The MCP registry, scored
Every public registry ranks MCP servers by stars and recency. Neither tells you whether a server is maintained, documented, licensed, or safe to wire into an agent. This one scores the signals that matter, on a method anyone can check, refreshed with every weekly sweep.
Praise-only, on purpose
The score is built from positive, publicly-derivable signals. Security and identity appear only as earned badges: a clean sweep gets named and credited; findings go to maintainers through coordinated disclosure, never into this list. A missing badge is deliberately ambiguous — not yet swept, not applicable, or in disclosure — because a static heuristic does not earn the right to put a warning label on someone's work. Good actors get named. Target lists do not get made.
Loading the registry…
The score, in the open
| maintained | 25 | pushed within 90 days for full marks, 180 for partial |
| documented | 15 | a real README, not a stub |
| licensed | 10 | OSI license for full marks, any license for partial |
| adoption | 20 | GitHub stars, banded (downloads are package-level and not yet repo-linked, so stars stand in) |
| transport declared | 10 | the repo makes clear how it runs (stdio, HTTP, both) |
| identity layer ✓ | +10 badge | a visible auth signal in source, from the weekly identity sweep |
| clean sweep ✓ | +10 badge | no risky pattern in the weekly security sweep |
Score out of 100: 80 from the base signals, 20 from the two badges. Every input is public and the sweeps are open source — check the method at mcp-scanner. Maintainers: ship auth and pass Surface Check and your score rises on the next sweep. That is the point.