seo-geo-mcp-server
npm
v1.2.0
Published by ortamarco — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
MCP server for SEO and GEO (Generative Engine Optimization) audits — on-page SEO, structured data, robots.txt, sitemaps, hreflang, and AI-crawler access for ChatGPT, Claude, Perplexity and Gemini. No API keys required.
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 4 = 96. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −3 | capability blast radius (moderate) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Tool "redirect_trace" takes a URL/host parameter "url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool redirect_trace · inputSchema.properties.url
Each tool and what it can reach — statically extracted from the published source.
ai_crawler_accessingests untrusted inputcanonical_host_checkingests untrusted inputredirect_traceingests untrusted inputrobots_txt_checkingests untrusted inputseo_auditingests untrusted inputsitemap_checkingests untrusted inputcontent_analysisno sensitive capabilitygeo_auditno sensitive capabilityheading_structureno sensitive capabilityhreflang_checkno sensitive capabilityimage_seo_checkno sensitive capabilitylink_auditno sensitive capabilityllms_txt_checkno sensitive capabilitymeta_tags_checkno sensitive capabilityrender_checkno sensitive capabilitysocial_preview_checkno sensitive capabilitystructured_data_checkno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.2.0 latest |
A 96/100 | 1 | 1.14.0 | 2026-09-24 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan seo-geo-mcp-server --online
Hotel booking MCP server — 300K+ properties, real confirmation numbers, loyalty programs. Builders monetize every booking via Stripe Connect. The first MCP server that completes real hotel reservations inside AI conversations.
Generates production-ready UI components from natural language, inspired by v0.
Model Context Protocol server that serves the A11y Context accessibility-pattern corpus (WCAG 2.2 AA patterns, Foundations rules) to AI coding agents.
Manage AdGuard Home through AI assistants
Read-only Azure DevOps for MCP clients using only your existing browser session — no PAT, no Azure CLI. Browse work items, pull requests, comments, attachments and Artifacts feeds across every project, repo and feed you can access.
MCP server for Adobe Experience Manager Assets integration development