hostinger / security
Security review

Is hostinger-api-mcp MCP safe to give an agent?

destructive capableunknowndestructive capablehealthy

A factual risk summary built from hostinger-api-mcp’s real tool surface, execution model, and verification history — not a vibe. Trust score 43/100.


01What it can do

Has tools that can delete or irreversibly change data.

203 tools observeddestructive presentwrite present

02Execution model

Transport not yet confirmed, so the execution model is unknown. Treat as untrusted until verified.

Installs via npx (`npx -y hostinger-api-mcp`) — it pulls and executes third-party code; pin versions and review the source.


03Permissions & auth
Process payments · destructiveQuery a database · destructiveManage GitHub · writeManage cloud infra · writeMaps & location · write

The write/destructive access this server can exercise, inferred from its verified tools.


04Verification
handshakenot confirmed
runshandshake:failed · metadata:passed · handshake:failed · metadata:passed · handshake:failed · metadata:passed · handshake:failed · metadata:passed · handshake:failed · metadata:passed
last_checked2026-08-16 20:10Z
sourcesnpm registry [p4] · Awesome MCP Servers (wong2) [p6]

Reduce the risk

Worried about handing an agent raw access? See governed agents in action — Apex gives your AI paced, capped, fully-logged hands with approval queues before anything runs.

Explore Apex →

See also: full server page · setup · alternatives

Is hostinger-api-mcp MCP safe? — risk & permissions — MCPExplorer