SimplyScan

Security, SEO and AI-visibility scanner for web apps · free scans and focused checks via MCP.

Should I use this

Quality & Safety

A
Description quality
89%
Schema completeness
100%
Naming quality
97%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (2)

  • LOWTool 'check_security_headers' description lacks action verbin check_security_headers
  • LOWTool 'check_exposed_files' description lacks action verbin check_exposed_files

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~792Tokens (tool definitions)
~551 BTypical response size
Moderate attention impact (0.62% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "simplyscan": {
      "url": "https://api.simplyscan.io/mcp"
    }
  }
}

Remote endpoints

https://api.simplyscan.io/mcpstreamable-http

What it can do

Tool inventory

Tools (7)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢scan_website(url)

Run a free SimplyScan security & speed scan of a deployed web app URL. Returns a 0-100 score and findings (exposed secrets, missing Supabase RLS, frontend leaks, speed issues). Best for apps built with Lovable, Bolt, v0, Cursor, Replit, etc.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "format": "uri",
      "description": "Full https URL to check"
    }
  },
  "required": [
    "url"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢check_security_headers(url)

Grade a URL's HTTP security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy, COOP, COEP) A-F.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "format": "uri",
      "description": "Full https URL to check"
    }
  },
  "required": [
    "url"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢check_ai_visibility(url)

AEO check: whether AI answer engines (ChatGPT/GPTBot, Claude, Perplexity, Google-Extended, etc.) can crawl and cite the site, plus llms.txt and structured-data signals.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "format": "uri",
      "description": "Full https URL to check"
    }
  },
  "required": [
    "url"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢check_seo(url)

On-page SEO audit of a URL: title, meta description, H1, canonical, indexability, Open Graph, structured data, image alt coverage, sitemap. Returns an A-F grade.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "format": "uri",
      "description": "Full https URL to check"
    }
  },
  "required": [
    "url"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢check_ssl(domain)

Inspect a domain's SSL/TLS certificate: issuer, expiry, protocol, and flags for expiring/self-signed/mismatched certs.

Input Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1,
      "description": "Domain, e.g. example.com"
    }
  },
  "required": [
    "domain"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢check_email_security(domain)

Check a domain's email authentication: SPF, DKIM (common selectors), and DMARC policy. Flags spoofable domains.

Input Schema

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1,
      "description": "Domain, e.g. example.com"
    }
  },
  "required": [
    "domain"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢check_exposed_files(url)

Probe a site for accidentally exposed high-risk files (.env, .git/config, backups, etc.). Reports HTTP status only, never file contents.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "format": "uri",
      "description": "Full https URL to check"
    }
  },
  "required": [
    "url"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded7 tools
verifiedversion not recorded7 tools