Most Secure
This leaderboard ranks MCP servers by their security analysis score — one of three dimensions in the SpiderScore model. The security score starts at 10.0 and decreases with each finding from our 46-rule static analyzer, which covers command injection, path traversal, SQL injection, SSRF, prompt injection, credential exposure, data exfiltration, and prototype pollution. Critical findings (reverse shells, credential theft) trigger hard constraints that force a grade cap regardless of other scores.
Across the ecosystem, the average security score is 7.29/10 — relatively healthy compared to description quality (3.94/10). However, 71.1% of servers lack sandbox configuration, the single most common security gap. A score of 10.0 means "zero issues found", not "proven secure" — static analysis has inherent limitations. See our methodology for details, or browse high-risk servers that need attention.
62 of 62 tools