io.github.artgas1/xmlriver-mcp
PYPI · XMLRIVER-MCP · SCANNED SEP 20
Google/Yandex SERP parsing and Yandex Wordstat keyword frequency via XMLRiver XML API
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security100
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- Runs hatchling.build at install time, a recognised native-build step with no shell scripting around it. View diagnostics → Pass
- 1 of 24 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency32
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- License check failed: the license (MIT License) isn't a recognized OSI-approved license. See how to fix → Fail
- Actively maintained (last published 46 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability63
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3797 tokens (~345/item across 11 items; 11 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management83
- Stability observed for 25 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 11 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 12 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the io.github.artgas1/xmlriver-mcp server?
io.github.artgas1/xmlriver-mcp runs locally as a PyPI package, launched with uvx xmlriver-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · xmlriver-mcp
claude mcp add artgas1-xmlriver-mcp -- uvx xmlriver-mcp
{
"mcpServers": {
"artgas1-xmlriver-mcp": {
"command": "uvx",
"args": [
"xmlriver-mcp"
]
}
}
} {
"servers": {
"artgas1-xmlriver-mcp": {
"command": "uvx",
"args": [
"xmlriver-mcp"
]
}
}
} codex mcp add artgas1-xmlriver-mcp -- uvx xmlriver-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"artgas1-xmlriver-mcp": {
"type": "local",
"command": [
"uvx",
"xmlriver-mcp"
],
"enabled": true
}
}
} openclaw mcp add artgas1-xmlriver-mcp --command uvx --arg xmlriver-mcp
mcp_servers:
artgas1-xmlriver-mcp:
command: "uvx"
args: ["xmlriver-mcp"] {
"McpServers": {
"artgas1-xmlriver-mcp": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"xmlriver-mcp"
]
}
}
} assistant mcp add artgas1-xmlriver-mcp -t stdio -c uvx -a xmlriver-mcp
{
"mcpServers": {
"artgas1-xmlriver-mcp": {
"command": "uvx",
"args": [
"xmlriver-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 18 Sept 26 +12
- Malware scan: unverified → pass ▲ security
- Stability: pass → 0.77 functional
- 17 Sept 26 +1
- Stability: 0.97 → pass security
- 16 Sept 26 −15
- Malware scan: pass → unverified ▼ security
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 −3
- Stability: pass → 0.80 functional
- 10 Sept 26 +1
- Stability: 0.97 → pass security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed pypi/xmlriver-mcp@0.2.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | pypi |
Background: How many MCP packages publish verified provenance →
Install scripts 1 script
| Hook | Tier | Command |
|---|---|---|
| build_backend | allowlisted | hatchling.build |
Background: Why install scripts are a supply-chain risk →
Dependencies 24 packages
| Packages resolved | 24 |
|---|---|
| Stale | 1 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_url_indexed Check Url Indexed ~196
Check if a URL is indexed in Google or Yandex. Internally uses `url:<URL>` operator with `inindex=1` flag to xmlriver (forces fresh index check, not cache). Use this for: SEO audits, indexation monitoring, "did Google find my new page?". Returns: Dict with: - `url` — checked URL - `search_engine` - `indexed` — bool - `details` — full search results if indexed (with title, snippet, position)
| Name | Type | Req | Description |
|---|---|---|---|
| country | integer | – | For Google: country ID (default 2008=Russia). For Yandex: region ID (default 213=Moscow). |
| search_engine | string | – | Which engine to check. Default 'google'. |
| url | string | yes | URL to check indexing for. Full URL with scheme. Example: 'https://example.com/page-slug'. |
Structured output declared, but exposes no named fields.
No examples provided.
get_balance Get Balance ~74
Get current XMLRiver account balance in rubles (₽). Use this to check funds before bulk operations or to monitor spending. Returns: Dict with `balance_rub` (float) or `isError` on failure. Examples: get_balance() → {"balance_rub": 1234.56}
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
get_cost Get Cost ~170
Get cost per 1000 requests for a given engine, in rubles (₽). Use this to estimate spend for a planned bulk operation. Cost depends on current tariff — see `get_tariff` for the tariff name. Returns: Dict with `engine`, `cost_per_1k_rub` or `isError`. Examples: get_cost(engine="google") → {"engine": "google", "cost_per_1k_rub": 25.0}
| Name | Type | Req | Description |
|---|---|---|---|
| engine | string | yes | Engine to check cost for. 'google' = Google SERP parsing, 'yandex' = Yandex SERP (direct), 'yaxml' = Yandex Search API v2 (slightly pricier), 'wordstat' = Wordstat New API. |
Structured output declared, but exposes no named fields.
No examples provided.
get_tariff Get Tariff ~126
Get current XMLRiver tariff name. Tariffs: - 'Basic' — pay-as-you-go, no prepay, 25 ₽ per 1k requests - 'Pro' — 5000 ₽/mo prepay, 20 ₽ per 1k - 'Mega' — 15000 ₽/mo prepay, 15 ₽ per 1k - 'Giga' — 50000 ₽/mo prepay, 12 ₽ per 1k Returns: Dict with `tariff` (str) or `isError`.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
get_tariff_expire Get Tariff Expire ~55
Get expiration date for prepay tariff (Pro/Mega/Giga). Returns 'never' or date for Basic tariff (no expiry). Returns: Dict with `expires_at` (str) or `isError`.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
google_maps_search Google Maps Search ~336
Search Google Maps for places around a point. Use this for: local competitor mapping, presence checks in a city, pulling a list of businesses by category around a coordinate. Do NOT use for: organic web results (use `google_search`), or for a place you can name exactly — a plain web search answers that in one request. Returns: Dict with `results`, `total_found`, `query`, `coords`, `zoom`, `count`, or `isError: True` on failure (`code 108` means zoom/coords missing). Examples: google_maps_search(query="кофейня", coords="55.75581,37.61764", zoom=13) → places around central Moscow google_maps_search(query="barber", coords="41.40338,2.17403", zoom=14, count=50) → up to 50 places around Barcelona
| Name | Type | Req | Description |
|---|---|---|---|
| coords | string | yes | Map centre as 'latitude,longitude' — e.g. '55.75581,37.61764' for Moscow. Required by the API together with zoom. |
| count | integer | – | Places to return, 5–50. The service clamps anything above 50. |
| language | string | – | Interface language code, e.g. 'ru' or 'en'. Default 'ru'. |
| query | string | yes | What to look for on the map, e.g. 'кофейня' or 'car repair'. |
| zoom | integer | – | Map zoom, 1–15. Required by the API together with coords. |
Structured output declared, but exposes no named fields.
No examples provided.
google_search Google Search ~857
Parse Google search results page (SERP) for a given query and locale. Use this for: SEO research (own/competitor ranking), keyword discovery, SERP feature analysis (featured snippets, knowledge graph, FAQ), competitive intel. Do NOT use for: live page content fetching (use a dedicated scraper for that), Google Ads keyword planner data (use Yandex Wordstat via `wordstat_query` for RU). Returns: Dict with: - `query` (echoed) - `total_found` — Google's reported result count - `page` — page number - `results` — list of organic results with `position`, `url`, `title`, `snippet` - `addresults` — featured_snippet, related_questions, related_searches, knowledge_graph (if present and requested via `additional_blocks`) - Or `isError: True` on XMLRiver error (15 = no results, 110 = rate limit, etc). Examples: google_search(query="python tutorial", country=2008, language="ru") → {"results": [...10 organic results...], "total_found": 12300, "page": 1} google_search(query="site:wikipedia.org python", country=2840, language="en") → results restricted to wikipedia.org domain
| Name | Type | Req | Description |
|---|---|---|---|
| additional_blocks | – | – | Comma-separated extra blocks to parse: 'topads,bottomads,faqsnippet,rq,rs,knowledge_graph,sitelinks,g_news,g_videos,g_inlineshopping,searchsters,scroller,extended_snippet'. Each adds parsing cost on… |
| ai_overview | boolean | – | Parse Google's AI Overview block (slower, costs extra). Default False. |
| country | integer | – | Country ID for Google location. Default 2008 (Russia). Common values: 2008=RU, 2840=US, 2826=UK, 2276=DE, 2250=FR, 2724=ES, 2484=MX. Full list: https://xmlriver.com/apidoc/country/ |
| date_filter | – | – | Date filter (Google `tbs` param). Examples: 'qdr:h' (last hour), 'qdr:d' (24h), 'qdr:w' (week), 'qdr:m' (month), 'qdr:y' (year), or custom 'cdr:1,cd_min:1/1/2024,cd_max:6/1/2024'. |
| device | string | – | Device emulation. Default 'desktop'. |
| domain | integer | – | Google domain ID. Default 10 (google.com). Common: 10=google.com, 11=google.co.uk, 53=google.com.tr, 84=google.ru. Full list: https://xmlriver.com/apidoc/domain/ |
| highlights | boolean | – | Wrap query words matched in title/snippet in <hlword> tags. |
| language | string | – | Interface language code (Google `lr` param). Examples: 'ru' (Russian), 'en' (English), 'de' (German), 'es' (Spanish). Default 'ru'. |
| location | – | – | Optional precise location ID (Google `loc` param). Overrides country/region with city-level precision. Full list: https://xmlriver.com/apidoc/loc/ |
| mobile_os | – | – | OS to emulate when device='mobile'. Ignored otherwise. |
| no_autocorrect | boolean | – | Search the query verbatim, without Google's spelling correction (nfpr=1). Use when checking how a misspelling actually ranks. |
| page | integer | – | Page number (1-based). Default 1. |
| query | string | yes | Search query. Plain text or with Google operators (site:, inurl:, etc). Example: 'купить iphone 15' or 'site:wikipedia.org openai'. |
| show_similar | boolean | – | Show near-duplicate results that Google hides by default. False (default) keeps Google's own behaviour; True sends filter=0. |
Structured output declared, but exposes no named fields.
No examples provided.
search_suggestions Search Suggestions ~441
Collect search-box suggestions (autocomplete) for a batch of phrases. Use this for: keyword research beyond Wordstat — suggestions surface live long-tail phrasings, including ones with no Wordstat frequency at all; they are what people actually type. Pair it with a prefix sweep (append each letter of the alphabet to a seed) to pull the tail systematically. Do NOT use for: frequency data (suggestions carry no volume — feed them to `wordstat_query` afterwards), or for SERP contents (use `google_search` / `yandex_search`). Returns: Dict with: - `engine` (echoed), `requested` — number of phrases sent - `suggestions` — flat, de-duplicated list of suggestion strings - `count` — number of suggestions returned - Or `isError: True` on failure (including API-level errors such as `code 104` for an unsupported parameter). Examples: search_suggestions(phrases=["отчет по практике"]) → {"engine": "google", "suggestions": ["отчет по практике пример", …], "count": 10} search_suggestions(phrases=["купить iphone", "купить ipad"], engine="yandex", lr="213") → suggestions from the Yandex search box for the Moscow region
| Name | Type | Req | Description |
|---|---|---|---|
| domain | – | – | Search domain. Yandex takes a string ('ru', 'com', 'ua', 'by', 'kz', 'com.tr'); Google takes its numeric domain id as a string. Omit for the default. |
| engine | string | – | Which search box to read suggestions from. Default 'google'. |
| lr | – | – | Language/region. Google: language code such as 'ru'. Yandex: numeric region id such as '213' (Moscow). Omit for the default. |
| phrases | array | yes | Phrases to autocomplete, 1–50 per call. BILLED PER PHRASE — 50 phrases in one call costs 50 requests, so batch deliberately rather than maximally. |
Structured output declared, but exposes no named fields.
No examples provided.
wordstat_query Wordstat Query ~684
Get Yandex Wordstat frequency, or demand dynamics over time, for a phrase. Use this for: keyword research, demand validation, **seasonality analysis**, long-tail discovery. **Russian/Yandex-speaking markets** — this is Yandex's equivalent of Google Keyword Planner. Do NOT use for: Google volume (Wordstat is Yandex-only — for Google use Google Keyword Planner or third-party tools). Two mutually exclusive modes, selected by `history_period`: - ``none`` (default) — `total_shows`, `containing_phrases`, `similar_queries` - anything else — `total_shows` plus `history`; **no phrases**, because the upstream API does not return them in this mode Returns: Dict with: - `query` (echoed), `region` (if set) - `total_shows` — monthly impressions for the phrase - `containing_phrases` / `similar_queries` — words mode only - `history` — list of `{date, shows, share_of_all_queries?}`, history mode only. `date` is `YYYY-MM` for monthly, `YYYY-MM-DD` for weekly (week start) and daily. - `window` — `{start, end, period}` actually requested upstream - Or `isError: True` on failure. Examples: wordstat_query(query="купить iphone") → {"total_shows": 187234, "containing_phrases": [...], "similar_queries": [...]} wordstat_query(query="реферат", history_period="monthly", start="2024-01-01") → {"total_shows": 145052, "history": [{"date": "2024-01", "shows": 2025430}, ...]}
| Name | Type | Req | Description |
|---|---|---|---|
| device | – | – | Device type filter. None (default) = all devices combined. Otherwise: 'desktop', 'phone', or 'tablet'. |
| end | – | – | History mode only. Window end, ISO 'YYYY-MM-DD'. Snapped to the period boundary and clamped to the last COMPLETE period — the current month/week and today are never returned. |
| history_period | string | – | Switch to demand-dynamics mode. 'none' (default) returns frequency plus related phrases. Any other value returns frequency plus a time series and NO phrases — the API modes are mutually exclusive. 'm… |
| query | string | yes | Keyword phrase to check frequency for. Yandex operators OK: '!' (exact form), '+' (require word), '"..."' (exact phrase), '-' (negative word). Examples: 'купить iphone', '!купить +iphone', '"новый го… |
| region | – | – | Yandex region ID for geo-targeted frequency. Default None = all of Russia + neighbors. 213=Moscow, 2=SPb, 65=Novosibirsk, etc. |
| start | – | – | History mode only. Window start, ISO 'YYYY-MM-DD'. Snapped to the period boundary (1st of month / Monday). Default: 24 months, 12 weeks or 30 days back depending on history_period. |
Structured output declared, but exposes no named fields.
No examples provided.
yandex_search Yandex Search ~587
Parse Yandex search results page (SERP) for a given query and region. Use this for: Russian SEO research (own/competitor ranking in Yandex), regional keyword analysis, SERP feature analysis (FAQ, knowledge graph), competitive intel for Russian-speaking markets. Do NOT use for: keyword frequency data — use `wordstat_query` instead. Do NOT use for: structured JSON output — use `yandex_search_api_v2` instead (official Yandex Search API proxy, cleaner JSON). Returns: Dict with `results` (organic 10 items), `total_found`, `page`, `addresults` (related_questions, knowledge_graph, etc), or `isError: True` on failure. Examples: yandex_search(query="купить iphone", region=213) → top 10 organic for Moscow yandex_search(query="site:wildberries.ru игрушки", region=2) → site-restricted search for St. Petersburg yandex_search(query="новости", within="77") → last-24-hours filtered
| Name | Type | Req | Description |
|---|---|---|---|
| additional_blocks | – | – | Comma-separated extra blocks: 'topads,bottomads,faqsnippet,rq,rs,knowledge_graph,sitelinks,extended_snippet,fast_links,related_searches'. |
| device | string | – | Device emulation. Default 'desktop'. |
| domain | string | – | Yandex domain. Default 'ru'. |
| filter_duplicates | boolean | – | Filter near-duplicate results. Default False (Yandex default). |
| highlights | boolean | – | Wrap query words matched in title/snippet in <hlword> tags. |
| language | string | – | Interface language. Default 'ru'. |
| mobile_os | – | – | OS to emulate when device='mobile'. Ignored otherwise. |
| page | integer | – | Page number (0-based for Yandex). Default 0. |
| query | string | yes | Search query. Plain text or with Yandex operators (site:, inurl:, host:, etc). Example: 'купить квартиру москва' or 'site:habr.com nextjs'. |
| region | integer | – | Yandex region ID (lr param). Default 213 (Moscow). Common: 213=Moscow, 2=SPb, 65=Novosibirsk, 54=Yekaterinburg, 47=NN, 10174=Samara, 11119=Krasnodar, 39=Rostov, 51=Kazan. Full list: https://yandex.ru… |
| within | – | – | Date filter (Yandex `within` param). Values: '77' (24h), '1' (2 weeks), '2' (1 month), or 'YYYYMMDD..YYYYMMDD' custom range. |
Structured output declared, but exposes no named fields.
No examples provided.
yandex_search_api_v2 Yandex Search Api V2 ~198
Query Yandex Search API v2 (official) via XMLRiver proxy. Use this when you need: cleaner structured output, no SERP-feature parsing overhead, documented Yandex Search API semantics. Slightly more expensive than `yandex_search` (~24 ₽/1k vs 25 ₽/1k on Basic tariff). Do NOT use for: SERP features (knowledge graph, FAQ, related questions) — those are not in the official API. Use `yandex_search` instead. Returns: Parsed search results dict similar to `yandex_search` but without addresults.
| Name | Type | Req | Description |
|---|---|---|---|
| group_count | integer | – | Results per page (Yandex Search API). Default 10. |
| page | integer | – | Page number (0-based). Default 0. |
| query | string | yes | Search query. |
| region | integer | – | Yandex region ID (lr). Default 213 (Moscow). |
Structured output declared, but exposes no named fields.
No examples provided.
What is the io.github.artgas1/xmlriver-mcp server?
io.github.artgas1/xmlriver-mcp is listed in the public MCP registry as io.github.artgas1/xmlriver-mcp. Google/Yandex SERP parsing and Yandex Wordstat keyword frequency via XMLRiver XML API. This page covers its PyPI package (xmlriver-mcp).
Is the io.github.artgas1/xmlriver-mcp server safe to use?
io.github.artgas1/xmlriver-mcp scores 77 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.artgas1/xmlriver-mcp server expose?
io.github.artgas1/xmlriver-mcp exposes 11 tools: get_balance, get_tariff, get_tariff_expire, get_cost, google_search, and 6 more. Their descriptions and schemas cost roughly 3,724 tokens of context every time the server is loaded.
Is the io.github.artgas1/xmlriver-mcp server still maintained?
io.github.artgas1/xmlriver-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.