Package Health

n8n-mcp

It includes clear documentation, TypeScript declarations, licensing, and no install-time script. Repository activity, testing, releases, and provenance are strong, though workflow hygiene needs attention before broad adoption.

Latest 2.90.0NPMNPM

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Project backingcaution

The repository is owned by a named individual rather than an organization, so the project has a thinner formal backing structure; strong recent release and repository activity partly compensates.

Workflow auditcaution

All 8 workflows were analyzed with no untrusted checkouts or script-injection counts, but two high-confidence template-injection findings, two adhoc package installations, and 70 of 110 unpinned action uses weaken workflow hygiene. The findings are not independently a release-blocking danger because no risky trigger or untrusted checkout was reported.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-924507
n8n-mcp is vulnerable to Server-Side Request Forgery (SSRF) in versions 2.16.3 - 2.68.4.
2.16.3 - 2.68.4
Low
AIKIDO-2026-552585
n8n-mcp is vulnerable to Insecure Direct Object Reference (IDOR) in versions 2.22.5 - 2.56.0.
2.22.5 - 2.56.0
Critical
AIKIDO-2026-210530
n8n-mcp is vulnerable to Incorrect Authorization in versions 2.7.7 - 2.57.3.
2.7.7 - 2.57.3
Medium
CVE-2026-45707
n8n-mcp is vulnerable to Improper Access Control in versions 0.0.0 - 2.51.1.
0.0.0 - 2.51.1
High
CVE-2026-45582
n8n-mcp is vulnerable to Insertion of Sensitive Information Into Sent Data in versions 0.0.0 - 2.51.3.
0.0.0 - 2.51.3
Medium

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
uuid
Version ^11.1.1
—
—
axios
Version ^1.7.7
—
—
tslib
Version ^2.6.2
—
—
dotenv
Version ^16.5.0
—
—
sql.js
Version ^1.13.0
—
—

Weekly Downloads

Info

Last Published
13 hours ago
Created
1 year ago
Unpacked Size
75.9 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform