Astrix Security

9 STATS1 REPORTS

All Statistics

Over 16,000 MCP servers are indexed by unofficial registries such as mcp.so.

Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context Protocol

79% of API keys found in open-source MCP server implementations are passed via simple environment variables.

Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context ProtocolAPI keys

There are a total of 20,000 MCP server implementations on GitHub.

Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context ProtocolGitHub

Unofficial marketplaces have indexed upwards of 17,000 open-source Model Context Protocol (MCP) server implementations.

Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context Protocol

8.5% of open-source Model Context Protocol (MCP) server implementations adopt modern and secure authentication methods, such as OAuth.

Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context ProtocolAuthenticationOAuth

88% of open-source Model Context Protocol (MCP) server implementations require credentials.

Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context ProtocolCredentials

53% of open-source Model Context Protocol (MCP) server implementations rely on insecure, long-lived static secrets, such as API keys and Personal Access Tokens (PATs).

Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context ProtocolSecretsAPI keysPATs

There was a 30% drop between the total number of repositories downloaded and those implementing real open-source Model Context Protocol (MCP) servers.

Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context Protocol

There are an estimated 20,000 repositories in GitHub implementing open-source Model Context Protocol (MCP) servers.

Astrix SecurityState of MCP Server Security 2025: 5,200 Servers, Credential Risks, and an Open-Source Fix·Oct 15, 2025
Model Context ProtocolGitHub