Mmcp.market

Is pkgxray MCP server safe?

Yes, with the usual care.

B74/100grade B

Safe to use. Minor gaps such as a missing repository or slower maintenance.

No critical or high findings in the latest scan.

Public scan report

scanner v0.1.9 · 2026-09-24 · same rubric, same numbers if you re-run it

2 medium
  • Code scan23 source files scanned15/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 0 days ago15/15
  • Maintainer identityregistry namespace matches repository owner6/10

Findings (2)

  • mediumeval / new Function usedexec.eval
    src/auditor.js: …`devtool:'eval'` wraps every module as `eval("<module source>")`, // and `new Functio…
  • mediumNetwork call to a raw IP addressnet.raw-ip
    src/auditor.js: …s not // execute: `// e.g. request.get('https://1.2.3.4/')` (superagent), an Apache // license U…
Overall 74/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Other servers that do what pkgxray does

  • npm Registry MCP Server
    npm registry MCP server — package intelligence, security audits, dependency analysis
    B
  • Npm Sentinel
    Advanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.
    A
  • Prodcheck
    4,372 pre-production checks: security, performance, scale, integrations, post-launch.
    A

pkgxray reviews, tools and install