Skip to content

MCP reports · registry snapshot 2026-10-04

What’s in the MCP registry

Every entry in the official MCP registry, described along a few axes. Each axis says how many entries we could answer it for, how many we couldn’t and why, and how many it doesn’t apply to — an answer we couldn’t get is never counted as a value.

full count, not sampled · 38,977 entries · aggregate only, no server names

Profile

The registry, axis by axis

“Known” is a share of the entries the question applies to and that we could answer. “Not determined” includes our own limits, labelled as such. “Does not apply” and “not in scope” are facts about the entry (for example, a remote-only server ships no package to license), not gaps.

Topic

AI-classified

What is the server mainly for?

AI-classified. Produced by AI models with independent checks (a label is kept only when the checks agree); not hand-checked by a person. Read these figures as estimates. Measured against a blind AI reference (Claude Opus 5.5) on a seeded sample of 150: 82.5% agreement (113 of 137 labelled items; 95% range 75–88%), checked 2026-10-09. The 1,695 labels added afterwards by the Gemini + Claude consensus were not part of that measurement.

known
37,182 · 95.4% of applicable
not determined
1,795
does not apply
0
not in scope
0

all 38,977 entries · known for 95.4% of them

Topic: distribution, as a share of the 37,182 known
ValueShareEntries% of known
Data & databases5,72415.4%
Developer tools5,36714.4%
Finance & payments4,89713.2%
Commerce & marketing4,10511.0%
Search & web data3,2428.7%
Productivity & docs2,3926.4%
Security2,0755.6%
Media & design1,9955.4%
AI & ML1,4313.8%
Communication & social1,4113.8%
Science, health & education1,3883.7%
Other1,3673.7%
Cloud & DevOps1,3503.6%
IoT & hardware4381.2%
not determined: 1,795 — why
  • the two runs disagreed, and so did the Gemini + Claude tie-break — 1,795 (100.0%)
  • method: An LLM (gemini-2.5-flash) labels the registry name, title and description twice with differently worded prompts; a label is kept only when both runs agree. Where the two runs disagreed, Gemini and Claude each labelled the entry once more, and a label is kept only when those two agree (1,695 labels). Label list is provisional (provisional-1: 31,019, provisional-2: 6,163).
  • source registry.modelcontextprotocol.io — name, title, description
  • checked 2026-10-08 to 2026-10-09

Pricing model

AI-classified

How is the product on the server’s website priced?

AI-classified. Produced by AI models with independent checks (a label is kept only when the checks agree); not hand-checked by a person. Read these figures as estimates. Measured against a blind AI reference (Claude Opus 5.5) on a seeded sample of 150: 84.1% agreement (90 of 107 labelled items; 95% range 76–90%), checked 2026-10-09. The 22 labels added afterwards by the Gemini + Claude consensus were not part of that measurement.

known
8,064 · 39.7% of applicable
not determined
12,257 (1,719 our limit)
does not apply
0
not in scope
18,656

all 38,977 entries · known for 20.7% of them · not in scope: registry entry has no websiteUrl

Pricing model: distribution, as a share of the 8,064 known
ValueShareEntries% of known
Freemium (permanent free tier + paid plans)3,63145.0%
Usage-based (pay per call, credit or unit)2,71033.6%
Free94111.7%
Open source, no commercial plan stated4275.3%
Paid subscription3374.2%
Contact sales / quote on request180.2%
not determined: 12,257 — why
  • uncertain: answer held back by the quote check — 4,940 (40.3%)
  • pages read do not state pricing — 3,067 (25.0%)
  • website link is a code-hosting, package or marketplace page — 2,063 (16.8%)
  • our limit: site could not be fetched by a plain request (HTTP error, network, not HTML) — 920 (7.5%)
  • our limit: page is nearly empty without JavaScript (not re-read in a browser) — 710 (5.8%)
  • website is gone (HTTP 404/410) — 378 (3.1%)
  • our limit: model output unusable on every attempt — 89 (0.7%)
  • site’s robots.txt disallows reading (respected) — 74 (0.6%)
  • uncertain: the Gemini + Claude judges disagreed — 16 (0.1%)
  • method: The website named in the registry entry (and its pricing page when linked) is read with a plain request; robots.txt is honoured. An LLM (gemini-2.5-flash-lite: 7,671, gemini-2.5-flash: 337, gemini-3.5-flash-lite: 34) names the pricing model and quotes the page. An answer is kept only if the quote is found on the page, passes a rule check that those words can carry the value, and a second, independent call that sees only the quote reaches the same value; 531 answers from the first batches also needed two differently worded runs to agree (7,511 used one run plus these checks). 1,658 answers where the model said “freemium” but the quote shows only a free allowance plus metered credits are counted as usage-based, as the definition states. Every “contact sales” answer was judged again by Gemini and Claude; 22 answers kept from that pass are those where both agreed and the quote check passed.
  • source registry.modelcontextprotocol.io — websiteUrl
  • source the server’s own website — homepage and pricing page text
  • checked 2026-10-08 to 2026-10-09

Programming language

Which language is most of the linked GitHub repository written in?

known
18,804 · 77.6% of applicable
not determined
5,421
does not apply
14,752
not in scope
0

all 38,977 entries · known for 48.2% of them

Programming language: distribution, as a share of the 18,804 known
ValueShareEntries% of known
TypeScript8,33344.3%
Python5,00726.6%
JavaScript3,53918.8%
Go5292.8%
Rust4432.4%
HTML2621.4%
C#1560.8%
Shell1540.8%
Dockerfile880.5%
Java470.2%
Swift450.2%
PHP250.1%
41 other languages1760.9%
not determined: 5,421 — why
  • GitHub detects no source language (docs-only or empty repository) — 5,421 (100.0%)
does not apply: 14,752 — why
  • no readable GitHub repository (none linked, empty link, on GitLab, or not returned by GitHub) — 14,752 (100.0%)
  • method: GitHub’s /languages byte counts for the linked repository; the language with the most bytes. A repository can be a monorepo, so this describes the repository, not necessarily the server alone.
  • source api.github.com — GET /repos/{owner}/{repo}/languages
  • checked 2026-10-08

MCP capabilities

Which MCP features does the server advertise when we connect?

known
18,889 · 60.3% of applicable
not determined
12,423 (23 our limit)
does not apply
0
not in scope
7,665

all 38,977 entries · known for 48.5% of them · not in scope: no HTTP remote and no npm/PyPI package we can start

MCP capabilities: servers advertising each feature, as a share of the 18,889 known
FeatureShareEntries% of known
Tools18,87799.9%
Resources6,59934.9%
Prompts5,48929.1%
Experimental1,5918.4%
Logging1,1326.0%
Extensions4192.2%
Completions1790.9%
Tasks630.3%
(none advertised)30.0%

A server can advertise several features, so the rows add up to more than 100%.

known via the remote endpoint 14,123 · via the package 4,766 · servers whose remote and package advertise different features: 69 (the remote’s answer is shown)

not determined: 12,423 — why
  • could not connect or initialize (cause not determined; can be our launch environment) — 6,620 (53.3%)
  • requires authentication before listing anything — 3,970 (32.0%)
  • package not executable (no bin, shebang or entrypoint) — 993 (8.0%)
  • package crashes on a broken dependency — 817 (6.6%)
  • our limit: timed out — 23 (0.2%)
  • method: Read-only connection: initialize plus tools/list, resources/list and prompts/list — no tool is ever called. Remote servers over HTTP; npm/PyPI packages launched inside an E2B sandbox. A server can advertise several features, so rows add up to more than 100%.
  • source the server itself — MCP initialize result and list responses
  • checked 2026-10-08 to 2026-10-09

Known vulnerabilities in dependencies

What is the most severe published advisory anywhere in the resolved dependency tree of the listed version?

known
13,923 · 96.5% of applicable
not determined
508 (324 our limit)
does not apply
0
not in scope
24,546

all 38,977 entries · known for 35.7% of them · not in scope: not an npm or PyPI package

Known vulnerabilities in dependencies: distribution, as a share of the 13,923 known
ValueShareEntries% of known
Critical2111.5%
High1,0127.3%
Moderate2601.9%
Low330.2%
No known advisory12,40789.1%
npm · 10,174 of 10,401 known
Critical 1.1% · High 9.3% · Moderate 2.1% · Low 0.3% · No known advisory 87.2%
PyPI · 3,749 of 4,030 known
Critical 2.5% · High 1.8% · Moderate 1.3% · Low 0.1% · No known advisory 94.2%
not determined: 508 — why
  • our limit: dependency tree could not be resolved safely — 324 (63.8%)
  • package or listed version not found upstream — 179 (35.2%)
  • listed version is not an exact version — 5 (1.0%)
  • method: npm: the listed version’s tree resolved with npm install --package-lock-only --ignore-scripts, then npm audit. PyPI: tree resolved with uv pip compile --no-build (Python 3.12, Linux x86_64), then OSV.dev. Nothing from the package is executed.
  • source registry.npmjs.org — npm audit advisory database
  • source api.osv.dev — PyPI advisories (querybatch)
  • checked 2026-10-08 to 2026-10-09

License class

Is the package’s declared license permissive, copyleft or something else?

known
13,419 · 90.0% of applicable
not determined
1,483 (2 our limit)
does not apply
24,075
not in scope
0

all 38,977 entries · known for 34.4% of them

License class: distribution, as a share of the 13,419 known
ValueShareEntries% of known
Permissive12,36892.2%
Other identifier (not sorted)7565.6%
Copyleft2952.2%
not determined: 1,483 — why
  • license text present, not a usable SPDX identifier — 481 (32.4%)
  • declares no package — 471 (31.8%)
  • no license declared — 377 (25.4%)
  • package or listed version not found on npm/PyPI — 152 (10.2%)
  • our limit: package metadata unreachable — 2 (0.1%)
does not apply: 24,075 — why
  • remote-only: ships no package — 22,396 (93.0%)
  • package ecosystem not covered (oci, mcpb, cargo, nuget) — 1,679 (7.0%)
  • method: The SPDX identifier declared on npm/PyPI, sorted into permissive (MIT, Apache-2.0, BSD, ISC, …) or copyleft (GPL family, MPL, EPL, EUPL, CDDL); “other” is a real identifier we don’t sort, not a claim about OSI status.
  • source registry.npmjs.org — license
  • source pypi.org — license, license_expression, classifiers
  • checked 2026-10-06

Maintenance

How recently was the linked GitHub repository pushed to?

known
24,256 · 84.4% of applicable
not determined
4,487
does not apply
10,234
not in scope
0

all 38,977 entries · known for 62.2% of them

Maintenance: distribution, as a share of the 24,256 known
ValueShareEntries% of known
Active (push ≤ 90 days)20,07082.7%
Slowing (91–365 days)3,75215.5%
Archived3091.3%
Stale (> 365 days)1250.5%
not determined: 4,487 — why
  • repository link is dead (HTTP 404) — 4,298 (95.8%)
  • repository link empty or unreadable — 189 (4.2%)
does not apply: 10,234 — why
  • no repository link — 10,187 (99.5%)
  • repository on GitLab (not covered) — 47 (0.5%)
  • method: archived if GitHub marks it archived; otherwise active = a push within 90 days, slowing = 91–365 days, stale = over 365 days.
  • source api.github.com — GET /repos/{owner}/{repo} → archived, pushed_at
  • checked 2026-10-06

Where it runs

Does the server run on the vendor’s infrastructure, on your machine, or either?

known
38,506 · 98.8% of applicable
not determined
471
does not apply
0
not in scope
0

all 38,977 entries · known for 98.8% of them

Where it runs: distribution, as a share of the 38,506 known
ValueShareEntries% of known
Vendor’s infrastructure (remote)22,39658.2%
Your machine (package)14,18536.8%
Either (both offered)1,9255.0%
not determined: 471 — why
  • declares neither a package nor a remote — 471 (100.0%)
  • method: From the registry entry: a remote endpoint means it runs on the vendor’s infrastructure; a package means it runs on your machine; both means either. This says where it runs, not what it can reach or control.
  • source registry.modelcontextprotocol.io — remotes[], packages[]
  • checked 2026-10-06

Read this before quoting

What these numbers don’t say

  • No finding about any server. This page is aggregate only; it names no server, package or publisher.
  • A dependency advisory is not a confirmed vulnerability in the server. It means a published advisory matches some package in the listed version’s resolved dependency tree; whether the server is exploitable through it is not tested here.
  • “No known advisory” is not “secure”. It only means no published advisory matched at check time.
  • MCP features are what a server advertises when we connect read-only; we never call its tools.
  • Language describes the linked repository, which may hold more than the server.
  • “Where it runs” is not “what it can reach”. A package on your machine may still call remote services.

Full method: methodology. Mistakes we’ve caught: corrections log. The aggregate as JSON: data.json.