whatsapp-mcp-server (rukman7/whatsapp-mcp-server) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 13 tools. No publisher has claimed this listing.
Enables LLMs to interact with WhatsApp via the official WhatsApp Cloud API, providing tools for sending messages, templates, media, and managing conversations.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
rukman7
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
whatsapp_get_business_profileRetrieve the WhatsApp Business Profile for the configured phone number. Returns: Business profile fields: about, address, description, email, websites, vertical, and profile picture URL.
whatsapp_update_business_profileUpdate the WhatsApp Business Profile fields. Args: - about (string, optional): About text (max 139 chars) - address (string, optional): Business address - description (string, optional): Description (max 512 chars) - email (string, optional): Contact email - websites (string, optional): J…
whatsapp_list_templatesList message templates for the WhatsApp Business Account. Requires WHATSAPP_BUSINESS_ACCOUNT_ID env var. Args: - limit (number): Max results (default: 20, max: 100) - status (string, optional): Filter by APPROVED, PENDING, or REJECTED Returns: List of templates with name, status, category, l…
whatsapp_send_textSend a text message to a WhatsApp user. Args: - to (string): Recipient phone number in international format - body (string): Message text (max 4096 chars) - preview_url (boolean): Show URL preview (default: false) Returns: Message ID and delivery status. Examples: - "Send hello to +3538…
whatsapp_send_templateSend an approved template message. Templates are the only way to initiate conversations outside the 24-hour window. Args: - to (string): Recipient phone number - template_name (string): Approved template name - language_code (string): Template language (default: "en_US") - components (strin…
whatsapp_send_imageSend an image to a WhatsApp user via a public URL. Args: - to (string): Recipient phone number - image_url (string): Public URL of the image - caption (string, optional): Image caption (max 1024 chars) Returns: Message ID and delivery status.
whatsapp_send_documentSend a document (PDF, DOCX, etc.) to a WhatsApp user via a public URL. Args: - to (string): Recipient phone number - document_url (string): Public URL of the document - filename (string, optional): Display filename - caption (string, optional): Document caption Returns: Message ID and de…
whatsapp_send_locationSend a location pin to a WhatsApp user. Args: - to (string): Recipient phone number - latitude (number): Latitude (-90 to 90) - longitude (number): Longitude (-180 to 180) - name (string, optional): Location name - address (string, optional): Location address Returns: Message ID and de…
whatsapp_send_contactSend a contact card to a WhatsApp user. Args: - to (string): Recipient phone number - first_name (string): Contact first name - last_name (string, optional): Contact last name - phone (string): Contact phone number - email (string, optional): Contact email Returns: Message ID and deliv…
whatsapp_send_reactionSend a reaction emoji to an existing message. Args: - to (string): Phone number of the conversation - message_id (string): wamid of the message to react to - emoji (string): Emoji character (e.g. '👍') Returns: Confirmation of reaction sent.
whatsapp_send_buttonsSend a message with up to 3 reply buttons. Args: - to (string): Recipient phone number - body_text (string): Main message body - buttons (string): JSON array of buttons: [{"id":"btn1","title":"Yes"},{"id":"btn2","title":"No"}] - header_text (string, optional): Header text - footer_text (s…
whatsapp_send_listSend a message with a menu list of options. Args: - to (string): Recipient phone number - body_text (string): Main message body - button_text (string): Text on the list menu button - sections (string): JSON array of sections with rows - header_text (string, optional): Header text - foot…
whatsapp_mark_as_readMark a received WhatsApp message as read (shows blue checkmarks). Args: - message_id (string): The wamid of the message to mark as read Returns: Confirmation.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
TRANSPORTexport ="stdio" # "stdio" (default) or "http"WHATSAPP_ACCESS_TOKENexport ="your_access_token"WHATSAPP_API_VERSIONexport ="v23.0" # Default: v23.0WHATSAPP_BUSINESS_ACCOUNT_IDexport ="your_waba_id" # Required for template operationsWHATSAPP_PHONE_NUMBER_IDexport ="your_phone_number_id"PORTTool inputs are validated
Only 0/13 tool handlers declare input schemas (0%)
Declare an inputSchema with zod/joi/yup on every tool definition.
Tool handlers catch errors
Only 4/13 tool handlers wrap calls in try/catch (31%)
Wrap each tool handler body in try/catch and return a structured error response.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.1 (high), @modelcontextprotocol/sdk@1.12.1 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/rukman7/whatsapp-mcp-server)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check