atx/registry

api.convalytics.dev

https://api.convalytics.dev/mcp

49
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 3h ago

Why this score

mcp.unauthenticated_consequential_tools-8
tls_present_and_valid+4
mcp_capabilities_discoverable+4
headers.missing_hsts-3
reachable+2

Findings (3)

mediumCapabilities are listable without authentication, including 3 whose names suggest state change (create_funnel, delete_funnel, update_funnel) — inferred from tool names, not confirmed
mcp.unauthenticated_consequential_tools @ 1.0.0
lowNo Strict-Transport-Security header
headers.missing_hsts @ 1.0.0
infoCORS allows any origin
cors.wildcard_origin @ 1.0.0

Evidence (8)

TypeObservedSHA-256
dns_resolution_observation3h ago495a2564fd09b45d…
http_response_observation3h ago5842172264325b16…
availability_observation3h ago86f801c314e38237…
hosting_provider_observation3h agoe7292135d1d3f6bd…
tls_certificate_observation3h agofa14854e108ef163…
oauth_metadata_observation3h ago5ae0458625110f65…
mcp_protocol_observation3h agoff4138359493793d…
mcp_capability_observation3h agoe03d39f292604605…

Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.

Operate this service?

Prove control of api.convalytics.dev to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.

Claim this profile →