{"name":"xyz.utilityhouse.updates/wp-update-radar","slug":"updates-wp-update-radar","title":"WP Update Radar","description":"WordPress plugin release signals from public support threads, with evidence and explicit unknowns.","url":"https://mcp.market/server/updates-wp-update-radar","rating":null,"grade":"C","score":60,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":8,"stars":null,"forks":null,"downloads_week":null,"last_push_at":null,"license":null},"uptime":{"percent":100,"checks":3,"ok":3,"last_checked_at":"2026-09-20T07:41:02.079Z","last_ok_at":"2026-09-20T07:41:02.079Z","latency_ms":84},"claimed":false,"transport":"remote","callable_via_gateway":true,"default_price_micros":0,"repository":null,"website":"https://updates.utilityhouse.xyz","version":"1.0.1","remotes":[{"type":"streamable-http","url":"https://updates.utilityhouse.xyz/mcp/registry"}],"packages":[],"tools":[{"name":"wp_update_radar_check","description":"Reports what wordpress.org's public support forum says about one plugin release, compared with the releases before it, counted the same way on both sides. It does not answer whether an update is safe: nothing here can see your site, your theme, your premium plugins or your PHP version.\n`state` is what the evidence supports doing, `signal` is only what was observed:\n  HOLD                 elevated public signal for this release\n  WAIT                 above this plugin's own normal, or the window is still open\n  GUARDED_ROLLOUT      no elevated public signal — roll out somewhere low-stakes first\n  NOT_ENOUGH_EVIDENCE  too little was attributable to judge; a gap here, NOT a finding about the release, and not a reason to reassure anyone\nThe legacy `verdict` field keeps its five strings (known-bad / wait / update-now / too-new / insufficient-data) for clients that already read it.\nUse it before applying a plugin update, or when someone asks whether a specific version broke anything. Not a security advisory and not a CVE lookup: it reports what other site owners are saying, which is a different question from whether a release is vulnerable. wordpress.org plugins only — premium and paid plugins have no public forum to read, and themes are out of scope. Covers the most-installed plugins; one outside that set returns an error rather than a guess.","write_action":true,"price_micros":0,"input_schema":{"type":"object","properties":{"plugin":{"type":"string","description":"wordpress.org plugin slug, e.g. \"woocommerce\""},"version":{"type":"string","description":"Exact release to check, e.g. \"8.5.1\""}},"required":["plugin","version"],"additionalProperties":false}},{"name":"wp_update_radar_check_many","description":"Answers: which of this site's plugin updates are risky right now? Prefer this over the single check whenever there is more than one plugin to look at — a whole site's plugin list costs one call here instead of one call each. Same five verdicts as the single check (known-bad, wait, update-now, too-new, insufficient-data), per item and independent: a plugin that is not indexed reports its own error and the rest still answer. Returns a count of each verdict, so the risky ones can be found without reading every row. Up to 25 plugins per call; more than that is reported, not silently cut. `insufficient-data` means this service does not know, which is not the same as safe. Not a security advisory and not a CVE lookup: it reports what other site owners are saying, which is a different question from whether a release is vulnerable. wordpress.org plugins only — premium plugins have no public forum to read, and themes are out of scope.","write_action":true,"price_micros":0,"input_schema":{"type":"object","properties":{"plugins":{"type":"array","minItems":1,"maxItems":25,"description":"The plugins and the exact versions in use","items":{"type":"object","properties":{"plugin":{"type":"string","description":"wordpress.org plugin slug, e.g. \"woocommerce\""},"version":{"type":"string","description":"Exact release in use, e.g. \"8.5.1\""}},"required":["plugin","version"],"additionalProperties":false}}},"required":["plugins"],"additionalProperties":false}}],"scan":{"score":60,"grade":"C","scanned_at":"2026-09-20T00:23:39.145Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-20T00:23:39.120Z","components":{"code":{"score":-1,"max":25,"notes":["remote-only server, no package to scan"]},"reliability":{"score":20,"max":20,"notes":["remote reachable in 471ms"]},"poisoning":{"score":15,"max":15,"notes":["2 tool descriptions checked"]},"auth":{"score":3,"max":15,"notes":["open endpoint exposes 2 write-action tools with no auth"]},"maintenance":{"score":3,"max":15,"notes":["no repository listed"]},"identity":{"score":4,"max":10,"notes":["verified namespace with website, no repo"]}},"findings":[{"id":"auth.open-write","severity":"high","component":"auth","title":"Write-action tools reachable without authentication"},{"id":"maint.no-repo","severity":"low","component":"maintenance","title":"No source repository listed"}],"inputs":{"probes":[{"url":"https://updates.utilityhouse.xyz/mcp/registry","reachable":true,"authRequired":false,"latencyMs":471,"serverInfo":{"name":"wp-update-radar","version":"1.0.1"}}],"packages":[],"repo":{"found":false},"icon":{"url":"https://updates.utilityhouse.xyz/favicon.svg","source":"site"},"presence":{"stars":null,"forks":null,"downloadsWeek":null,"license":null,"lastPushAt":null,"score":8}}}},"grade_history":[],"reviews":[]}