Over 16,000 MCP servers are indexed by unofficial registries such as mcp.so.
Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context Protocol
79% of API keys found in open-source MCP server implementations are passed via simple environment variables.
Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context ProtocolAPI keys
There are a total of 20,000 MCP server implementations on GitHub.
Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context ProtocolGitHub
Unofficial marketplaces have indexed upwards of 17,000 open-source Model Context Protocol (MCP) server implementations.
Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context Protocol
8.5% of open-source Model Context Protocol (MCP) server implementations adopt modern and secure authentication methods, such as OAuth.
Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context ProtocolAuthenticationOAuth
88% of open-source Model Context Protocol (MCP) server implementations require credentials.
Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context ProtocolCredentials
53% of open-source Model Context Protocol (MCP) server implementations rely on insecure, long-lived static secrets, such as API keys and Personal Access Tokens (PATs).
Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context ProtocolSecretsAPI keysPATs
There was a 30% drop between the total number of repositories downloaded and those implementing real open-source Model Context Protocol (MCP) servers.
Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context Protocol
There are an estimated 20,000 repositories in GitHub implementing open-source Model Context Protocol (MCP) servers.
Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025