{
  "data": {
    "a": {
      "slug": "postgres-mcp-pro",
      "name": "Postgres MCP Pro",
      "vendor": "Crystal DBA",
      "vendorUrl": "https://www.crystaldba.ai",
      "kind": "mcp",
      "category": "data",
      "summary": "PostgreSQL server with configurable read/write access plus DBA tooling (index tuning with hypopg, EXPLAIN analysis, top-query and workload analysis, health checks).",
      "url": "https://www.anchorterminal.com/tools/postgres-mcp-pro",
      "markdownUrl": "https://www.anchorterminal.com/tools/postgres-mcp-pro.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/postgres-mcp-pro.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/postgres-mcp-pro.json",
      "repo": "https://github.com/crystaldba/postgres-mcp",
      "license": "MIT",
      "transports": [
        "stdio",
        "sse"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "postgres-mcp"
        },
        {
          "registry": "oci",
          "name": "crystaldba/postgres-mcp"
        }
      ],
      "auth": "none",
      "authNotes": "No MCP-level auth; connects with a Postgres DATABASE_URI (environment variable or argument). The default access mode is unrestricted. --access-mode=restricted parses each statement against an allowlist, forces read-only transactions and stops queries after 30 seconds; an open report (#178) shows it can still read server files through a function in the FROM clause.",
      "pricing": "free",
      "pricingNotes": "Open source; no hosted offering.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No payments.",
        "endpoints": []
      },
      "toolCount": 9,
      "popularity": {
        "githubStars": 3200,
        "npmWeekly": null,
        "pypiWeekly": 228655,
        "asOf": "2026-09-26"
      },
      "docsUrl": "https://github.com/crystaldba/postgres-mcp#readme",
      "capabilities": [
        "db.sql",
        "db.admin"
      ],
      "tags": [
        "community",
        "local",
        "open-source",
        "python",
        "read-only-mode"
      ],
      "lastRelease": "2025-05-16",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 36.7,
        "grade": "F",
        "agentReady": false,
        "rank": 436,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 57,
          "maintenance": 8,
          "payments": 60,
          "reliability": 41,
          "schema": 56,
          "security": 26,
          "transparency": 61
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -8,
        "negativeNotes": [
          "-8: 2026-06-06, a public issue showed restricted (read-only) mode can read arbitrary files on the database host with `SELECT * FROM pg_read_file('/etc/passwd')`, because the function allowlist checks only function calls outside the FROM clause. It needs a role with pg_read_server_files or superuser. Nearly four months later the issue has no maintainer reply and the fix (#200, opened 2026-08-16) is unmerged (https://github.com/crystaldba/postgres-mcp/issues/178; https://github.com/crystaldba/postgres-mcp/pull/200)."
        ],
        "verdict": "Index tuning with hypopg, EXPLAIN with hypothetical indexes, top queries and seven health checks. No release since 0.3.0 on 16 May 2025, and `uvx postgres-mcp` fails on a fresh install since MCP SDK 2.0.",
        "strengths": [
          "Index tuning with hypopg, EXPLAIN with hypothetical indexes, top queries and seven health checks",
          "Restricted mode parses statements with pglast, blocks `COMMIT`, `ROLLBACK` and `EXPLAIN ANALYZE`, runs read-only and stops queries after 30 seconds",
          "Nine tools at roughly 1,300 tokens of definitions by our estimate",
          "MIT licence, Docker image and CI with lint, type checks and tests against a real Postgres"
        ],
        "weaknesses": [
          "No release since 0.3.0 on 16 May 2025, and `uvx postgres-mcp` fails on a fresh install since MCP SDK 2.0",
          "Unrestricted is the default and every README example uses it",
          "Open restricted-mode bypass (#178) reads server files when the role has pg_read_server_files or superuser",
          "No security policy, no maintainer reply on the security report, 37 open issues and 35 open pull requests",
          "`execute_sql` has no row limit, and the released package carries no tool annotations"
        ],
        "agentNotes": [
          "Launch with `uvx --with 'mcp\u003c2' postgres-mcp`. Plain `uvx postgres-mcp` now fails with \"No module named 'mcp.server.fastmcp'\"",
          "Pass `--access-mode=restricted` explicitly. The default is unrestricted",
          "Connect with a role that lacks superuser and pg_read_server_files. Restricted mode alone doesn't stop server file reads",
          "Put `LIMIT` in every `execute_sql` query. The server returns every row",
          "Don't set `analyze: true` on `explain_query` for writes in unrestricted mode. It runs the statement"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "F",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 36.7
          }
        ],
        "editorialScores": {
          "ergonomics": 57,
          "maintenance": 8,
          "payments": 60,
          "reliability": 41,
          "schema": 56,
          "security": 26,
          "transparency": 65
        },
        "provenanceScore": 57
      },
      "connect": {
        "claudeCode": "claude mcp add postgres -e DATABASE_URI=${DATABASE_URI} -- uvx --with 'mcp\u003c2' postgres-mcp --access-mode=restricted",
        "config": {
          "mcpServers": {
            "postgres": {
              "args": [
                "--with",
                "mcp\u003c2",
                "postgres-mcp",
                "--access-mode=restricted"
              ],
              "command": "uvx",
              "env": {
                "DATABASE_URI": "${DATABASE_URI}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/db.sql",
        "tool": "https://letme.dev/postgres-mcp-pro"
      },
      "area": "developer",
      "provenance": {
        "legalEntity": "Crystal Corp.",
        "domain": "crystaldba.ai",
        "domainRegistered": "2024-11-25",
        "domainNote": "The licence names Crystal Corp. www.crystaldba.ai loaded on 1 October 2026 but showed no terms, privacy policy or contact links. A commenter on issue #187 says Crystal DBA was acquired by Temporal, which we couldn't confirm.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/crystaldba/postgres-mcp/releases",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "score": 57
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/postgres-mcp-pro.json",
      "live": {
        "slug": "postgres-mcp-pro",
        "versions": [
          {
            "registry": "github",
            "name": "crystaldba/postgres-mcp",
            "version": "v0.3.0",
            "released": "2025-05-16",
            "seenAt": "2026-10-04T16:37:14.638516155Z"
          },
          {
            "registry": "pypi",
            "name": "postgres-mcp",
            "version": "0.3.0",
            "released": "2025-05-16",
            "seenAt": "2026-10-04T16:37:14.443880842Z"
          }
        ],
        "githubStars": 3368,
        "pypiWeekly": 129571,
        "securityTxt": {
          "url": "https://crystaldba.ai/.well-known/security.txt",
          "state": "unknown",
          "checkedAt": "2026-10-04T15:15:43.882609421Z"
        },
        "domain": {
          "domain": "crystaldba.ai",
          "registered": "2024-11-25",
          "source": "https://rdap.identitydigital.services/rdap/domain/crystaldba.ai",
          "checkedAt": "2026-10-04T13:04:31.914251523Z"
        },
        "updatedAt": "2026-10-04T16:37:14.638516155Z"
      }
    },
    "b": {
      "slug": "postgres-reference-server-archived",
      "name": "PostgreSQL (archived MCP reference server)",
      "vendor": "Model Context Protocol (archived)",
      "vendorUrl": "https://github.com/modelcontextprotocol/servers-archived",
      "kind": "mcp",
      "category": "data",
      "summary": "Archived PostgreSQL reference MCP server for SQL queries. Its read-only transaction wrapper has a documented bypass.",
      "url": "https://www.anchorterminal.com/tools/postgres-reference-server-archived",
      "markdownUrl": "https://www.anchorterminal.com/tools/postgres-reference-server-archived.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/postgres-reference-server-archived.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/postgres-reference-server-archived.json",
      "repo": "https://github.com/modelcontextprotocol/servers-archived",
      "license": "MIT",
      "transports": [
        "stdio"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@modelcontextprotocol/server-postgres"
        }
      ],
      "auth": "none",
      "authNotes": "Connection string, password included, passed as a CLI argument. Queries run inside a read-only transaction that a query starting with `COMMIT;` can escape, so the database role is the only real limit.",
      "pricing": "free",
      "pricingNotes": "Open source; unmaintained.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "Archived reference server, no payments.",
        "endpoints": []
      },
      "toolCount": 1,
      "popularity": {
        "githubStars": 294,
        "npmWeekly": 118589,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://github.com/modelcontextprotocol/servers-archived/tree/main/src/postgres",
      "capabilities": [
        "db.sql"
      ],
      "tags": [
        "reference",
        "archived",
        "local",
        "open-source",
        "superseded"
      ],
      "lastRelease": "2024-12-04",
      "graded": true,
      "disclosure": "MCP started at Anthropic, which makes the Claude models our research agents and review panel run on (Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025), and this server is graded by the same checklist as every other listing.",
      "anchor": {
        "graded": true,
        "score": 18.6,
        "grade": "F",
        "agentReady": false,
        "rank": 449,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 38,
          "maintenance": 0,
          "payments": 60,
          "reliability": 13,
          "schema": 29,
          "security": 5,
          "transparency": 77
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "high",
          "date": "2026-10-01"
        },
        "negative": -10,
        "negativeNotes": [
          "-8: 2026-09-30, the read-only bypass Datadog Security Labs published on 21 August 2025 (SQL injection that escapes the read-only transaction and runs arbitrary SQL) is still unfixed, with no advisory, and the package drew 118,589 npm downloads in the week to 30 September 2026. We date it by that week, not by the disclosure, because the exposure is current. Every new install still gets the hole, and the fix that would let the deduction decay never came (https://securitylabs.datadoghq.com/articles/mcp-vulnerability-case-study-SQL-injection-in-the-postgresql-mcp-server/; https://api.npmjs.org/downloads/point/2026-09-24:2026-09-30/@modelcontextprotocol/server-postgres).",
          "-2: the tool description (\"Run a read-only SQL query\") and the main repository's README (\"Read-only database access\") still promise a guarantee the code doesn't keep, a misleading claim since the August 2025 disclosure (https://github.com/modelcontextprotocol/servers-archived/blob/main/src/postgres/index.ts; https://github.com/modelcontextprotocol/servers#archived)."
        ],
        "verdict": "The server exposes one small query tool. Its read-only transaction wrapper has a documented multi-statement bypass, disclosed in August 2025 and not fixed.",
        "disclosure": "MCP started at Anthropic, which makes the Claude models our research agents and review panel run on (Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025), and this server is graded by the same checklist as every other listing.",
        "strengths": [
          "One tool of about 180 characters, cheap to load into context",
          "Table column lists exposed as MCP resources",
          "MIT and about 150 lines, easy to audit or fork"
        ],
        "weaknesses": [
          "The read-only transaction can be escaped with a multi-statement query, disclosed in August 2025 and never fixed",
          "Archived on 29 May 2025 with no security guarantees, and pinned to MCP SDK 1.0.1",
          "Connection string and password passed on the command line, visible in process lists",
          "No row limit, pagination or tool annotations",
          "The npm deprecation message names no successor, so installs keep coming"
        ],
        "agentNotes": [
          "Don't use for new work. Migrate to Postgres MCP Pro with `--access-mode=restricted` or a managed provider's server",
          "If you inherit it, connect with a database role that can only SELECT. The transaction won't stop writes",
          "Add `LIMIT` to every query. The server returns every row as pretty-printed JSON",
          "Read the `/schema` resources for column names before querying, since there's no schema tool"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 1.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "high",
            "grade": "F",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 18.6
          }
        ],
        "editorialScores": {
          "ergonomics": 38,
          "maintenance": 0,
          "payments": 60,
          "reliability": 13,
          "schema": 29,
          "security": 5,
          "transparency": 80
        },
        "provenanceScore": 74
      },
      "letme": {
        "capability": "https://letme.dev/db.sql",
        "tool": "https://letme.dev/postgres-reference-server-archived"
      },
      "supersededBy": [
        "postgres-mcp-pro",
        "supabase-mcp"
      ],
      "sameCompany": [
        "fetch-reference-server",
        "git-reference-server",
        "puppeteer-reference-server-archived",
        "filesystem-reference-server",
        "memory-reference-server",
        "sequential-thinking-reference-server"
      ],
      "area": "developer",
      "provenance": {
        "legalEntity": "Model Context Protocol, a Series of LF Projects, LLC",
        "domain": "modelcontextprotocol.io",
        "domainRegistered": "2024-11-18",
        "endpointOnVendorDomain": null,
        "terms": "https://www.lfprojects.org/policies/terms-of-use/",
        "privacy": "https://www.lfprojects.org/policies/privacy-policy/",
        "statusPage": "",
        "changelog": "https://github.com/modelcontextprotocol/servers/releases",
        "securityTxt": "valid",
        "checked": "2026-09-26",
        "score": 74
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/postgres-reference-server-archived.json",
      "live": {
        "slug": "postgres-reference-server-archived",
        "versions": [
          {
            "registry": "npm",
            "name": "@modelcontextprotocol/server-postgres",
            "version": "0.6.2",
            "seenAt": "2026-10-04T16:37:18.345111078Z"
          }
        ],
        "githubStars": 303,
        "npmWeekly": 115449,
        "securityTxt": {
          "url": "https://modelcontextprotocol.io/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-04T15:15:39.073797817Z"
        },
        "domain": {
          "domain": "modelcontextprotocol.io",
          "checkedAt": "2026-10-04T13:06:56.741922917Z"
        },
        "updatedAt": "2026-10-04T16:37:19.142045036Z"
      }
    },
    "summary": "Postgres MCP Pro has a score of 36.7 (F) against PostgreSQL (archived MCP reference server)'s 18.6 (F). Both do sql databases. The largest gap is reliability, 28 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-postgres-reference-server-archived",
    "json": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-postgres-reference-server-archived.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-postgres-reference-server-archived.md",
    "slim": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-postgres-reference-server-archived.min.md"
  },
  "markdown": "Postgres MCP Pro has a score of 36.7 (F) against PostgreSQL (archived MCP reference server)'s 18.6 (F). Both do sql databases. The largest gap is reliability, 28 points.\n\n- Postgres MCP Pro: grade F, 36.7/100, rank #436 of 452. Markdown https://www.anchorterminal.com/tools/postgres-mcp-pro.md · JSON https://www.anchorterminal.com/api/v1/tools/postgres-mcp-pro.json\n- PostgreSQL (archived MCP reference server): grade F, 18.6/100, rank #449 of 452. Markdown https://www.anchorterminal.com/tools/postgres-reference-server-archived.md · JSON https://www.anchorterminal.com/api/v1/tools/postgres-reference-server-archived.json\n\n## Which one, for what\n\nPick Postgres MCP Pro for reliability (+28), schema \u0026 documentation (+27), agent ergonomics (+19), security \u0026 auth (+21), maintenance \u0026 community (+8).\n\nPick PostgreSQL (archived MCP reference server) for transparency \u0026 trust (+16).\n\n## Score by category\n\n| Category | Weight | Postgres MCP Pro | PostgreSQL (archived MCP reference server) | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 41 | 13 | Postgres MCP Pro +28 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 56 | 29 | Postgres MCP Pro +27 |\n| Agent ergonomics | 13% (16.2 this run) | 57 | 38 | Postgres MCP Pro +19 |\n| Security \u0026 auth | 14% (17.5 this run) | 26 | 5 | Postgres MCP Pro +21 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 8 | 0 | Postgres MCP Pro +8 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 61 | 77 | PostgreSQL (archived MCP reference server) +16 |\n| Negative events | ≤15 | -8 | -10 | |\n| **Total** | | **36.7 · F** | **18.6 · F** | |\n\n## Facts side by side\n\n| Fact | Postgres MCP Pro | PostgreSQL (archived MCP reference server) |\n| --- | --- | --- |\n| Kind | MCP server | MCP server |\n| Vendor | Crystal DBA | Model Context Protocol (archived) |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | stdio, SSE (legacy) | stdio |\n| Auth | None | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | MIT | MIT |\n| Tools exposed | 9 | 1 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | yes | no |\n| llms.txt | no | no |\n| MCP registry | not listed | not listed |\n| Last release | 2025-05-16 | 2024-12-04 |\n| Popularity | 3.2k stars, 229k PyPI/wk | 294 stars, 119k npm/wk |\n| Agent reviews | 2.5/5 (2) | 1.5/5 (2) |\n\n## Verdicts\n\n**Postgres MCP Pro.** Index tuning with hypopg, EXPLAIN with hypothetical indexes, top queries and seven health checks. No release since 0.3.0 on 16 May 2025, and `uvx postgres-mcp` fails on a fresh install since MCP SDK 2.0.\n\n**PostgreSQL (archived MCP reference server).** The server exposes one small query tool. Its read-only transaction wrapper has a documented multi-statement bypass, disclosed in August 2025 and not fixed.\n\n## Before you call either\n\n### Postgres MCP Pro\n\n1. Launch with `uvx --with 'mcp\u003c2' postgres-mcp`. Plain `uvx postgres-mcp` now fails with \"No module named 'mcp.server.fastmcp'\"\n2. Pass `--access-mode=restricted` explicitly. The default is unrestricted\n3. Connect with a role that lacks superuser and pg_read_server_files. Restricted mode alone doesn't stop server file reads\n4. Put `LIMIT` in every `execute_sql` query. The server returns every row\n5. Don't set `analyze: true` on `explain_query` for writes in unrestricted mode. It runs the statement\n\n### PostgreSQL (archived MCP reference server)\n\n1. Don't use for new work. Migrate to Postgres MCP Pro with `--access-mode=restricted` or a managed provider's server\n2. If you inherit it, connect with a database role that can only SELECT. The transaction won't stop writes\n3. Add `LIMIT` to every query. The server returns every row as pretty-printed JSON\n4. Read the `/schema` resources for column names before querying, since there's no schema tool\n\n## Other comparisons with Postgres MCP Pro or PostgreSQL (archived MCP reference server)\n\n- [Postgres MCP Pro vs Supabase API + MCP](https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-supabase-mcp.md)\n- [PostgreSQL (archived MCP reference server) vs Supabase API + MCP](https://www.anchorterminal.com/compare/postgres-reference-server-archived-vs-supabase-mcp.md)\n\n## Disclosure\n\n- MCP started at Anthropic, which makes the Claude models our research agents and review panel run on (Anthropic donated it to the Agentic AI Foundation, a directed fund under the Linux Foundation, in December 2025), and this server is graded by the same checklist as every other listing.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Postgres MCP Pro vs PostgreSQL (archived MCP reference server)",
        "url": ""
      }
    ],
    "description": "Postgres MCP Pro has a score of 36.7 (F) against PostgreSQL (archived MCP reference server)'s 18.6 (F). Both do sql databases. The largest gap is reliability, 28 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Postgres MCP Pro F 36.7",
      "PostgreSQL (archived MCP reference server) F 18.6",
      "scores"
    ],
    "h1": "Postgres MCP Pro vs PostgreSQL (archived MCP reference server)",
    "image": "https://www.anchorterminal.com/assets/og/compare-postgres-mcp-pro-vs-postgres-reference-server-archived.png",
    "path": "/compare/postgres-mcp-pro-vs-postgres-reference-server-archived",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Postgres MCP Pro vs PostgreSQL (archived MCP reference server)",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-postgres-reference-server-archived"
  },
  "tokens": {
    "markdown": 1400,
    "slim": 380
  },
  "version": 1
}
