@modelcontextprotocol/server-everart
MCP server for EverArt API integration
Installing this server brings 94 third-party packages inside your agent's trust boundary (4 direct). This is attack surface, not a vulnerability count — it does not affect the grade above.
Findings (3)
- HIGH
DEPRECATED— @modelcontextprotocol/server-everart is marked deprecated on npm. Deprecated packages receive no security fixes. Migrate. - LOW
PKG_LOWDL— @modelcontextprotocol/server-everart has very low weekly downloads (75). Few users means few eyes on the code. - LOW
NO_REPO— @modelcontextprotocol/server-everart has no linked source repository. Unverifiable source. Prefer packages with a public repo.
Embed this badge
[](https://vulnrable.com/mcp/modelcontextprotocol--server-everart/)
Automated registry-metadata scan; not a code audit. Findings come from npm metadata
published by the package owner and from public security advisories (OSV/GHSA) — not from our own
assessment of the code.
Grade scanned 2026-09-04 · package count resolved 2026-08-18.
A package fixed after that date will still show its earlier grade here.
Maintainer and think this is wrong or out of date? Get in touch — corrections are welcome.