Methodology
How we measure
Every figure on this site comes from a real request to a real source, on a stated date. If something wasn’t checked, we say so.
Rules we publish under
- Every fact names its source and the date we checked it.
- No sampling where a full count is possible. When we do sample, we say so and give a 95% confidence interval (Wilson).
- Missing data is never a finding. If a lookup failed on our side — a rate limit, a timeout — the value is marked as our limit, not as something the server lacks.
- Coverage is shown as a fraction with its cause (“tested 2 of 12 applicable”), never hidden inside a single score.
- Mistakes are logged in the corrections log, including ones caught before publishing.
The registry report
What counts as an entry
We paged the official registry API (registry.modelcontextprotocol.io/v0/servers) to the end on 2026-10-04: 131,427 version rows for 38,977 distinct server names. One entry is one server name at its latest version — the row the registry marks isLatest. A publisher is the namespace before the first “/” in the server name; there are 23,016.
Where each check comes from
- Registry fields (status, packages, remotes) — from the registry API itself.
- Package checks — npm (
registry.npmjs.org) and PyPI (pypi.orgJSON API), for the exact version the registry lists. Versions are compared with real semver (npm) and PEP 440 (PyPI) parsers; a version we can’t parse is “unknown”, never “current”. - Repository checks — the GitHub REST API (
api.github.com/repos/…), authenticated, paced to stay inside GitHub’s published limits.
All upstream checks for this report ran on 2026-10-06 (UTC).
Definitions
- Repository link can’t be opened publicly — the entry links a GitHub repository and the API returns 404. That means missing or private; GitHub doesn’t tell the two apart, and neither do we.
- Listed version is withdrawn upstream — the listed npm version carries a deprecation message, or the listed PyPI release is yanked.
- Active, but declares no way to run it — status
active, with neitherpackagesnorremotes. - Linked repository is archived — the GitHub API reports
archived: true. - Listed version can’t be installed — the package doesn’t exist, has no releases, or doesn’t have the listed version.
The “registry check” labels
Each finding is labelled by what the registry’s own validator does about it, read from its source code at commit c384c4b: verified once (checked at publish by default, never re-checked), never checked, or allowed by schema. Validation can be turned off with a setting that defaults to on; production’s actual setting isn’t visible from outside, so we say “by default”.
Same base for every row
Every percentage in the findings table is of all 38,977 entries (or all 23,016 publishers), so no single finding can look larger than the total. Each finding’s rate within its own subset — for example, of entries that link a GitHub repository — is shown beside it as context.
Runtime testing
Server pages will add results from running servers in an isolated sandbox against 18 test dimensions, using the official MCP SDK. Those results will be published with the same rules: every dimension is attempted, and each result says whether it was exercised, blocked (for example by a credential only the vendor has), or not applicable. There is no single numeric grade. We don’t probe servers we aren’t authorised to test.