabilityget_sessions_weeklyno sensitive capabilityget_shareno sensitive capabilityget_statsno sensitive capabilityget_teamno sensitive capabilityget_team_userno sensitive capabilityget_userno sensitive capabilityget_user_teamsno sensitive capabilityget_user_usageno sensitive capabilityget_user_websitesno sensitive capabilityget_websiteno sensitive capabilityget_website_reportsno sensitive capabilityheartbeatno sensitive capabilityjoin_teamno sensitive capabilitylist_reportsno sensitive capabilitylist_team_usersno sensitive capabilitylist_team_websitesno sensitive capabilitylist_teamsno sensitive capabilitylist_usersno sensitive capabilitylist_websitesno sensitive capabilityremove_team_userno sensitive capabilityremove_team_websiteno sensitive capabilityreset_websiteno sensitive capabilityrun_reportno sensitive capabilitysend_eventno sensitive capabilitytransfer_websiteno sensitive capabilityupdate_my_passwordno sensitive capabilityupdate_reportno sensitive capabilityupdate_teamno sensitive capabilityupdate_team_userno sensitive capabilityupdate_userno sensitive capabilityupdate_websiteno sensitive capabilityverify_authno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.2.1 latest |
A 96/100 | 0 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @mikusnuz/umami-mcp --online
Independent packages implementing the same tool, scanned with the same engine. Compare all 5 side by side →
A minimal, read-only Model Context Protocol server for Umami analytics (Cloud or self-hosted).
MCP server for Umami Analytics — 61 tools, 4 prompts, 3 resources. Cloud and self-hosted.
MCP server exposing Umami analytics (Cloud + self-hosted) via typed read-only tools
MCP server exposing Umami analytics (Cloud + self-hosted)
Adapters for the FrontMCP framework
Transcend MCP Server — Admin tools.
Transcend MCP Server — Assessments tools.
MCP Server for Bling
MCP Server for Blogger API
Official MCP server for Brilliant Directories — manage members, posts, leads, reviews, and more.