# hosting_listNode_jsVulnerabilitiesV1

Lists known npm package vulnerabilities detected on a Node.js website, enriched with advisory metadata (severity, CVSS score, CVE, advisory URL). Results are sorted from the most severe to the least severe, then by publish date (newest first). Use the severities query parameter to filter. Vulnerabilities with is_patchable set to true can be auto-fixed via the Patch Node.js Vulnerabilities endpoint, which opens a GitHub pull request with updated package versions. Auto-fix is only available for websites deployed from a connected GitHub repository. Vulnerabilities with is_patching_in_progress set to true are already included in an open patch pull request; while any patch pull request is open, new patch requests for this website are rejected until it is merged or closed. Data comes from periodic dependency scans, so it may lag behind the latest deployment. An empty list means the most recent scan found no vulnerabilities; it does not guarantee the current deployment is vulnerability-free. Available on Business and Cloud Hosting plans.

Agent View of the PolicyLayer registry record for `hosting_listNode_jsVulnerabilitiesV1`. HTML page: https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-listnode-jsvulnerabilitiesv1

## Facts

- Tool: `hosting_listNode_jsVulnerabilitiesV1`
- Server: Hostinger Api (`hostinger-api-mcp`) — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp.md
- Install: `npx -y hostinger-api-mcp`
- Homepage: https://github.com/hostinger/api-mcp-server
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 3 (2 required)
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `domain` | string | yes | Domain name |
| `username` | string | yes | username parameter |
| `severities` | array | no | Severities to filter by |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "hosting_listNode_jsVulnerabilitiesV1",
    "arguments": {
      "domain": "<domain>",
      "username": "<username>"
    }
  }
}
```

## Why hosting_listNode_jsVulnerabilitiesV1 is rated Low

Even though hosting_listNode_jsVulnerabilitiesV1 only reads data, uncontrolled read access leaks sensitive information and racks up API costs: an agent caught in a retry loop can make thousands of calls a minute without anyone noticing.

## Use case

AI agents call hosting_listNode_jsVulnerabilitiesV1 to retrieve information from Hostinger Api without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Hostinger Api:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "hosting_listNode_jsVulnerabilitiesV1": {}
  }
}
```

## Other tools on Hostinger Api (257)

- `agency-hosting_clearAgencyPlanWebsiteCacheV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-clearagencyplanwebsitecachev1.md
- `agency-hosting_deleteAgencyPlanWebsiteCronJobV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deleteagencyplanwebsitecronjobv1.md
- `agency-hosting_deleteAgencyPlanWebsiteDatabaseUserV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deleteagencyplanwebsitedatabaseuserv1.md
- `agency-hosting_deleteAgencyPlanWebsiteDatabaseV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deleteagencyplanwebsitedatabasev1.md
- `agency-hosting_deleteAgencyPlanWebsiteV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agency-hosting-deleteagencyplanwebsitev1.md
- `agencyHosting_deployNodeStaticWebsite` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agencyhosting-deploynodestaticwebsite.md
- `agencyHosting_deployPhpApplication` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/agencyhosting-deployphpapplication.md
- `billing_deletePaymentMethodV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/billing-deletepaymentmethodv1.md
- `DNS_deleteDNSRecordsV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/dns-deletednsrecordsv1.md
- `DNS_resetDNSRecordsV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/dns-resetdnsrecordsv1.md
- `domains_deleteDomainForwardingV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/domains-deletedomainforwardingv1.md
- `domains_deleteWHOISProfileV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/domains-deletewhoisprofilev1.md
- `ecommerce_deleteStoreV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/ecommerce-deletestorev1.md
- `hosting_clearWebsiteCacheV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-clearwebsitecachev1.md
- `hosting_deleteAccountCronJobV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deleteaccountcronjobv1.md
- `hosting_deleteAccountDatabaseRemoteConnectionV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deleteaccountdatabaseremoteconnectionv1.md
- `hosting_deleteAccountDatabaseV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deleteaccountdatabasev1.md
- `hosting_deleteWebsiteParkedDomainV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsiteparkeddomainv1.md
- `hosting_deleteWebsiteSubdomainV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsitesubdomainv1.md
- `hosting_deleteWebsiteV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewebsitev1.md
- `hosting_deleteWordPressInstallationV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-deletewordpressinstallationv1.md
- `hosting_uninstallWordPressPluginsV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-uninstallwordpresspluginsv1.md
- `hosting_uninstallWordPressThemesV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/hosting-uninstallwordpressthemesv1.md
- `mail_deleteMailboxV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/mail-deletemailboxv1.md
- `mail_deleteWebhookV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/mail-deletewebhookv1.md
- `mail_revokeAPITokenV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/mail-revokeapitokenv1.md
- `reach_deleteAContactV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/reach-deleteacontactv1.md
- `VPS_deleteFirewallRuleV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/vps-deletefirewallrulev1.md
- `VPS_deleteFirewallV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/vps-deletefirewallv1.md
- `VPS_deletePostInstallScriptV1` — Destructive — https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp/vps-deletepostinstallscriptv1.md
- …and 227 more: https://policylayer.com/tools/io-github-hostinger-hostinger-api-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-hostinger-hostinger-api-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-hostinger-hostinger-api-mcp
