major labs
Open data · Registry

The MCP registry, scored

Every public registry ranks MCP servers by stars and recency. Neither tells you whether a server is maintained, documented, licensed, or safe to wire into an agent. This one scores the signals that matter, on a method anyone can check, refreshed with every weekly sweep.

Praise-only, on purpose

The score is built from positive, publicly-derivable signals. Security and identity appear only as earned badges: a clean sweep gets named and credited; findings go to maintainers through coordinated disclosure, never into this list. A missing badge is deliberately ambiguous — not yet swept, not applicable, or in disclosure — because a static heuristic does not earn the right to put a warning label on someone's work. Good actors get named. Target lists do not get made.

Loading the registry…

The score, in the open

maintained25pushed within 90 days for full marks, 180 for partial
documented15a real README, not a stub
licensed10OSI license for full marks, any license for partial
adoption20GitHub stars, banded (downloads are package-level and not yet repo-linked, so stars stand in)
transport declared10the repo makes clear how it runs (stdio, HTTP, both)
identity layer ✓+10 badgea visible auth signal in source, from the weekly identity sweep
clean sweep ✓+10 badgeno risky pattern in the weekly security sweep

Score out of 100: 80 from the base signals, 20 from the two badges. Every input is public and the sweeps are open source — check the method at mcp-scanner. Maintainers: ship auth and pass Surface Check and your score rises on the next sweep. That is the point.