Back to Browse

Everthread Cli MCP Server

Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Plain-English website security check for agents: certificate, headers, scripts, forms, spam.

About

Plain-English website security check for agents: certificate, headers, scripts, forms, spam.

Security Report

5.2
Moderate5.2Moderate Risk

EverThread is a well-structured MCP server for website security checks with appropriate authentication and permissions scoping. The code is clean and makes only legitimate API calls to the EverThread service. Minor code quality issues around input validation and error handling do not materially impact security posture. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

6 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-pb-digital-llc-everthread": {
      "args": [
        "-y",
        "everthread"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

everthread

A website security check that explains itself in plain English. Free, no key, observation only.

npx everthread check yourbakery.com
EverThread · yourbakery.com
WORTH A LOOK  Nothing alarming, but one thing is worth fixing.

FIX THIS WEEK  Your site lets browsers fall back to an insecure connection
  The Strict-Transport-Security header is not being sent. ...
  Fix: Send the technical line below to whoever runs your site. ...
  • One fresh check per site per week. Inside that week you get the stored result, its age, and a note about daily watching.
  • --json for machines, --fail-on urgent (or attention) to fail a CI step.
  • everthread explain tls.expiring and everthread findings for the explanations behind every finding.

As an MCP server

{ "mcpServers": { "everthread": { "command": "npx", "args": ["-y", "everthread", "mcp"] } } }

Tools: check_site, explain_finding, list_findings. Works with Claude Code, Claude Desktop, Cursor, and anything else that speaks MCP.

What it does and doesn't do

It loads the home page the way a browser does and reads the certificate, security headers, scripts, forms, frames, redirects, a fixed handful of well-known files, and the page text. It never logs in, probes for hidden paths, or runs exploit tooling. Public results withhold the exact address of an exposed file; the site owner sees it after signing up. Only check sites you own or have permission to check.

Docs: https://everthread.live/api · Every finding explained: https://everthread.live/fix/

MCP Badge

Reviews

No reviews yet

Be the first to review this server!