Scoring methodology

MCP Rank starts with manual and semi-automated review because trust data needs judgment. The automation pipeline is designed to gather signals, not pretend every risk can be reduced to a star count.

Weighted score categories

Install + docs

18%

Can a developer install it cleanly, understand prerequisites, and reproduce examples?

Maintenance

18%

Recent commits, releases, issue response, package health, and ownership clarity.

Auth handling

16%

OAuth or token scope handling, secret storage guidance, and write-action guardrails.

Client compatibility

16%

Evidence that the server works across Claude, Cursor, Codex, VS Code, and common transports.

Real usefulness

20%

Real workflows, concrete examples, community mentions, and repeated daily value.

Safety signals

12%

Permission surface, local or account data exposure, dependency risk, and abuse potential.

Status and confidence rules

Review depth gates rankings

Only Deep Review entries and listings with explicit Maintainer Verified evidence appear in leaderboards. Indexed, Source Reviewed, and Install Tested listings remain searchable but unranked.

Safest lists require confidence

Top trusted rankings require high confidence and exclude high-risk tools, even when the underlying server is useful.

Maintainer verified is stronger evidence

Maintainer verification means a real maintainer has claimed or confirmed the listing details. It is not inferred from an external directory and is not formal certification.

High risk can still be reviewed

Payments, chat, databases, browsers, and file systems can be valuable, but they need prominent cautions and rollout controls.

Data sources

MCP Rank indexes MCP servers from public registries, package metadata, directories, GitHub search, and maintainer submissions. Rankings are assigned only after Deep Review or explicit Maintainer Verified review depth.

External source metadata may come from Glama, the official MCP Registry, Smithery, package registries, or maintainer-submitted links. External scores or verification signals are not treated as MCP Rank scores.

  • Official MCP registry
  • Smithery
  • Glama and other MCP directories
  • GitHub search and repository metadata
  • npm and PyPI package metadata

Viable product path

  1. Normalize registry, Smithery, Glama, GitHub, npm, and PyPI candidates.
  2. Run reproducible install checks and collect client compatibility notes.
  3. Refresh GitHub stars and maintenance signals daily through Vercel Cron.
  4. Store scoring snapshots in Neon so every score change is explainable.
  5. Add side-by-side comparisons for install success, scopes, examples, and data exposure.
  6. Publish weekly reports that separate recommendation from raw popularity.

Independence disclaimer

MCP Rank is independent and not affiliated with Anthropic, OpenAI, GitHub, or the official MCP project. Scores are review signals, not certifications.