
Product
PHP and Composer Support Is Now in Beta
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.
Native repository intelligence for coding agents: 42 read-only MCP operations backed by typed evidence graphs, impact, architecture, APIs, Git, search, semantics, and memory.
Give your coding agent repository evidence before it starts guessing.
Weavatrix is the native MCP product for repository intelligence. It gives Codex, Claude Code, and other coding agents 42 read-only operations over one revision-bound evidence graph: impact, architecture, APIs, Git history, duplicates, dead code, search, semantic links, and temporal memory.
It does not answer from a larger grep or an invented confidence score. Every bounded result can carry the repository revision, file, line, extractor, evidence kind, and confidence that produced it.
This npm package is the convenient prebuilt distribution of the same native
product published on crates.io as weavatrix. It is not a separate
JavaScript engine; both registry packages run the same Rust adapter and engine.
The separately versioned weavatrix-js package is a legacy compatibility
implementation and is not bundled here.
npx -y weavatrix mcp .
Or install the same native MCP product through Cargo:
cargo install weavatrix
weavatrix mcp .
[mcp_servers.weavatrix]
command = "npx"
args = ["-y", "weavatrix", "mcp", "."]
claude mcp add weavatrix -- npx -y weavatrix mcp .
Profiles expose bounded views of the same engine:
npx -y weavatrix mcp . --profile=all
npx -y weavatrix mcp . --profile=code
npx -y weavatrix mcp . --profile=seo
The package contains native binaries for Windows x64/arm64, macOS x64/arm64, and glibc Linux x64/arm64. It has no install script and performs no runtime download.
What breaks if I change src/auth/middleware.ts?
Trace POST /api/orders through this backend and its clients.
Which production symbols are dead, and what evidence proves it?
Show duplicate implementations but suppress router boilerplate.
Which dependency violates .weavatrix/architecture.json?
Find every GraphQL, gRPC, Kafka, RabbitMQ, NATS, JMS, SQS, or SNS
contract affected by this branch.
Build the smallest source bundle needed to edit this symbol safely.
| Workflow | Operations |
|---|---|
| Graph orientation | graph_stats, get_node, get_neighbors, query_graph, god_nodes, shortest_path, get_community, list_communities, module_map, build_graph |
| Change impact | get_dependents, change_impact, select_tests, verified_change, prepare_change, graph_diff |
| Exact source context | search_code, read_source, inspect_symbol, context_bundle, map_stacktrace |
| Health and quality | find_duplicates, find_dead_code, run_audit, coverage_map, hot_path_review |
| APIs and transports | list_endpoints, trace_endpoint, trace_api_contract |
| Architecture | get_architecture_contract, verify_architecture, explain_architecture_violation, propose_architecture_exception |
| Git and repositories | git_history, cross_repo_git, open_repo, list_known_repos, rebuild_graph |
| Native extensions | vector_search, semantic_link, seo_link_suggestions, memory_context |
Every operation is read-only with respect to the analyzed repository. Pagination and explicit limits bound large neighborhoods, histories, searches, and contract inventories.
| Group | Surfaces |
|---|---|
| Code | Rust; JavaScript/JSX; TypeScript/TSX; Python; Go; Java; C#; C; C++; SQL; Bash/Zsh; Swift; Solidity |
| Contracts and configuration | GraphQL; Protobuf/gRPC; JSON/JSONC; YAML/Kubernetes; Terraform/HCL; XML |
| Documents and UI | HTML/Vue/Svelte; CSS/SCSS/Sass/Less; Markdown/MDX; reStructuredText; AsciiDoc |
Cross-surface analysis connects HTTP, GraphQL, gRPC, Kafka, RabbitMQ/AMQP, JMS, NATS, SQS, and SNS evidence. Dynamic dispatch that cannot be proved stays unresolved; static reachability is never presented as measured coverage.
coding agent
|
| MCP over stdio
v
weavatrix 1.3.1
profile catalog · refresh · watcher · MCP framing
|
v
weavatrix-rust 2.2.1
typed graph · analysis · 42 read-only operations
This npm product owns MCP transport and native distribution. The
weavatrix-rust crate is
the reusable protocol-independent engine; it is not an MCP server.
Its standalone diagnostic therefore reports weavatrix-rust <engine-version>,
while this MCP product reports both its product and embedded-engine identities.
Engine 2.2.1 makes three reports carry only what their evidence supports:
find_duplicates reports the lines a clone covers completely and the byte
range to check them by, run_audit runtime findings land on the line they
matched, and token_budget is refused by the operations that cannot apply it
rather than accepted and ignored. find_duplicates also gains
include_strings, which compares the payloads of multi-line literals - inline
SQL, embedded templates - that the code pass sees as a single token.
The installed-package benchmark packs both products, installs them into isolated npm roots, starts fresh MCP processes with empty caches, and validates identity, advertised operations, results, and cleanup.
The packaged 1.2.0 product (weavatrix-rust 2.1.1) was measured on 2026-08-03
against installed weavatrix-js 0.3.15 on a real JavaScript service
repository: paired cold-boundary median 32.06x (spawn to first tool
result: 157.34 ms vs 5,068.22 ms) and warm tools/call median 36.85x
(7.94 ms vs 292.55 ms), passing the 24x cold and 30x warm release
thresholds and sitting slightly above the 30.34x recorded for the 1.0.0
baseline.
Full evidence and methodology: benchmarks.
unsafe Rust forbidden in first-party engine crates;MIT.
FAQs
Native repository intelligence for coding agents: 43 read-only MCP operations backed by typed evidence graphs, impact, architecture, APIs, Git, search, semantics, and memory.
The npm package weavatrix receives a total of 207 weekly downloads. As such, weavatrix popularity was classified as not popular.
We found that weavatrix demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.

Research
/Security News
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.