Is UpgradeLens MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
no findings
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 544ms20/20
- Tool poisoning4 tool descriptions checked15/15
- Auth qualityopen endpoint, read-only tools10/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityno repository or website to verify2/10
Overall 67/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what UpgradeLens does
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB
- Dependency Vulnerability Tracker — package security advisories ($0.01/query)Dependency vulns & malicious-package advisories. Register in-session — free testnet funds.not reviewedNewC
- Fedramp Oscal Ssp Lint16 checks on a system-security-plan JSON, in your editor, before a validator returns the packagenot reviewedNewA