sitezen-mcp
npm
v1.20.3
Published by an unidentified publisher — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.
SiteZen MCP server — lets Claude Desktop (or any MCP client) drive a SiteZen-enabled WordPress site directly. The end user's Claude subscription pays for LLM tokens; the conversion rules + license are served from the SiteZen platform.
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 8 = 92. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
| −2 | publisher verification (unlinked) — no provenance/repo link, but the shipped source was fully read |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
In the server's implementation (`dist/converge.js:1`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt{spawn as J}from"node:child_process";import _ from"node:net";import N from"node:crypto";import b from"node:fs";import
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/converge.js
In the server's implementation (`dist/figma.js:1`): A hardcoded outbound call to a fixed external host inside server code is a classic exfiltration/telemetry channel — especially paired with reads of local data. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: {...u}]}}}const c=await fetch(`https://api.figma.com/v1/files/${i}${o==="shallow"?"?depth=3":""}`,{headers:{"X-Figma-Tok
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/figma.js
In the server's implementation (`dist/tools.js:11`): A hardcoded outbound call to a fixed external host inside server code is a classic exfiltration/telemetry channel — especially paired with reads of local data. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: ale=1":"",T=await(await fetch(`https://api.figma.com/v1/images/${u.fileKey}?ids=${x[l].join(",")}&format=${l}${E}`,{head
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/tools.js
Each tool and what it can reach — statically extracted from the published source.
get_page_htmlingests untrusted inputlist_pagesingests untrusted inputpush_section_to_pageingests untrusted inputassemble_sectionno sensitive capabilitycheck_configno sensitive capabilityconnect_siteno sensitive capabilitycreate_filter_datano sensitive capabilitycreate_header_footerno sensitive capabilitycreate_pageno sensitive capabilitycreate_productsno sensitive capabilitycreate_templateno sensitive capabilitydelete_sectionno sensitive capabilitydetect_section_kindno sensitive capabilitydisconnect_siteno sensitive capabilityeditor_v2_capabilitiesno sensitive capabilityelementor_create_menuno sensitive capabilityelementor_create_postsno sensitive capabilityelementor_get_rulesno sensitive capabilityelementor_pushno sensitive capabilityelementor_readno sensitive capabilityelementor_sideload_mediano sensitive capabilityelementor_start_conversionno sensitive capabilityelementor_verifyno sensitive capabilityget_conversion_rulesno sensitive capabilityget_license_statusno sensitive capabilityget_rendered_previewno sensitive capabilityget_site_globalsno sensitive capabilityget_site_widthsno sensitive capabilityget_wc_single_templateno sensitive capabilitylist_connected_sitesno sensitive capabilitylist_section_rendersno sensitive capabilitylist_sectionsno sensitive capabilitylist_templatesno sensitive capabilityprepare_sectionno sensitive capabilityreplace_sectionno sensitive capabilityreport_copy_attemptno sensitive capabilityrestore_sectionno sensitive capabilityset_page_roleno sensitive capabilityset_site_brandingno sensitive capabilityset_wc_single_product_templateno sensitive capabilitystart_conversionno sensitive capabilitystart_fix_loopno sensitive capabilitystart_html_importno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.20.3 latest |
A 92/100 | 3 | 1.13.0 | 2026-09-07 |
v1.20.2 |
A 92/100 | 3 | 1.13.0 | 2026-08-28 |
v1.20.0 |
A 92/100 | 3 | 1.12.1 | 2026-08-16 |
v1.19.0 |
A 92/100 | 3 | 1.12.1 | 2026-08-13 |
v1.17.1 |
A 92/100 | 3 | 1.12.1 | 2026-08-12 |
v1.14.10 |
A 92/100 | 3 | 1.12.1 | 2026-08-10 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan sitezen-mcp --online
Apify MCP Server
Model Context Protocol (MCP) Server for the *@inkeep/agents-mcp* API.
Medicare spending, chronic conditions, hospital quality, readmissions, and enrollment
Public read-only MCP for products, frameworks, guides, methodology, and blog metadata.
Community-maintained MCP server for Atlassian Confluence Data Center. Not affiliated with Atlassian.
MCP server for Contentful Content Management API integration