— THE NUMBERS

The MCP ecosystem, measured.

We track 39,374 MCP servers, agent skills and plugins. 14,419 carry a score, 7,862 have been scanned for advisories at the version you would install today, and 74% of those ship with no build provenance.

Every figure on this page is a count of rows, recomputed nightly and derived from public evidence. Nothing here is behind the paywall — a fact you have to pay for is a fact nobody repeats. How we measure · What changed recently

What is measured

39,374
capabilities tracked Every MCP server, agent skill and plugin we have discovered, measured or not.
14,419
carry a tashan score Enough public evidence to rank on upkeep, freshness and real adoption.
7,862
scanned for advisories Queried against OSV.dev at the version you would install today, so a finding means the current release is affected.
3,969
graded on how well they document themselves Read against a published, conjunctive rubric rather than a feeling.

What the ecosystem looks like

727
are deprecated, archived or abandoned Their publisher, npm or the registry says to stop using them.
7,652
have a single primary maintainer One person away from unmaintained. Not a fault, but a fact worth knowing before you depend on it.
490
run a script on your machine at install time A postinstall or preinstall hook — code that runs before you have agreed to anything.
74%
of scanned packages ship with NO build provenance npm signs every tarball it hosts, so a signature proves nothing about who built it. Only a build attestation ties the artifact to its source.
6
are in OSV's malicious-packages database Not a vulnerability — the package IS the attack. They are refused a place on every ranking and kept reachable only so a tool can warn someone already running one.

Coverage, weighted by demand

The aggregate ratio falls every time discovery succeeds — finding a thousand new capabilities makes the fraction we have measured smaller while nothing has got worse. So it is reported and never targeted. What we commit to is the demand curve, because what costs a reader is an absence on the thing they looked up, not a gap in the tail.

100%
of the top 100 by adoption are scanned for advisories
92%
carry a score
67%
are graded on documentation

The record behind it

229,279 measurements across 17 days. That series cannot be backfilled by anyone, including us — you cannot know what a score was in June unless you measured it in June — which is why what changed is a page nobody else can publish.

Cite this

Published under CC BY 4.0. Quote any number here, with attribution. If you are writing about which MCP server to use, these are the figures behind the rankings — and llms.txt is the machine version.

tashan, “The MCP ecosystem, measured” (2026-08-16): 39,374 capabilities tracked, 7,862 scanned against OSV at the installable version. https://tashan.sh/stats — CC BY 4.0.