MCP Security Intelligence · Live ecosystem evidence

MCP security landscape: what is verified, vulnerable, and still unknown

The MCP ecosystem is expanding faster than runtime evidence. This living report separates canonical inventory, scanned implementations, completed current-version verification, proven vulnerabilities, verified-clean results, and the untested remainder.

Production snapshot · 71,584 active listings resolved into 71,565 canonical MCP implementations
71,565canonical MCPs
8,593MCPs scanned
8,402current versions verified
508current versions vulnerable

The MCP security evidence gap

Runtime scans have covered 12.0% of canonical MCP implementations. Completed evidence for the selected current version covers 11.7%. Those are different measures: historical scanning does not guarantee that the release selected today has completed evidence.

63,163 current security states remain unknown. Unknown is not clean, vulnerable, or safe. It means exact-current-version proof evidence is not publicly complete.

Current evidence states

8,593implementations scanned across 9,298 retained versions
7,894selected current versions with completed clean results
508selected current versions with at least one proven finding
63,163canonical MCPs awaiting a current scan

What “proven vulnerable” means

A current version is counted as vulnerable only when the proof engine completes the required evidence flow for that exact selected version and retains at least one publishable proven finding. The result describes the tested method and deployment context; it does not automatically prove remote exploitability, vendor ownership, bounty eligibility, or identical behavior in every installation.

Exact-version boundary: results from an older release are historical evidence. They do not make a newer current version clean or vulnerable.

What “verified clean” means

Verified clean means the completed current-version run did not prove a vulnerability using the scanner methods exercised in that run. It does not prove the absence of every possible vulnerability, configuration error, credential exposure, malicious behavior, or cross-MCP attack path.

Remote MCP exposure

The catalog currently links 5,032 MCPs to remote endpoints. Bounded observation has reached 4,445 of them; 1,439 require authentication, 2,860 have unhealthy outcomes, and 1,135 are blocked by observation policy. Availability and authentication outcomes are not vulnerability verdicts.

Where verification has the highest value

  1. MCPs enabled in a real organization or agent environment.
  2. Servers exposing write, destructive, execution, credential, or open-world authority.
  3. Remote services whose ownership or behavior can change independently of a package release.
  4. Packages with unresolved publisher attribution or conflicting distribution coordinates.
  5. New versions that materially change observed tools or authority.

Methodology and limitations

The public catalog joins canonical identity, package version, protocol discovery, remote observation, and proof-engine results. Embargoed evidence is excluded and must remain indistinguishable from unscanned public inventory. Rates describe the observed population and must not be projected onto unknown MCPs.

Investigate the evidence

Review current verification records, vulnerable MCPs, and attack paths formed between separate servers.

Completed verificationVulnerable MCPsCross-MCP attacks

Let’s talk about MCP security.

Share your details and our security team will contact you.