← Back to search

io.github.domdomegg/google-maps-places-mcp

domdomegg Scanned 14d ago

Allow AI systems to search for places and get business info via Google Maps Places API.

B
80.5 / 100

Versions

1.1.2latest
first seen May 19, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 2

text_search
annotations: verified low

Search for places using a text query. Returns place details including name, address, rating, opening hours, photos, and more.

readOnlyHint true
photo_get
annotations: verified low

Get a photo URL for a place. Use the photo name from a text search response. At least one of maxHeightPx or maxWidthPx should be specified.

readOnlyHint true

Permissions 2

network medium
Server uses network capabilities via: fetch()
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 19

info
Tool 'text_search' annotations are consistent annotation_checker · 80%
info
Tool 'photo_get' annotations are consistent annotation_checker · 80%
high
Hardcoded OAuth client ID in domdomegg-google-maps-places-mcp-0bed135/src/main.ts auth_checker · 85%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.24.0 (GHSA-345p-7cg4-v4c7) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.24.0 (GHSA-8r9q-7v3j-jr4g) dependency_analyzer · 95%
medium
Vulnerable dependency: vitest@3.0.0 (GHSA-5xrq-8626-4rwp) dependency_analyzer · 95%
medium
Vulnerable dependency: vitest@3.0.0 (GHSA-9crc-q9x8-hgqq) dependency_analyzer · 95%
info
package.json metadata manifest_parser · 100%
info
Tool: text_search manifest_parser · 85%
info
Tool: photo_get manifest_parser · 85%
info
Transport: stdio manifest_parser · 90%
info
Required env vars (4) manifest_parser · 80%
medium
Hardcoded OAuth client ID in domdomegg-google-maps-places-mcp-0bed135/src/main.ts oauth_scope_analyzer · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 70%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 405 components sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%