snogfever · MCP server
Search-only commerce MCP server (Stripe-backed)
Not claimed by its maker.
Published because it was found. A finding is information about where the limits are, not a verdict that the software is unsafe.
Receipt history: every signed receipt for every version of this listing, and what changed between them.
Search-only commerce MCP server (Stripe-backed)
Static scanned
Paste this into your client's MCP configuration.
{
"mcpServers": {
"mcp-merchant": {
"command": "npx",
"args": [
"-y",
"mcp-merchant@0.1.3"
]
}
}
}Or run it directly.
npx -y mcp-merchant@0.1.3Pinned to 0.1.3, which is the version the findings above were found in. Drop the version to take whatever is newest, and the report on this page stops describing what you installed.
249 installs last month · no published advisories · version current · checked 2026-10-07
No build provenance published. The repository above is the one the publisher declared, and nothing links it to the package you would install. That is not a mark against this listing, since most packages are published this way, but it is a check nobody can run.
It renders the current rung (static scanned) and links back here, where what that does and does not establish is one click away. It updates itself as the evidence deepens.
[](https://ooruby.com/market/mcp-merchant)Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.
Your AI agent, fluent in Australian tax. MCP server with cited answers from 34,500+ ATO documents, the income tax and GST Acts and 4,900+ rulings, plus deduction, depreciation, BAS and audit-risk tool
Maintenance
AbandonedLast release 16 Sep 2025 (0.1.3), 381 days before this check on 3 Oct 2026.
Read from the npm registry's publish history, read by the nightly publisher check.
Release activity only: it says nothing about quality or safety, and a finished small package can be fine without releases. How it is measured