# Website Auditor (npm · website-auditor-mcp)

AI visibility + site audits: see if ChatGPT, Perplexity, Claude & Gemini recommend a website.

- Trust score: 63/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- npm · `website-auditor-mcp`: 63/100 (this document), [markdown](https://verifymcp.io/servers/spikeycoder-website-auditor-mcp/website-auditor-mcp.md), [page](https://verifymcp.io/servers/spikeycoder-website-auditor-mcp/website-auditor-mcp)

## Channel facts

- Registry: `npm`
- Package: `website-auditor-mcp`
- Version: `1.0.7`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 87/100
  - No malware found by supply-chain analysis.
  - Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 32/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - License check failed: the license (Elastic-2.0) isn't a recognized OSI-approved license.
  - Actively maintained (last published 1 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 79/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1535 tokens (~118/item across 13 items; 13 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add spikeycoder-website-auditor-mcp -- npx -y website-auditor-mcp
```

### Codex

```bash
codex mcp add spikeycoder-website-auditor-mcp -- npx -y website-auditor-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "spikeycoder-website-auditor-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "website-auditor-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add spikeycoder-website-auditor-mcp --command npx --arg -y --arg website-auditor-mcp
```

### Hermes

```yaml
mcp_servers:
  spikeycoder-website-auditor-mcp:
    command: "npx"
    args: ["-y", "website-auditor-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "spikeycoder-website-auditor-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "website-auditor-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 63, +43)

- [security regression] Provenance: unverified → fail
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Install scripts: unverified → pass
- [security improvement] Malware scan: unverified → pass
- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional regression] License: unverified → fail
- [functional regression] Tool coverage: 100 → unverified
- [functional regression] Security disclosure: fail → unverified
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Schema quality: unverified → excellent
- [functional] First check of Schema quality: unverified
- [functional] Licence: Elastic-2.0

### 2026-07-31 (score 20)

First indexed and scored.

## MCP tools (13)

### `get_ai_visibility` (~165 tokens)

Check AI visibility

Check how visible a website is to AI assistants right now. Use this whenever someone asks "does ChatGPT/Perplexity/Claude/Gemini recommend this business," "is my site showing up in AI answers," "what's my AI visibility / GEO score," or wants a quick read on whether an AI assistant would surface a given domain. Returns an overall AI-visibility score (0–100), a per-engine breakdown (ChatGPT, Perplexity, Claude, Gemini), and the top competitor appearing in place of the site. The result also includes trend data: 7- and 30-day score movement computed from the domain's stored snapshot history. Requires an active subscription.

Input parameters:

- `domain` (string, required): The website domain, e.g. "example.com".

### `run_audit` (~109 tokens)

Run a full audit

Run a full one-time audit of a website — AI visibility plus SEO, security headers, broken links, and performance. Use this when someone asks to "audit," "scan," "check," or "review" a website's health or SEO, or wants a complete report rather than just the AI-visibility number. Returns a scored summary across categories and a link to the full report. Requires an active subscription.

Input parameters:

- `domain` (string, required): The website domain, e.g. "example.com".

### `get_changes` (~123 tokens)

What changed since last check

Report what changed in a website's AI visibility and audit since it was last checked. Use this when someone asks "did anything change," "what's different this week/month," "did my AI visibility drop," or "did a competitor overtake me." Requires the domain to be tracked (see track_site). Returns deltas: score movement, engines gained/lost, competitors that moved, and new or resolved issues.

Input parameters:

- `domain` (string, required): The website domain, e.g. "example.com".
- `since` (string): Optional ISO date or "last_check".

### `compare_competitors` (~177 tokens)

Compare against competitors

Compare a website's AI visibility head-to-head against named competitors. Use this when someone asks "how do I stack up against X and Y," "who does ChatGPT recommend instead of me," or wants a competitive AI-visibility view. Returns each competitor's score and where they appear that the site does not. Each competitor not already cached costs one audit against your daily quota; if the quota can't cover every competitor, it ranks the ones it could audit and returns a `quota` summary plus a `skipped` list naming the rest — it never drops competitors silently or invents scores. If the quota is already exhausted it returns an over-quota error with the reset time.

Input parameters:

- `competitors` (array, required): Competitor domains to compare against.
- `domain` (string, required): The website domain, e.g. "example.com".

### `track_site` (~110 tokens)

Start/stop monitoring

Start (or stop) ongoing monitoring of a website's AI visibility on a schedule. Use this when someone wants to "monitor," "track," "watch," or "get alerted about" a site's AI visibility over time, rather than a one-off check. Establishes the history that get_changes reads from.

Input parameters:

- `cadence` (string): Monitoring cadence (weekly).
- `domain` (string, required): The website domain, e.g. "example.com".
- `enabled` (boolean): Set false to stop monitoring.

### `get_benchmark` (~103 tokens)

Benchmark vs industry/geo

Benchmark a website's AI visibility against its industry and location. Use this when someone asks "how do I compare to others in my space," "is this a good score for my industry," or wants percentile/peer context rather than an absolute number. Backed by aggregated audit data.

Input parameters:

- `domain` (string, required): The website domain, e.g. "example.com".
- `geo` (string): Optional location override.
- `industry` (string): Optional industry override.

### `get_recommendations` (~84 tokens)

Prioritized fixes

Get specific, prioritized fixes to raise a website's AI visibility and audit scores. Use this when someone asks "how do I fix this," "what should I change," "how do I improve my AI visibility," or after an audit surfaces issues. Returns ranked actions with expected impact.

Input parameters:

- `domain` (string, required): The website domain, e.g. "example.com".

### `generate_schema` (~102 tokens)

Generate JSON-LD schema

Generate ready-to-paste structured data (JSON-LD schema) tailored to a website, to improve how AI assistants and search engines understand it. Use this when someone asks for "schema," "structured data," "JSON-LD," or wants the actual markup to implement a recommendation. Returns valid JSON-LD.

Input parameters:

- `domain` (string, required): The website domain, e.g. "example.com".
- `type` (string): Schema type, or auto-detect.

### `get_report` (~83 tokens)

Shareable report + badge

Get a shareable report URL and the embeddable "Audited by Website Auditor" badge snippet for a website. Use this when someone wants to "share," "export," "send a client," or "embed" the audit result. Returns a link and an HTML badge snippet.

Input parameters:

- `domain` (string, required): The website domain, e.g. "example.com".

### `untrack_site` (~96 tokens)

Stop monitoring

Stop ongoing monitoring of a website's AI visibility. Use this when someone wants to "stop tracking," "unmonitor," "stop watching," or "remove" a site from scheduled monitoring, or to free up a monitoring slot. Idempotent — safe to call even if the site isn't currently tracked. Returns how many monitoring slots are now free.

Input parameters:

- `domain` (string, required): The website domain, e.g. "example.com".

### `list_tracked_sites` (~80 tokens)

List monitored sites

List the websites currently being monitored for AI visibility on a schedule. Use this when someone asks "what am I tracking," "which sites am I monitoring," "how many monitoring slots am I using," or wants to see their tracked domains. Returns each tracked domain with its cadence and active state, plus slots used and remaining (out of 5).

### `get_monitoring_status` (~102 tokens)

Monitoring status summary

Get a glanceable summary of monitoring status across all tracked websites. Use this when someone asks "how are my tracked sites doing," "what's my current AI visibility across everything I monitor," "when were my sites last checked or when do they run next," or wants a dashboard of their monitored domains. Returns, per domain, the latest AI-visibility score, when it was last audited and next runs, and the most recent change since the prior check.

### `check_upgrade_status` (~117 tokens)

Check upgrade status

Check the caller's own Website Auditor subscription standing. Use this when someone asks "am I on Pro," "is my trial still active," "when does my subscription renew/end," "why is this tool locked," or before suggesting an upgrade. Works with any valid API key and consumes no audit quota. Returns the tier (none/free/pro), raw subscription status, period end, whether the subscription is set to cancel, the upgrade URL, and a plain-language summary — including what starting Pro requires (a payment method and accepting the Terms).

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/spikeycoder-website-auditor-mcp/website-auditor-mcp#diagnostics

## Score history

- 2026-08-03: 63
- 2026-08-02: 63
- 2026-08-01: 20
- 2026-07-31: 20

## Links

- npm package: https://www.npmjs.com/package/website-auditor-mcp
- Socket report: https://socket.dev/npm/package/website-auditor-mcp
- Repository: https://github.com/SpikeyCoder/website-auditor-mcp
- Website: https://website-auditor.io/
- Changelog RSS feed: https://verifymcp.io/servers/spikeycoder-website-auditor-mcp/website-auditor-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/spikeycoder-website-auditor-mcp/website-auditor-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/spikeycoder-website-auditor-mcp/website-auditor-mcp
