Skip to content

MCP reports · registry snapshot 2026-10-04

The MCP registry vs. reality

The official MCP registry checks a package once, at publish, and never re-checks it — and a few things it never checks at all. We compared every entry with what npm, PyPI and GitHub say today.

Context

What the registry checks today

Read from the registry’s source code at commit c384c4b on 2026-10-06:

  • At publish, it checks the exact listed version exists and that the package names the server — on npm and PyPI. This is on by default; whether production has ever turned it off can’t be seen from outside.
  • Nothing re-checks an entry after publish. There is no scheduled or periodic validation.
  • The repository link is checked for format only (a regex) — never opened.
  • The schema requires only a name, description and version — not a package and not a remote endpoint.
  • Upstream withdrawal (npm deprecation, PyPI yank) and archived repositories are not checked.

Findings

Where listings and reality disagree

All percentages share one base — all 38,977 entries, or all 23,016 publisher namespaces — so no row can exceed the total. An entry can appear in more than one row; “any of the below” counts it once.

MCP registry entries by mismatch, checked 2026-10-06
MismatchRegistry checkShare of entries% of all 38,977 entries% of all 23,016 publishers
Any of the below
5,435 entries · 3,169 publishers
13.9%13.8%
Repository link can’t be opened publicly
4,298 of 28,743 with a GitHub repository link · 15.0%
never checked11.0%11.3%
Listed version is withdrawn upstream
663 of 14,431 shipping an npm or PyPI package · 4.6%
never checked1.7%1.0%
Active, but declares no way to run it
459 of 38,977 in the registry · 1.2%
allowed by schema1.2%1.3%
Linked repository is archived
309 of 24,256 with a reachable GitHub repository · 1.3%
never checked0.8%0.6%
Listed version can’t be installed
157 of 14,431 shipping an npm or PyPI package · 1.1%
verified once0.4%0.5%

Detail

Each finding, with its source

Repository link can’t be opened publicly

never checked

GitHub returns HTTP 404 — the repository is missing or private; we can’t tell which. The registry checks the link’s format only, never that it opens.

entries
4,298 of 38,977 · 11.0%
publishers
2,594 of 23,016 · 11.3%
within its subset
4,298 of 28,743 · 15.0%

subset: entries with a GitHub repository link

  • source api.github.com — GET /repos/{owner}/{repo} → 404 · checked 2026-10-06
  • registry check: Not checked by the registry, at publish or afterwards.

Listed version is withdrawn upstream

never checked

Deprecated on npm or yanked on PyPI. The registry doesn’t check withdrawal status, and neither npm nor PyPI records when it happened.

entries
663 of 38,977 · 1.7%
publishers
226 of 23,016 · 1.0%
within its subset
663 of 14,431 · 4.6%

subset: entries shipping an npm or PyPI package

  • source registry.npmjs.org — listed version’s “deprecated” field · checked 2026-10-06
  • source pypi.org — listed release’s “yanked” flag · checked 2026-10-06
  • registry check: Not checked by the registry, at publish or afterwards.

Active, but declares no way to run it

allowed by schema

No packages and no remotes. The registry schema requires neither.

entries
459 of 38,977 · 1.2%
publishers
295 of 23,016 · 1.3%
within its subset
459 of 38,977 · 1.2%

subset: entries in the registry

  • source registry.modelcontextprotocol.io — status “active”, no packages[], no remotes[] · checked 2026-10-06
  • registry check: Permitted by the registry’s server.json schema.

Linked repository is archived

never checked

The GitHub repository behind the entry is archived (read-only). The registry doesn’t check this.

entries
309 of 38,977 · 0.8%
publishers
149 of 23,016 · 0.6%
within its subset
309 of 24,256 · 1.3%

subset: entries with a reachable GitHub repository

  • source api.github.com — GET /repos/{owner}/{repo} → “archived”: true · checked 2026-10-06
  • registry check: Not checked by the registry, at publish or afterwards.

Listed version can’t be installed

verified once

The listed package or exact version doesn’t exist on npm/PyPI. By default the registry checks the exact version exists at publish; all of these were published after that check was introduced.

entries
157 of 38,977 · 0.4%
publishers
124 of 23,016 · 0.5%
within its subset
157 of 14,431 · 1.1%

subset: entries shipping an npm or PyPI package

  • source registry.npmjs.org — package or listed version → 404 / no releases · checked 2026-10-06
  • source pypi.org — package or listed release → 404 / no releases · checked 2026-10-06
  • registry check: Checked by the registry at publish (by default), never re-checked.

Read this before quoting

What these numbers don’t say

  • This is not a security finding. It measures whether listings match upstream records, not whether any server is safe.
  • It isn’t a judgement of publishers. Upstream records change after an entry is published, and some of these checks were never part of publishing.
  • A 404 means missing or private. GitHub returns the same response for both, so we don’t distinguish them.
  • We can’t date withdrawals or archiving. npm, PyPI and GitHub don’t record when a version was deprecated or yanked or when a repository was archived, so we don’t say these happened “after” publish.
  • Counts are per entry and per publisher namespace. A few namespaces publish hundreds of entries; the publisher column stops them from dominating.
  • No names. This report is aggregate only. Pages for individual servers will follow, quoting only upstream facts, each with its source and date.

Full method: methodology. Mistakes we’ve caught, including before publishing: corrections log. The aggregate as JSON: data.json.

Get the next report

One email when a report or a correction is published.