Secure Your MCP Servers
MCPSafe is the security scanner and quality registry for Model Context Protocol servers. Registry metadata is live; public security findings are published only after review gates pass.
Trusted by the MCP Community
Live registry metadata and reviewed security intelligence for Model Context Protocol servers
Featured MCP Servers
Verified MCP server entries with live source metadata. Security scores return only after reviewed findings are enabled.
Findings MCPSafe Highlights
Public vulnerability claims stay behind review gates, but the homepage should still show the MCP-specific risk classes our scanner looks for.
Why MCPSafe?
Security analysis for MCP servers with reviewed-publication gates to avoid unverified claims.
Security Scanning
Deep analysis of MCP server code for vulnerabilities, unsafe patterns, and potential security risks.
Code Analysis
AST-based parsing to detect command injection, credential exposure, and dangerous API usage.
Trust Registry
Browse verified MCP servers with source, popularity, quality, freshness, and reviewed security data kept separate and readable.
Connect Your Agent in Seconds
One endpoint. Full security intelligence. Built for Claude, GPT, and any AI agent.
Quick Start — Get Service Info
No auth required. Your agent can discover all capabilities instantly.
Response:
{
"service": "MCPSafe",
"capabilities": ["scan_url", "get_report", "get_badge"],
"endpoints": {
"scan": "POST /api/v1/scans/url",
"badge": "GET /api/badge/{slug}.svg"
},
"free_tier": { "scans_per_month": "unlimited" }
}Instant Scans
Submit any GitHub URL, get security results in seconds
Security Badges
Embed trust badges for any scanned server
Full Registry
Query verified MCP servers with security and quality scores
Free public registry access and server scanning while the reviewed-security publication layer is finalized.
Everything You Need for MCP Security
From source-aware code analysis to readable registry cards, MCPSafe separates security, quality, usage, and freshness so users can understand why a server ranks where it does.
AST-Based Analysis
Tree-sitter powered parsing for JavaScript, TypeScript, and Python. Analyze code structure without executing it.
50+ Security Rules
Comprehensive rule set covering OWASP Top 10, command injection, path traversal, SSRF, and more.
Real-Time Scanning
Scan any MCP server in seconds. Submit a GitHub URL, npm package, or upload source code directly.
Vulnerability Details
Get detailed reports with code snippets, line numbers, CWE IDs, CVSS scores, and remediation guidance.
CI/CD Integration
GitHub Actions and CLI tools to automate security checks in your development workflow.
Security Alerts
Get notified when new vulnerabilities are discovered in servers you're watching.
API Access
Full REST API with OpenAPI documentation. Build custom integrations and workflows.
Multi-Factor Scoring
Separate security, MCP risk, supply-chain, quality, popularity, and freshness signals roll into a clear trust view without hiding the underlying data.
Registry Discovery
Browse the verified MCP registry, backed by live source checks and strict cleanup of non-server packages.
100% Free — No Limits
Every feature is free for everyone. Unlimited scans, full registry access, API access, webhooks, and more — no credit card required.
- Full registry access — all servers
- Unlimited security scans
- Detailed vulnerability reports
- Full API access
- Unlimited watchlist
- Webhook notifications
- CI/CD integration
- Email alerts
Ready to secure your MCP servers?
Everything is free — create an account and start scanning in seconds.