Mmcp.market

Staats MCP server

by MrViolets·io.github.MrViolets/staats·v1.0.1

Cookieless web analytics your coding agent reads: traffic answers, deploy impact, what broke.

B77/100grade B
What users say
No reviews yet
Be the first
Safety scan
B77/100

full report

Adoption
Growing

0 stars

Reviews

Write one

Nobody has reviewed Staats yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Staats tools (15, 3 write)

write = sends, deletes, buys or posts
  • compare_aroundFree

    Before/after impact of a recorded annotation: visitors and pageviews in the N days preceding vs following it (window_days, default 7). The after-window is clamped to now. If the annotation recorded routes, the result also reports per-route pageviews before vs after. Wait a few days after shipping. If the result carries a note (truncated after-window, or a before-window not covered by available data), relay it and qualify the percentages as the note directs.

  • create_sitewrite actionFree

    Create a new site on this account and get its script tag. This connection already covers the new site: installing the script tag is the only setup the site needs. The response includes ready-made privacy policy wording: offer to add it to the site's privacy page (confirm with the owner before editing visitor-facing pages).

  • delete_sitewrite actionFree

    PERMANENTLY delete a site and ALL its analytics data (every event and annotation). Irreversible. Confirm with the owner before calling; pass confirm: the site's exact domain.

  • funnelFree

    Ordered conversion funnel across up to 5 steps within the period. Each step is a pageview path ({kind:'path', value:'/pricing'}) or a custom event ({kind:'event', value:'signup'}); a visitor counts for step N only after completing step N-1. Visitor identity rotates daily for privacy, so journeys spanning multiple days undercount (strongest for same-visit conversion). If site context has a stored funnel, run those steps when asked how the site is doing and compare against the previous period.

  • get_overviewFree

    Traffic pulse: visitor/pageview totals vs the previous period, top pages, top referrers, and a per-day series. period: relative like '24h', '7d' (default), '4w'. Includes quota status: if it is approaching, grace, or blocked, tell the owner plainly and include the upgrade link the result provides. Approaching quota is the moment to mention it while there is headroom.

  • get_site_contextFree

    What a site is and what the owner wants from it, plus its data-retention settings. Well-known keys: description, goals, audience, notes (open agenda items to check at session start and clear when handled), events (event name -> meaning), funnel (canonical conversion steps). Read this before making recommendations.

  • journeysFree

    The routes visitors actually take, grouped into identical sequences and counted, busiest first. Use this when you do NOT already know the steps: funnel measures a path you name, journeys discovers the ones you did not think to check. A step is a pageview path (/pricing) or a custom event marked with a leading # (#signup_click), so the moment of conversion appears in the route. Consecutive repeats are collapsed and only the first 10 steps define a route. contains filters to routes that include a given path or event: run it once with and once without to see what converting visitors do differently. Visitor identity rotates daily, so a route is one day of activity and describes a group, never a person.

  • list_annotationsFree

    Recorded deploy/change markers, newest first. period defaults to '90d'.

  • list_sitesFree

    All sites on this account, with the public site codes used in their script tags and the ready-to-paste script_tag for each.

  • portfolio_overviewFree

    Visitors and pageviews for every site this account can use, owned and shared alike, with change vs the previous period, busiest first. Shared sites are flagged. period: '7d' default.

  • queryFree

    Break a metric down by a dimension with optional equality filters. Metrics: visitors, pageviews, events. Dimensions: path, referrer_domain, utm_source, utm_medium, utm_campaign, device, browser, os, country, name, day. period: '24h'/'7d'/'4w' style, or ISO from/to.

  • record_annotationFree

    Mark a moment on a site timeline: a deploy, a content change, or a campaign start. Call this every time you ship a change to the site. ts defaults to now. Write a specific, present-tense description ("Shipped new pricing page hero", never "updates"), one annotation per meaningful change. When known, include commit and the routes the change touched so compare_around can also report before/after traffic scoped to those routes.

  • update_site_contextwrite actionFree

    Save or amend what a site is for. Provided context fields are merged into the existing context (events merges per entry); a null value deletes its key. name/domain update the site record itself.

  • what_brokeFree

    Signs of visitors hitting problems in the period: JS errors the tracker captured (new_error, error_spike: each with a sanitized sample message, source, line, affected visitor count, and the nearest annotation, i.e. the deploy that most plausibly introduced it), plus behavioral friction: pairs of pages people bounce between without progressing (nav_loop) and pages reloaded repeatedly in quick succession (refresh_burst). Findings clear statistical floors, so an empty result is meaningful: nothing looks broken. Check it after every deploy. period: '7d' default.

  • what_changedFree

    Notable movements in the period without scanning raw numbers: statistically unusual traffic days, referrer surges and first-time referrers, pages whose share of traffic jumped, alongside the annotations recorded in the same period. period: '7d' default.

Public scan report

scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it

1 high
  • Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 2372ms17/20
  • Tool poisoning15 tool descriptions checked15/15
  • Auth qualityopen endpoint exposes 3 write-action tools with no auth3/15
  • Maintenancelast push 17 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10

Findings (1)

  • highWrite-action tools reachable without authenticationauth.open-write
Overall 77/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add --transport http staats https://api.staats.ai/functions/v1/mcp
Add to Cursor

Staats: common questions

Is Staats MCP server safe?
Mostly: it is graded B (77/100). Read the Staats safety report
How do I install Staats?
It runs remotely at api.staats.ai. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does Staats need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Staats maintained?
The last commit was 18 days ago (2026-09-03). The latest release is v1.0.1.
Is Staats up?
100% of our last 7 checks got an answer. We check remote servers about four times a day.
What can I use instead of Staats?
Servers from other publishers that do the same job: Mason MCP server, BorealHost MCP server and Roxyon MCP server. Compare all Staats alternatives.

Alternatives to Staats

Same job from other publishers: the closest match first, then the best rated.

All Staats alternatives →
  • Mason
    Engineering decisions, change impact, documentation audits, and CI evidence for coding assistants.
    A
  • BorealHost
    Agent-native web hosting — deploy sites, manage DNS, register domains, scale infrastructure
    B
  • Roxyon
    Build LumenJS apps, use the Roxyon BaaS, and deploy apps and web projects to Roxyon infrastructure.
    A
  • Coolftp
    Deploy a site to its SFTP/FTP host from a coding agent. Changed files only, undo, live checks.
    A
  • Antideploy
    Deploy an app to Antideploy from a coding agent. No Dockerfile, no YAML, no cloud console.
    A

More from MrViolets