Atlas / MCP servers / pnizer / WWeb

WWebSAFE

mcp/pnizer/wweb

WhatsApp Web MCP Server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
13 8r · 5w · 0d
Transport
sse · stdio
License
MIT
Stars
46
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/pnizer/wweb-mcp/actions/workflows/pr-checks.yml)

A Node.js application that connects WhatsApp Web with AI models through the Model Context Protocol (MCP). This project provides a standardized interface for programmatic interaction with WhatsApp, enabling automated messaging, contact management, and group chat functionality through AI-driven workflows.

Overview

WhatsApp Web MCP provides a seamless integration between WhatsApp Web and AI models by:

  • Creating a standardized interface through the Model Context Protocol (MCP)
  • Offering MCP Server access to WhatsApp functionality
  • Providing flexible deployment options through SSE or Command modes
  • Supporting both direct WhatsApp client integration and API-based connectivity

Disclaimer

IMPORTANT: This tool is for testing purposes only and should not be used in production environments.

Disclaimer from WhatsApp Web project:

This project is not affiliated, associated, authorized, endorsed by, or in any way officially connected with WhatsApp or any of its subsidiaries or its affiliates. The official WhatsApp website can be found at whatsapp.com. "WhatsApp" as well as related names, marks, emblems and images are registered trademarks of their respective owners. Also it is not guaranteed you will not be blocked by using this method. WhatsApp does not allow bots or unofficial clients on their platform, so this shouldn't be considered totally safe.

Learning Resources

To learn more about using WhatsApp Web MCP in real-world scenarios, check out these articles:

Read from source at commit 6446dbf3ef95OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add wweb-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "wweb-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (13)

8 read · 5 write · 0 destructive.

ToolRiskDescription
add_participants_to_groupwrite
create_groupwrite
download_media_from_messageread
get_chatsread
get_group_by_idread
get_group_messagesread
get_messagesread
get_statusread
search_contactsread
search_groupsread
send_group_messagewrite
send_media_messagewrite
send_messagewrite
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/main.ts:192
logger.info(`WhatsApp API key: ${apiKey}`);
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslintrc.js
.eslintrc.js
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.puppeteer_ws
.puppeteer_ws
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/unit/api.test.ts:1
import { routerFactory } from '../../src/api';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/unit/api.test.ts:5
import { WhatsAppService } from '../../src/whatsapp-service';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/unit/api.test.ts:8
jest.mock('../../src/whatsapp-service');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/unit/mcp-server.test.ts:1
import { createMcpServer, McpConfig } from '../../src/mcp-server';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/unit/mcp-server.test.ts:2
import { WhatsAppService } from '../../src/whatsapp-service';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, express, mime-types, qrcode-terminal, whatsapp-web.js, winston, yargs
Why it matters. 29 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 6446dbf3ef95full audit observations/trust-audit/mcp-server/pnizer__wweb.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-086446dbf3ef95SAFEB89first audit
06

Questions

What is the WWeb MCP server?

WhatsApp Web MCP Server

What tools does WWeb expose?

13 in total: 8 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is WWeb safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does WWeb need?

No credential environment variables were found in its source, so it appears to need none.

How does WWeb run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as wweb-mcp at 0.2.5.

How current is this page?

The grade is for one exact copy of the source (6446dbf3ef95), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement