Registry Landscape
The MCP ecosystem is fragmented across 9+ registries. No single source has complete coverage or security scanning.
| Registry | Servers | API | Publishing | Hosting | Search | Security | Versioning | Auth |
|---|---|---|---|---|---|---|---|---|
| Cursor Directory https://cursor.directory | 500 | None | ||||||
| GitHub (search) https://github.com | 3,200 | OAuth | ||||||
| Glama https://glama.ai | 23,900 | None | ||||||
| MCP.so https://mcp.so | 21,164 | None | ||||||
| npm https://www.npmjs.com | 400 | None | ||||||
| Official MCP Registry https://registry.modelcontextprotocol.io | 600 | None | ||||||
| PulseMCP https://pulsemcp.com | 15,440 | API Key | ||||||
| PyPI https://pypi.org | 200 | None | ||||||
| Smithery https://smithery.ai | 7,200 | Bearer |
Registry Profiles
Curated directory for Cursor IDE focused on developer productivity servers.
No security scanning. Curation provides some quality filtering but no formal security review.
GitHub is where most MCP servers are published, but it is not a curated discovery surface — we index by topic search and repo metadata, not editorial inclusion.
Dependabot and CodeQL available but not MCP-aware. No annotation verification or trust scoring.
Largest registry by count. Offers MCP server for querying its own registry.
No security scanning. No verification. No trust scoring. Quantity over quality.
Scraping-based aggregator indexing servers from GitHub, npm, and other sources.
No API
Node.js package registry increasingly used for MCP server distribution.
npm audit for dependency vulnerabilities. Sigstore provenance attestations for build verification. No MCP-specific scanning.
The canonical registry from the MCP specification authors at modelcontextprotocol.io. Delegates security scanning to subregistries — Ultra Ledger is that subregistry.
No scanning. No verification. No signing. Security is explicitly out of scope — the spec says subregistries handle it.
Community-curated registry with editorial approach and visitor analytics.
No automated scanning. Editorial curation provides some quality signal but no formal security assessment.
Python package index with growing MCP server ecosystem.
Trusted Publishers for verified uploads. Sigstore attestations. Malware detection via automated scanning. No MCP-specific analysis.
Largest independent MCP registry with hosted deployment and semantic search.
No security scanning or vulnerability checking. No annotation verification. Servers are accepted without security review.