Tools/MCP Server Trust Score

MCP Server Trust Score

Grade an MCP server A–F on maintenance health and adoptability — so you can choose between four servers that all claim to do the same thing.

A–F GRADE
Der RechnerPage 1
Shown for context. Deliberately contributes 0 points.
Blank scores neutrally (10/25) rather than assuming the best or worst.
TICK WHAT IS TRUE
The declared GitHub repo still existsDeleted or made private repos are a hard fail.
Ships a working install configFor Claude Desktop / Cursor / VS Code.
README documents the tools and credentialsWhat it exposes, and what it needs.
Listed in the official MCP registryA baseline signal, not a safety guarantee.
The package is deprecated by its authorTick if the author has marked it deprecated.
70/ 100
CUsable with caution
some-mcp-server · 1,200 ★ (not scored)
Grade bands: A ≥ 90 · B ≥ 78 · C ≥ 62 · D ≥ 45 · F below
Repository reachable30 / 30
Declared repository is reachable.
Maintenance10 / 25
Last commit date unknown — scored neutrally.
Package health15 / 15
Package not deprecated.
Install config15 / 15
Ships a usable install config.
Documentation0 / 10
Tool surface and credential requirements are undocumented.
Registry verified0 / 5
Not in the official registry (not fatal, but no baseline signal).
GradeScoreVerdictWhat it means in practice
A90–100safe to adoptReachable, maintained, installable and documented.
B78–89safe to adoptSound overall; one signal is weak.
C62–77usable with cautionWorks today, but something will bite you.
D45–61avoidStale or uninstallable — pick an alternative.
F0–44avoidDead, deprecated, or the repo is gone.
Data Source & Legal Disclaimer
Effective: Scoring model reviewed 2026-09
Sources: Two independent 2026 MCP ecosystem audits (registry liveness, package deprecation, commit recency)

This grades the signals you supply, not the code. A server can score A and still be insecure — use the MCP Server Security Audit for that. Absence of a repository or registry entry is not proof of malice, only of missing evidence.

See all data sources & update policy →
So funktioniert esPage 2

Half the MCP servers people are installing are dead

Two independent audits in 2026 converged on the same number: 52% of publicly listed MCP servers are dead or abandoned. The underlying registry data is blunter still — of 15,382 entries, 1,880 point to repositories that no longer exist, 218 packages have been deprecated by their own authors, and 299 have had no push in six months. This matters because MCP servers run inside your agent with your credentials; an abandoned server is not a neutral choice, it is an unpatched one. The trap is that the signal everyone reaches for first — star count — is the least reliable. A server with 300 stars and a commit last week is a better bet than one with 3,000 stars and nothing since 2024. So this scorer deliberately does not count stars: reachability, commit recency, deprecation status, installability and documentation are what actually predict whether the thing will work and keep working.

What the 100 points are actually made of
Repository reachable30Maintenance recency25Package not deprecated15Install config ships15Tools documented10In official registry5★ stars: intentionally 0 points — a misleading signal

Reachability and maintenance carry 55 of the 100 points between them, because those are what separate a working server from a dead one. Install config and documentation carry 25 more — a server nobody can install or understand is unusable no matter how healthy its repo is.

The popular server that scores D, and the obscure one that scores A

Two servers both claim to expose the same GitHub toolset. One has 3,000 stars but its last commit was 400 days ago and its npm package is deprecated. The other has 180 stars, a commit 12 days ago, a working install config and documented tools.

  1. Popular server:Reachable 30 + abandoned 0 + deprecated 0 + install 15 + docs 10 + registry 5 = 60 → grade D, avoid
  2. Obscure server:Reachable 30 + active 25 + not deprecated 15 + install 15 + docs 10 + registry 0 = 95 → grade A, safe to adopt
  3. Why stars lose:Stars measure past attention, not present maintenance — and they are trivially bought
  4. The hard gate:If the repo is gone, the score is 0 regardless of everything else
Joke of the Day
Sep 15

Why did the cow cross the road?

Free core, forever

Keep the Free Edition Free

No signups, no data sold. The core of every tool is free forever — the optional Pro plan adds batch processing, unlimited downloads, white-label exports and an ad-free experience.

Support me on Ko-fi— keep tools free

100% of proceeds go towards hosting & building more free tools.