VirtualSMS MCP Server (virtualsms-io/mcp-server) is an MCP server listed on the M8ven Trust Index. It scores 62 out of 100, grade C. It declares 44 tools. No publisher has claimed this listing.

C
Caution
62/100

VirtualSMS MCP Server

MCP server for SMS verification — get virtual phone numbers, receive OTP codes, and manage verifications for 500+ services across 50+ countries via the VirtualSMS API.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

virtualsms-io

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 15 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: VIRTUALSMS_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes44 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

virtualsms_list_proxy_catalog
virtualsms_list_proxies
virtualsms_buy_proxy
virtualsms_rotate_proxy

Request a fresh IP for an existing proxy. Useful when an endpoint flags the current exit IP.

virtualsms_get_proxy_usage

Get cached GB used/remaining and request count for one proxy. Cheap, no upstream call. Reads a cached value refreshed every ~5 minutes.

virtualsms_get_proxy_usage_history

Get a per-day traffic (GB) and request-count series for one proxy over the last 7 or 30 days.

virtualsms_set_proxy_targeting
virtualsms_test_proxy
virtualsms_list_proxy_locations
virtualsms_generate_proxy_endpoint
virtualsms_start_manual_registration_session

Beta, invite-only. Start a country-matched cloud browser you drive yourself: returns a viewer_url, an authenticated live-viewer link you open to watch and drive the session (manual takeover), plus optional order phone number and timeline. Agent-driven navigation is the separate opt-in session tools.

virtualsms_list_services
virtualsms_list_countries
virtualsms_get_price
virtualsms_get_balance
virtualsms_create_order
virtualsms_get_sms
virtualsms_cancel_order
virtualsms_wait_for_sms
virtualsms_find_cheapest
virtualsms_search_services
virtualsms_swap_number
virtualsms_list_orders
virtualsms_get_order
virtualsms_cancel_all_orders
virtualsms_order_history
virtualsms_get_stats
virtualsms_get_profile
virtualsms_get_transactions
virtualsms_rentals_pricing
virtualsms_rentals_available
virtualsms_rentals_services
virtualsms_rentals_price

Get the catalog-driven retail price for a (service, country, duration) platform-tier rental combo.

virtualsms_create_rental
virtualsms_list_rentals
virtualsms_get_rental
virtualsms_extend_rental

Extend an active rental by an additional duration. Charges your balance at the current catalog price for that duration.

virtualsms_cancel_rental
virtualsms_release_rental
virtualsms_retry_order
virtualsms_check_number

Public carrier + line-type lookup for an arbitrary E.164 phone number (mobile/landline/VoIP, spam risk). No API key required.

virtualsms_stop_session

Beta. Stop an active browser session and release it.

virtualsms_navigate_session

Beta. Navigate an active browser session to a URL.

virtualsms_session_viewer

Beta. Get the live viewer URL and current status for an active browser session.

// known CVEs in dependencies15 high5 medium11 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.0.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highaxios@1.7.0GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.7.0GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

highaxios@1.7.0GHSA-43fc-jf86-j433

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

highaxios@1.7.0GHSA-4hjh-wcwx-xvwj

Axios is vulnerable to DoS attack through lack of data size check

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configMCP_HTTP_PORT
🔐 secretVIRTUALSMS_API_KEY"": "vsms_your_api_key_here"
configVIRTUALSMS_BASE_URLNo https://virtualsms.io API base URL
configVIRTUALSMS_DEFAULT_COUNTRY
configVIRTUALSMS_ENABLE_RELEASENo off Serves the early-release rental tool when set to 1, true or yes. Off by default while its refund terms are being settled
configVIRTUALSMS_ENABLE_SESSIONSNo off Serves 3 additional session-drive tools when set to 1, true or yes. Off by default
configVIRTUALSMS_RATE_LIMIT_CAPACITY
configVIRTUALSMS_RATE_LIMIT_REFILL_PER_SEC
configVIRTUALSMS_TIMEOUT
// quality suggestions

Production dependencies are patched

0 critical, 15 high severity in production deps — @modelcontextprotocol/sdk@1.0.0 (high), axios@1.7.0 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/virtualsms-io/mcp-server?variant=verified)](https://m8ven.ai/mcp/virtualsms-io/mcp-server)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: c6232fdb5e904e040d6ddf3a1081a3c45837becd
code hash: f9487d5e92b73638db5ef957bb3fd28e39bdfbbeba20738c56ba8259a1107fa3
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client