EverThread MCP server
Plain-English website security check for agents: certificate, headers, scripts, forms, spam.
0 stars
Reviews
Write oneNobody has reviewed EverThread yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
EverThread tools (3, 1 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
check_sitewrite actionRun EverThread's free security check on a website's home page. One fresh check per site per week; within that week you get the stored result with its age, and a `nudge` you should relay to the user: the audit is old, and EverThread can watch the site daily for free. When relaying results, lead with items whose urgency is Fix today or Fix this week; describe Optional hardening items as optional, si
explain_findingExplain one EverThread finding type in plain English: what it means, why it matters, how to fix it, and the developer line. Use list_findings for the type names.
list_findingsEvery finding type EverThread reports, with its urgency and a link to the plain-English page.
Public scan report
scanner v0.1.9 · 2026-09-23 · same rubric, same numbers if you re-run it
- Code scan6 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner7/10
What the publisher says
From the EverThread repository's README, as published. We do not edit it. Read it on GitHub
everthread
A website security check that explains itself in plain English. Free, no key, observation only.
npx everthread check yourbakery.comEverThread · yourbakery.com
WORTH A LOOK Nothing alarming, but one thing is worth fixing.
FIX THIS WEEK Your site lets browsers fall back to an insecure connection
The Strict-Transport-Security header is not being sent. ...
Fix: Send the technical line below to whoever runs your site. ...- One fresh check per site per week. Inside that week you get the stored result, its age, and a note about daily watching.
- --json for machines, --fail-on urgent (or attention) to fail a CI step.
- everthread explain tls.expiring and everthread findings for the explanations behind every finding.
As an MCP server
{ "mcpServers": { "everthread": { "command": "npx", "args": ["-y", "everthread", "mcp"] } } }Tools: checksite, explainfinding, list_findings. Works with Claude Code, Claude Desktop, Cursor, and anything else that speaks MCP.
What it does and doesn't do
It loads the home page the way a browser does and reads the certificate, security headers, scripts, forms, frames, redirects, a fixed handful of well-known files, and the page text. It never logs in, probes for hidden paths, or runs exploit tooling. Public results withhold the exact address of an exposed file; the site owner sees it after signing up. Only check sites you own or have permission to check.
Docs: https://everthread.live/api · Every finding explained: https://everthread.live/fix/
Nothing above is checked by us. What we check is on the safety report.
Install directly
Runs npx -y everthread on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add everthread -- npx -y everthread
EverThread: common questions
- Is EverThread MCP server safe?
- Yes, by our scan: it is graded A (91/100). Read the EverThread safety report
- How do I install EverThread?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does EverThread need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is EverThread maintained?
- The last commit was in the last day (2026-09-23). The latest release is v0.1.3.
- What can I use instead of EverThread?
- Servers from other publishers that do the same job: MCP server, Nel Veil MCP server and ScanLabsAI Security Scanner MCP server. Compare all EverThread alternatives.
Alternatives to EverThread
Same job from other publishers: the closest match first, then the best rated.
- MCPSecurity tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.not reviewedGrowingA
- Nel VeilFree passive security scanning - check any domain's DMARC, TLS, headers, and exposures.not reviewedGrowingA
ScanLabsAI Security ScannerScan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixesnot reviewedNewB- goliveCheck a site before you share it: link previews, SPA refresh 404s, noindex, security headers.not reviewedNewA
- Prodcheck4,372 pre-production checks: security, performance, scale, integrations, post-launch.not reviewedGrowingA