mcpbeat Sign in

CodeVulnerability MCP Server

answering

CodeVulnerability is answering right now. Last checked 14 min ago.

OWASP threat scanner auditing codebases for safety leaks.

Uptime history 47 days of history · worst day 99%
47 days agonow
100.0%
Uptime 24h
91 of 91 checks
Tools
hidden behind auth
88 ms
Response time
average over 24h
authentication required
Access
sse

Nothing serious here today

Today is the operative word: we check CodeVulnerability every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 14 min ago.

run in your terminal
claude mcp add codevulnerability --transport http https://codevulnerability-mcp.vercel.app/api/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "codevulnerability": {
      "url": "https://codevulnerability-mcp.vercel.app/api/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.codevulnerability]
url = "https://codevulnerability-mcp.vercel.app/api/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "codevulnerability": {
      "url": "https://codevulnerability-mcp.vercel.app/api/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "codevulnerability": {
      "url": "https://codevulnerability-mcp.vercel.app/api/mcp"
    }
  }
}

This endpoint answered with an authorization challenge. The server is running, but it did not say what kind of credentials it expects.

Endpoints

URLTransportStateLatencyChecked
https://codevulnerability-mcp.vercel.app/api/mcp sse needs auth 66 ms 14 min ago

Alternatives to CodeVulnerability

same job, measured the same way
Scanpay
by misterio070

Code security scanner for AI agents. 45+ vulnerability patterns, AST analysis, Solana micropayments.

41 installs/wk local only
Bug Detector
by madhavi-opsera

Analyzes code for bugs, security vulnerabilities, and code smells

local only
SecurityScan
by apisecurityscan

Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.

8 tools answering
GhostFree
by shane-js

MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.

31 installs/wk local only
AI Scanner
by aakashbhardwaj27

Scan codebases for LLM/AI SDK usage, exposed API tokens, and hardcoded secrets.

44 installs/wk local only
MCP Codeaudit
by infoinlet-marketplace

Security audit for AI agents — scan code/diffs for leaked secrets, check deps via OSV.

23 installs/wk local only
Rune
by thecolourfoundation

Evidence-traced codebase understanding and security scanning for AI agents over MCP.

24 installs/wk local only
Scannd
by scannd

Trigger security scans and read reports/vulnerabilities via the hosted Scannd API. Free: 2 scans/mo.

54 installs/wk local only

CodeVulnerability — questions

Answers built from our own checks of this server.

Why is there no tool list for CodeVulnerability?
The server answered our handshake with an authorization challenge, so it is running — but it will not describe its tools to an anonymous client. To see them you need to connect with your own credentials. We record it as alive, not as broken: 100.0% of checks in the last 24 hours got a reply.
Is CodeVulnerability working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 88 ms. The bar chart above shows every period we have measured.
How do I connect CodeVulnerability?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address. You will need your own credentials: it refuses anonymous clients.
Does CodeVulnerability need an API key?
Yes. Every time we knock, CodeVulnerability answers with an authorization challenge instead of its tool list — that is how we know it is running and gated rather than broken. Bring your own credentials and it will talk.
How fast is CodeVulnerability?
It answers our handshake in 88 ms on average, which is faster than 85% of all working MCP servers we measure. That puts it in the quick quarter of the ecosystem. The comparison comes from our own checks across the whole registry, every 15 minutes.