Why trust this leaderboard?

Because the scoring rules, data sources and decision logic are all written on this page, and every server page notes its data sources and fetch time. No black box — you can re-check any score with the same public data.

👤Maintainer

MCP Radar is maintained by its editorial and data team. We collect public repository, package and registry signals to help readers investigate maintenance risk. TrustScore is a screening signal, not a security certification or a substitute for testing a server in your own environment.

— MCP Radar editorial team Research, data review and methodology

Scoring methodology (fully public)

TrustScore is out of 100, weighted across five dimensions, all signals from public APIs:

DimensionWeightSignal fields
Maintenance30%Days since last commit, commits in 90 days, share of recent issues with replies, whether archived
Adoption25%GitHub stars and trend (weighted above npm downloads), npm weekly download trend, release frequency
Usability20%Verified in the official registry, whether an installable package or remote endpoint is published, repository auditability
Health15%Open issue count and whether the repository declares a license
Community10%Contributor count and fork activity

Lifecycle rules

🟢 active

Normally maintained

🟡 dying

Last commit > 180 days AND no issue response AND no new release

⚰️ dead

Repo archived == true

unverifiable

Remote-only (no open-source repo / no package), unverifiable

"Has an auditable repo" is a usability bonus — a remote-only service can't have its behavior verified, which is itself a risk signal.

Data sources and limits

SourceFields providedKnown limits
MCP official registryManifest, repo url, package name, official status, publish/update timeNo stars / activity / downloads
GitHub APILast commit, commits in 90 days, recent issues with replies, archived, stars, forks, open issues, license, contributors
npm registryWeekly downloads, version release timelineUnderestimates servers installed directly from GitHub

Update frequency: health data is scanned incrementally daily, with a full diff weekly (the radar page's data source).

We flag our boundaries: remote-only servers have no repo signals and are always marked unverifiable; npm downloads underestimate servers installed directly from GitHub, so stars are weighted higher; fetching has lag, so a project that just resumed maintenance may still be briefly marked dying — which is exactly why we keep a correction channel open.

Conflict-of-interest disclosure

This site accepts sponsored detail-page placements (clearly labeled "Sponsored"), but rankings, scores and categories never accept bidding of any kind. Sponsorship buys placement, not a score. The moment we accept ranking bids, the credibility of our proprietary data collapses — that's the foundation of this site, not for sale.

See sponsorship rules →

Data correction / death-call appeal

Maintainer thinks a server's score or call is wrong (e.g. maintenance resumed, repo moved)? Send the repo URL and details; we review manually and update within 48 hours: wangknit@gmail.com