MCPSafe.io
RegistryThreatsMethodologyDocsPricingScanSign in
MCPSafe.io

Security checks for MCP servers — public packages and private repos, fast or deep.

Legal

Privacy PolicyCookie PolicyTerms of ServiceSecurity disclosure

Resources

State of MCP SecuritySupportSystem statusMade in Germany 🇩🇪

© 2026 MCPSafe. All rights reserved.

GDPR — Privacy Policy

Public dashboard · Last refresh 4d ago

The State of MCP Security

Live numbers from MCPSafe’s scan cache. Updated every few minutes as new servers are scanned.

Packages scanned

6

Graded A or B

4

67% of catalog

Graded D or F

1

17% of catalog

Total findings

13

across latest scans

Grade distribution

6
  • A1(17%)
  • B3(50%)
  • C1(17%)
  • D0(0%)
  • F1(17%)

Top finding categories

  • verbose errors
    8
  • server configuration
    2
  • readiness
    1
  • data exfiltration
    1
  • resource exhaustion
    1

Top MCP packages

Most popular

Ranked by GitHub stars.

  1. 1.Bpunkpeye/awesome-mcp-servers90,647 ★
  2. 2.Cgithub:github/github-mcp-server@1add5fe2310430,137 ★
  3. 3.Dgithub:modelcontextprotocol/python-sdk@e8e64842781c23,113 ★
  4. 4.Btadata-org/fastapi_mcp11,939 ★
  5. 5.Dgithub:LaurieWired/GhidraMCP@27f316f801398,965 ★
  6. 6.Bwong2/awesome-mcp-servers4,203 ★
  7. 7.Dcloudflare/mcp-server-cloudflare3,935 ★
  8. 8.Cgithub:bethington/ghidra-mcp@de5f9ac9c8be2,946 ★
  9. 9.Bgithub:GongRzhe/Office-Word-MCP-Server@a3bbbb6d61672,111 ★
  10. 10.BGongRzhe/Office-Word-MCP-Server2,096 ★

Highest rated

A-graded packages, ranked by safety score.

  1. 1.Avercel-labs/mcp-for-next.jsscore 96

By package source

How the catalog splits across npm, PyPI, GitHub, and Docker Hub — and which source ships the safest MCP servers on average.

npm

67%

4

scanned

Avg score
88
Graded A/B
4 (100%)
Graded D/F
0
Findings
3

PyPI

17%

1

scanned

Avg score
80
Graded A/B
0 (0%)
Graded D/F
0
Findings
10

GitHub

17%

1

scanned

Avg score
0
Graded A/B
0 (0%)
Graded D/F
1
Findings
0

Top publishers

  • truongbuinh
    1

Subscribe

Get the monthly State of MCP Security in your inbox.

One email per month. Quotable stats, new threat patterns, and the packages worth watching. Unsubscribe anytime.

Share:X / TwitterLinkedIn

How these numbers are built

  • Every counter is derived from the most recent scan of each package in our cache. Older scans do not double-count.
  • Grade distribution uses the same A–F scale shown on the scan report. See /threats for the detection categories behind each finding.
  • Top publishers are inferred from GitHub package URLs (the owner in github.com/owner/repo). Packages from npm, PyPI, and Docker don’t count here today.
  • Browse the full catalog from the registry.

Frequently asked

What is an MCP server?+
Model Context Protocol (MCP) servers expose tools, resources, and prompts to AI agents. They sit between an LLM and an underlying system — your filesystem, a database, an API — and execute privileged actions on the agent's behalf, which makes their security profile materially different from a typical web service.
Where does this data come from?+
Every counter is derived from the most recent MCPSafe scan of each public MCP server in our cache. Older scans don't double-count. Findings are produced by the same rule engine that powers individual scan reports — see our methodology page for the rubric.
How is the safety grade calculated?+
Each server gets a 0-100 safety score that combines static analysis findings, supply-chain signals (typosquatting, CVEs), permission and network posture, and LLM-judged behavioral risks. Scores map to A through F bands. The full scoring rubric is published — we don't keep it secret.
How often is this dashboard updated?+
The dashboard re-reads its source-of-truth aggregate every few minutes. Individual server scans are re-run when their version changes, when a new rule ships, or on demand from the public registry.
Can I scan a private MCP server?+
Public scans are free and require no account. Private repository scanning is available on paid plans — see the pricing page for details.
Can I cite or embed this data?+
Yes — the dataset is intended to be quoted in research, blog posts, and security write-ups. Please link back to this page and credit MCPSafe. An embeddable widget for partner sites is on the roadmap.