Wass MCP

A Model Context Protocol (MCP) server for web application security scanning. MCP Protocol Support - Full compatibility with MCP clients (Claude, etc.) Nikto Integration - Web server vulnerability scanning Nuclei Integration - Template-based vulnerability scanning Wapiti Integration - Web application vulnerability scanning Shcheck Integration - Security headers analysis Execution History - Persistent storage of scan…

People who need security tools inside Claude, Cursor, VS Code, or another MCP client. The project is written in Go.

VERIFIED ACTIVE

LAST COMMIT 2026-03-18 · ★ 7 · #182 OF 182 MAINTAINED SECURITY · VERIFIED 2026-08-25

BSD-3-Clause · Go servers · how we verify → /methodology

01 · Evidence

Security posture

What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.

license BSD-3-Clause - declared in the repository

registry namespace io.github.tb0hdan is GitHub-verified and matches the repo owner

02 · What Wass MCP can do

Prose above is summarized from the project's README and registry record - no invented capabilities.

What you can build

An agent gets 2 documented tools across shcheck, full, including shcheck_py, full_scan.

The 2 tools it gives your agent

Extracted from the project's README - what wass-mcp lets an agent do.

shcheck_py
- Analyze HTTP security headers using shcheck.py.
full_scan
- Perform a comprehensive security scan using all available scanners in parallel.

Latest releases

v1.1.0 · 2026-03-03

Release Notes · Recent Changes · Version bump · BuildTargetURL fix · Version bump · Shcheck · Version bump for future changes · Docker run should not require docker build · Deduplicate tools code · MCP registry…

v1.0.6 · 2026-03-03

Release Notes · Recent Changes · BuildTargetURL fix · Version bump · Shcheck · Version bump for future changes · Docker run should not require docker build · Deduplicate tools code · MCP registry server.json · Tests…

v1.0.5 · 2026-03-03

Release Notes · Recent Changes · Shcheck · Version bump for future changes · Docker run should not require docker build · Deduplicate tools code · MCP registry server.json · Tests · Readme update · Version bump for…

03 · Who maintains Wass MCP

wass-mcp is maintained by tb0hdan. It's the only MCP server we track from this author; the repo dates to Jan 2026.

04 · Facts

category
security - ranked #182 of 182 actively-maintained security servers as of 2026-08-25.
registry
io.github.tb0hdan/wass-mcp (active, first published 2026-01-23 · 2 versions)

05 · Wass MCP FAQ

What is Wass MCP?

A Model Context Protocol (MCP) server for web application security scanning. MCP Protocol Support - Full compatibility with MCP clients (Claude, etc.) Nikto Integration - Web server vulnerability scanning Nuclei Integration - Template-based vulnerability scanning Wapiti Integration - Web application vulnerability scanning Shcheck Integration - Security headers analysis Execution History - Persistent storage of scan…

Is Wass MCP still maintained?

Yes - as of 2026-08-25, its last commit was 2026-03-18. We re-verify nightly.

06 · Alternatives to Wass MCP