58
/ 100
10 days ago
glama

remote-mcp-starter

A production-ready remote MCP server with per-user tenant isolation, PAT authentication, and a notes domain, using Stateless Streamable HTTP transport.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical, 11 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
// known CVEs in dependencies1 critical11 high18 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalbetter-auth@1.6.9GHSA-pw9m-5jxm-xr6h

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

high@hono/node-server@1.13.8GHSA-wc8c-qw6v-h7f6

@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware

highbetter-auth@1.6.9GHSA-7w99-5wm4-3g79

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

highbetter-auth@1.6.9GHSA-86j7-9j95-vpqj

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

highbetter-auth@1.6.9GHSA-9h47-pqcx-hjr4

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configDATABASE_URLEnv vars: , BETTER_AUTH_SECRET (openssl rand -base64 32),
configPORTOrigin header of state-changing auth requests against it), and .
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/cdotta-remote-mcp-starter-4z127h)](https://m8ven.ai/mcp/cdotta-remote-mcp-starter-4z127h)
commit: af1c4e8a2063c66f5616df271f59c44d0cf4228d
code hash: 096b5735316e616458b7117b713b9b69134baed0aafc6db827c4e5bef377657c
verified: 7/21/2026, 9:39:28 AM
view raw JSON →