Skip to content

Security: PiwikPRO/mcp

SECURITY.md

HTTP Transport

When running with --transport streamable-http, the MCP server exposes an unauthenticated HTTP endpoint. Anyone who can reach that endpoint can invoke MCP tools within the limits of the server's configured Piwik PRO API token. This transport is intended for local development only — do not expose it to the public internet without your own authentication layer in front of it.

See Development Guide — HTTP Transport for details.

Reporting a Vulnerability

If you discover a vulnerability in this repository, please use the “Report a vulnerability” feature available under the Security tab of the repository.

  • Go to the repository on GitHub.
  • Click on the Security tab.
  • Select Report a vulnerability to securely notify us.

This ensures that sensitive information is not publicly disclosed before a fix is available.

Response Timeline

  • You will receive an acknowledgment of your report within 48 hours.

There aren't any published security advisories