CommerceHub MCP (spirit122/commercehub-mcp) is an MCP server listed on the M8ven Trust Index. It scores 50 out of 100, grade D. It declares 41 tools. No publisher has claimed this listing.

D
Caution
50/100

CommerceHub MCP

Enables AI agents to manage e-commerce operations across multiple platforms (Shopify, WooCommerce, Stripe, MercadoLibre) through a conversational interface.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

spirit122

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Known vulnerabilities in dependencies: 2 critical, 7 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 1 credential: COMMERCEHUB_LICENSE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes41 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

setup_help

Muestra instrucciones de configuración de CommerceHub

license_status

Muestra el plan actual, herramientas disponibles y estado de la licencia

license_activate

Activa una license key de CommerceHub Pro o Business

license_plans

Muestra los planes disponibles y sus precios

analytics_avg_order

Analiza el valor promedio de orden (AOV) con tendencia, comparación y distribución

analytics_conversion

Obtiene el embudo de conversión con tasas en cada etapa del proceso de compra

analytics_dashboard

Genera resumen ejecutivo completo con revenue, órdenes, top productos, stock, clientes y conversión

analytics_refunds

Analiza reembolsos con tasa, top razones y productos más reembolsados

analytics_revenue

Genera reporte de ingresos con comparación de período anterior y desglose diario

analytics_by_channel

Compara ventas entre plataformas con revenue, órdenes y ticket promedio por canal

analytics_forecast

Genera pronóstico de ventas con media móvil ponderada, tendencia y rango de confianza

analytics_top_products

Obtiene el ranking de productos más vendidos con revenue y porcentaje del total

customers_lifetime_value

Calcula el valor de vida del cliente (CLV) con predicciones y riesgo de churn

customers_orders

Obtiene el historial de compras de un cliente con totales y detalles

customers_segments

Analiza la segmentación de clientes con conteo, revenue y criterios RFM

customers_get

Obtiene el perfil completo de un cliente con estadísticas, direcciones y segmento

customers_list

Lista clientes con filtros por segmento, gasto mínimo, órdenes y paginación

customers_search

Busca clientes por nombre, email o teléfono

inventory_bulk

Actualiza inventario de múltiples productos en lote con resumen de resultados

inventory_get

Consulta el inventario actual de productos con stock, reservado y disponible

inventory_forecast

Genera pronóstico de inventario con velocidad de venta, fecha de agotamiento y sugerencia de reorden

inventory_history

Consulta el historial cronológico de movimientos de inventario de un producto

inventory_low_stock

Genera reporte de productos con stock bajo, días para agotarse y sugerencia de reorden

inventory_update

Actualiza el inventario de un producto con motivo de ajuste y trazabilidad

orders_cancel

Cancela una orden existente con motivo opcional y reposición de inventario

orders_create

Crea una nueva orden con email del cliente, productos y dirección de envío

orders_fulfill

Registra el cumplimiento (envío) de una orden con información de tracking

orders_get

Obtiene el detalle completo de una orden: líneas de pedido, direcciones, pagos y timeline

orders_list

Lista órdenes de una plataforma de e-commerce con filtros avanzados y paginación

orders_add_note

Agrega una nota a una orden. Puede ser interna o enviada al cliente

orders_timeline

Obtiene la línea de tiempo completa de eventos de una orden, ordenada cronológicamente

orders_refund

Procesa un reembolso total o parcial de una orden

products_bulk_price

Actualización masiva de precios. Permite fijar precios individuales o aplicar un porcentaje de ajuste

products_create

Crea un nuevo producto en la plataforma de e-commerce

products_delete

Elimina o archiva un producto. Por defecto solo lo archiva para mayor seguridad

products_seo_audit

Audita el SEO de un producto: analiza título, descripción, imágenes y tags con puntuación y recomendaciones

products_get

Obtiene el detalle completo de un producto por su ID

products_list

Lista productos de una plataforma de e-commerce con filtros y paginación

products_search

Busca productos por texto libre con filtros opcionales de precio y estado

products_sync

Sincroniza productos entre dos plataformas de e-commerce. Soporta modo simulación (dry_run)

products_update

Actualiza un producto existente. Solo se modifican los campos proporcionados

// known CVEs in dependencies2 critical7 high9 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@2.1.0GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

criticalvitest@2.1.0GHSA-9crc-q9x8-hgqq

Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening

high@modelcontextprotocol/sdk@1.12.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretCOMMERCEHUB_LICENSE_KEY
configLOG_LEVEL
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

41/41 tools missing one or more hints — setup_help (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); license_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); license_activate (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +38 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

38/41 tool handlers declare input schemas (93%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

37/41 tool handlers wrap calls in try/catch (90%)

Wrap each tool handler body in try/catch and return a structured error response.

Tool test coverage

Only 0/41 tools referenced in tests (0%)

Write tests that reference each tool by name so every tool has at least one test.

Production dependencies are patched

0 critical, 7 high severity in production deps — @modelcontextprotocol/sdk@1.12.0 (high), @modelcontextprotocol/sdk@1.12.0 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Dev dependencies

2 critical/high in dev-only deps (does not ship to users)

Upgrade dev dependencies when convenient.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/spirit122/commercehub-mcp?variant=verified)](https://m8ven.ai/mcp/spirit122/commercehub-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 4667c509a1f7f9059d5b903b562a941fccdcfb6e
code hash: 6db0a6fa7c033c713e6def900ca19954b0471b8d7442377ea132531366f3519a
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client