fluent-community-mcp (wplaunchify/fluent-community-mcp) is an MCP server listed on the M8ven Trust Index. It scores 54 out of 100, grade D. It declares 169 tools. No publisher has claimed this listing.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

wplaunchify

Source: ModelScope

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: WORDPRESS_API_URL. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Known vulnerabilities in dependencies: 15 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 1 credential: WORDPRESS_PASSWORD
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes145 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

list_comments

Lists comments with filtering, sorting, and pagination options

get_comment

Gets a comment by ID

create_comment

Creates a new comment

update_comment

Updates an existing comment

delete_comment

Deletes a comment

fcart_list_products

List all products in FluentCart store with filtering options

fcart_get_product

Get detailed information about a specific product

fcart_create_product

Create a new product in FluentCart

fcart_update_product

Update an existing product

fcart_delete_product

Delete a product from FluentCart

fcart_update_product_pricing

Update product pricing (price, sale_price, SKU)

fcart_get_product_thumbnail

Get product thumbnail image

fcart_set_product_thumbnail

Set product thumbnail image

fcart_list_orders

List all orders with filtering options

fcart_get_order

Get detailed information about a specific order

fcart_create_order

Create a new order manually

fcart_update_order

Update order status or details

fcart_mark_order_paid

Mark an order as paid

fcart_refund_order

Refund an order

fcart_update_order_statuses

Bulk update order statuses

fcart_delete_order

Delete an order

fcart_list_customers

List all customers in FluentCart

fcart_get_customer

Get customer details including order history

fcart_create_customer

Create a new customer

fcart_update_customer

Update customer details

fcart_list_coupons

List all discount coupons

fcart_create_coupon

Create a new discount coupon

fcart_update_coupon

Update coupon details

fcart_delete_coupon

Delete a coupon

fcart_get_coupon

Get coupon details

fcart_apply_coupon

Apply a coupon to a cart or order

fcart_list_subscriptions

List all subscriptions

fcart_get_subscription

Get subscription details

fcart_cancel_subscription

Cancel a subscription

fcart_reactivate_subscription

Reactivate a cancelled subscription

fcart_get_analytics

Get store analytics and sales data

fc_list_posts

List all posts from FluentCommunity with optional filtering

fc_get_post

Get a specific FluentCommunity post by ID with all details

fc_create_post

Create a new post in FluentCommunity

fc_update_post

Update an existing FluentCommunity post

fc_delete_post

Delete a FluentCommunity post

fc_list_spaces

List all spaces in FluentCommunity

fc_get_space

Get detailed information about a specific FluentCommunity space

fc_create_space

Create a new space in FluentCommunity

fc_update_space

Update an existing FluentCommunity space

fc_list_comments

List FluentCommunity comments for a specific post or all comments

fc_create_comment

Create a new comment on a FluentCommunity post

fc_update_comment

Update an existing FluentCommunity comment

fc_delete_comment

Delete a FluentCommunity comment

fc_list_space_members

List members of a specific FluentCommunity space

fc_add_space_member

Add a user to a FluentCommunity space

fc_remove_space_member

Remove a user from a FluentCommunity space

fc_search_content

Search across all FluentCommunity content (posts, comments, spaces)

fc_get_space_analytics

Get analytics and statistics for a FluentCommunity space

fc_bulk_create_posts

Create multiple FluentCommunity posts at once (useful for AI-generated content campaigns)

fc_bulk_update_posts

Update multiple FluentCommunity posts at once

fc_bulk_delete_posts

Delete multiple FluentCommunity posts at once

fc_get_colors

Get FluentCommunity color scheme (light or dark mode)

fc_update_colors

Update FluentCommunity color scheme for light or dark mode

fc_get_portal_settings

Get FluentCommunity portal display settings

fc_update_portal_settings

Update FluentCommunity portal display settings (layout, sidebar, features)

fc_get_branding

Get FluentCommunity branding settings (logo, favicon, custom CSS)

fc_update_branding

Update FluentCommunity branding (logo, favicon, custom CSS/HTML)

fc_get_layout

Get FluentCommunity layout settings (menu position, sidebar placement, component visibility, content injection)

fc_update_layout

Update FluentCommunity layout settings. Control menu positioning (top/side), sidebar placement (left/right), component visibility (hide/show members, spaces, etc.), and inject custom content (header, sidebar, footer with HTML/shortcodes)

fcrm_list_contacts

List FluentCRM contacts with filtering and pagination

fcrm_get_contact

Get a specific FluentCRM contact by ID

fcrm_create_contact

Create a new FluentCRM contact

fcrm_update_contact

Update an existing FluentCRM contact

fcrm_delete_contact

Delete a FluentCRM contact

fcrm_list_lists

List all FluentCRM contact lists

fcrm_get_list

Get a specific FluentCRM list by ID

fcrm_create_list

Create a new FluentCRM list

fcrm_update_list

Update a FluentCRM list

fcrm_delete_list

Delete a FluentCRM list

fcrm_list_tags

List all FluentCRM tags

fcrm_get_tag

Get a specific FluentCRM tag by ID

fcrm_create_tag

Create a new FluentCRM tag

fcrm_update_tag

Update a FluentCRM tag

fcrm_delete_tag

Delete a FluentCRM tag

fcrm_list_campaigns

List all FluentCRM email campaigns

fcrm_get_campaign

Get a specific FluentCRM campaign by ID

fcrm_create_campaign

Create a new FluentCRM email campaign

fcrm_send_campaign

Send a FluentCRM campaign

list_media

Lists media items with filtering and pagination options

create_media

Creates a new media item

edit_media

Updates an existing media item

delete_media

Deletes a media item

mlcanvas_create_page

Create a custom HTML/CSS page using ML Canvas Block. Perfect for landing pages, full-width designs, and custom layouts. No block recovery needed!

mlcanvas_edit_page

Surgical editing for ML Canvas pages - find/replace specific HTML/CSS snippets without rewriting entire page. Works on ANY post type with ML Canvas block.

mlcanvas_get_docs

Get ML Canvas Block API documentation

mlimg_generate

Generate new AI image from text prompt using Gemini 2.5 Flash. Perfect for creating custom images, illustrations, and visual content.

mlimg_edit

Edit existing image with AI. Modify colors, add elements, change styles, or transform existing images.

mlimg_iterate

Create variations of existing image. Generate multiple versions with different styles or modifications.

mlimg_batch_generate

Generate multiple AI images in batch. Create multiple images from different prompts in one request.

mlimg_list_images

List AI-generated/edited images. Filter by operation type, category, and more.

mlimg_get_history

Get image generation/editing history for a specific image. See all operations performed on an image.

mlimg_list_categories

List media categories available for organizing AI-generated images.

mlimg_health

Check ML Image Editor API health and configuration. Verify plugin is installed and API keys are configured.

mlmh_search_images

Search Google Images via SERP API. Returns image results with URLs, thumbnails, dimensions, and sources ready for import to WordPress media library. Requires SERP API key configured in ML Media Hub settings.

45 further tools are not listed here. The complete surface is in the source.

// known CVEs in dependencies15 high4 medium11 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.4.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.4.1GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highaxios@1.6.7GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.6.7GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

highaxios@1.6.7GHSA-43fc-jf86-j433

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configWORDPRESS_API_URL"": "https://yoursite.com",
🔐 secretWORDPRESS_PASSWORD
configWORDPRESS_USERNAME"": "your-username",
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

169/169 tools missing one or more hints — list_comments (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_comment (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); create_comment (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +166 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tests exist

No test files found

Add tests that exercise each declared tool.

Shell command execution

1 child_process/subprocess call in production code — runs shell commands (src/cli.ts:34)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Secrets not logged

1 secret value sent to console.log

Redact or omit secret values from log output.

Production dependencies are patched

0 critical, 15 high severity in production deps — @modelcontextprotocol/sdk@1.4.1 (high), @modelcontextprotocol/sdk@1.4.1 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/wplaunchify/fluent-community-mcp?variant=verified)](https://m8ven.ai/mcp/wplaunchify/fluent-community-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 7dd4607b112d4aa90f9a6600e90b3bf05ebefe16
code hash: e720a37bb26eab8eab4659b53b439fb58d039ce40f61f7bfa5b4684d890348a9
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client