HODOR

MCP Safety Index

A security score for every MCP you connect.

An independent ranking of official MCP servers — hosted and local — scored on security, compliance, and protocol fidelity, so you know what you're really plugging your agents into before you connect it.

Two transports, one question: how much do you expose by connecting it. Hosted and local servers are scored on the same scale — each measured for what it can actually do wrong.

Security

Token/credential handling, authz enforcement, data over-sharing, and supply-chain integrity — how much damage a single tool call, or a single install, can do.

OWASP MCP Top 10 · 5 measured live + 5 LLM-assessed, cited · Hosted: scope creep & over-sharing · Local: package integrity & process blast radius

Access & credentials

How access is granted and the credential is protected — and what it can reach if it leaks.

Hosted: OAuth 2.1 + RFC 8707/9728/7591/7636/9207, walked live · Local: secret storage (keychain vs plaintext env) & blast radius under your user

Protocol fidelity

How faithfully the server implements the spec — capabilities, tool schemas, errors, transport — judged for today and for the July release.

MCP 2025-06-18 & the 2026-07-28 RC · official conformance suite, run as an authorized client (HTTP or stdio)

Get an MCP scored

Want your MCP server in the index?

Drop the server URL and your email — we'll run it through the rubric and send you the results.

Ranking

ServerSecurityAuthProtocol · 2025-06-18Overall
1

Productboard

https://mcp.productboard.com/mcp

Hosted MCP ServerOAuth
82
88
91
87B
2

ElevenLabs

local:elevenlabs-mcp

Local · stdioAPI key
76
81
91
83B
3

Honeycomb

https://mcp.honeycomb.io/mcp

Hosted MCP ServerOAuth
75
79
94
83B
4

Airtable

https://mcp.airtable.com/mcp

Hosted MCP ServerOAuth
76
81
88
82B
5

Apify

https://mcp.apify.com

Hosted MCP ServerOAuth
72
75
97
81B
6

Make

https://mcp.make.com

Hosted MCP ServerOAuth
72
81
91
81B
7

Mixpanel

https://mcp.mixpanel.com/mcp

Hosted MCP ServerOAuth
75
78
91
81B
8

Stripe

https://mcp.stripe.com

Hosted MCP ServerOAuth
75
75
94
81B
9

Attio

https://mcp.attio.com/mcp

Hosted MCP ServerOAuth
81
82
77
80B
10

Calendly

https://mcp.calendly.com

Hosted MCP ServerOAuth
76
76
88
80B
110 of 55
1 / 6