seocrawl-mcp (SEOcrawl/seocrawl-mcp) is an MCP server listed on the M8ven Trust Index. It scores 62 out of 100, grade C. It declares 38 tools. No publisher has claimed this listing.

C
Caution
62/100

seocrawl-mcp

SEO + GEO MCP server: live Google Search Console & GA4 data, keyword and page analysis, AI-visibility tracking across ChatGPT, Claude, Gemini & Perplexity, site audit and SEO task management — all from chat.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

SEOcrawl

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
// tools this server exposes38 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

list_properties

Every Google Search Console property you can access (returns the property ID + URL used by all other tools).

get_gsc_summary

GSC clicks, impressions, CTR and average position over a window, plus a branded vs non-branded breakdown.

compare_date_ranges

Two GSC windows side by side with diff and change_pct.

list_winners_losers

Biggest movers between two periods (keywords or pages), deltas pre-computed.

get_top_keywords

Top keywords by clicks/impressions/CTR/position, period-over-period, branded filter, paginated.

get_keyword_detail

Daily time series for a single query.

list_pages_for_keyword

Pages earning a query's clicks (cannibalization / canonical finding).

get_top_pages

Top pages with period-over-period deltas, paginated.

get_page_detail

Daily time series for a single URL.

list_keywords_for_page

Queries driving a page's clicks (the inverse of list_pages_for_keyword).

list_tasks

All SEO tasks for a property, filterable by status/assignee/taskbox/search.

list_taskboxes

The task board's columns (taskboxes) for a property.

get_task

Full task detail (by UUID, slug or task URL).

create_task

Create a task (title required + optional description, assignee, priority, taskbox).

update_task

Partial update of any task field, or unassign.

add_comment

Append a comment to a task.

get_comments

List comments incl. nested replies.

add_annotation

Dated chart note (+ optional description, category, linked task).

list_annotations

Annotations in a date range, newest first.

get_annotation

Full detail for one annotation.

delete_annotation

Remove your own custom annotation.

page_explorer

Crawled pages matching technical criteria (status code, missing canonical, missing H1, any audit check), sorted by health, with indexability, performance score and error/warning counts.

list_prompts

AI Tracker (Brand Radar) prompts a property tracks, with engines, last run and runs-in-range; filter by engine (ChatGPT, Claude, Gemini, Perplexity).

list_ga4_properties

GA4 properties connected to your projects.

get_ga4_summary

GA4 sessions, users, new users, conversions, engagement rate and sessions/user, each vs the previous period.

compare_ga4_date_ranges

Two GA4 windows side by side with diff and change_pct.

get_ga4_traffic_by_source

GA4 sessions by source/medium or default channel grouping, with share %.

get_ga4_ai_referrers

AI/LLM referral traffic by engine (ChatGPT, Perplexity, Gemini, Claude, Copilot…). Your GEO traffic, measured.

list_tags

A property's keyword and page tags with rule and member counts.

create_tag

Create a keyword/url/both tag (optional hex color).

apply_tag

Manually apply a tag to specific keywords and/or pages.

remove_tag

Unassign a tag from specific keywords and/or pages.

delete_tag

Delete a tag entirely (built-in Brand / Non-Brand tags are protected).

list_tag_rules

Auto-assignment rules that tag keywords/pages automatically.

create_tag_rule

Create an auto-assignment rule (contains, exact, starts/ends_with, regex).

delete_tag_rule

Delete an auto-assignment rule by id.

fetch_url

Fetch a live URL on demand and get final URL, status, redirect chain, timing, parsed SEO elements, clean markdown and raw HTML. Free — never burns MCP credits.

health

Live status of each backend surface (GSC, GA4, Site Audit, AI Tracker, Tasks). Free, no arguments.

// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

38/38 tools missing one or more hints — list_properties (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_gsc_summary (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); compare_date_ranges (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +35 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tests exist

No test files found

Add tests that exercise each declared tool.

Production dependencies are patched

0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.0 (high), @modelcontextprotocol/sdk@1.12.0 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/seocrawl/seocrawl-mcp?variant=verified)](https://m8ven.ai/mcp/seocrawl/seocrawl-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: c492abaa099121728a1eb8f1b36954015ce69d53
code hash: c706cd8e84bc9ea0f6b12479e80914d8248108ce31606be5108e79a09363d446
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client