In May 2026, a scan of 111,076 domains from the top 200k found no site running WebMCP in production. That sample is popular sites, which are the ones that would have to write an implementation themselves. Our crawl list covers 5,369,528 domains; we have fetched 5,369,482 of them so far and found 76,250 sites exposing tools to AI agents.
72,197 of them simply carry a tool set their platform distributes to them — Shopify to its storefronts, Cloudflare at the edge. Documented platform features, not vulnerabilities. 4,053 sites wrote their own, and between them those are 3,500 distinct implementations.
Reported as a single number, the total would be misleading. So we report it as two. Aggregate findings, methodology, and limitations below — free, no sign-up.
On 2026-08-06 Cloudflare shipped a one-switch WebMCP injection in developer preview, which requires no change at the origin. That is consistent with what we measure, and it is the second instance of it: when WebMCP spreads, it spreads because infrastructure ships a switch, not because sites write an implementation. We found 169 sites already carrying it. We expect the vendor-distributed share to grow, and we report vendors separately as they appear.
Aggregate, anonymized snapshot. Individual entries do not reveal the scanned domain.
Every domain is re-scanned on a tier-based schedule. Sites that wrote their own implementation are re-checked daily; copies of a vendor-distributed template are re-checked on a seven-day rotation, because every copy carries the same implementation.
Separate from the website crawl above: we score every server published to the official MCP registry, and connect to the ones that declare no authentication to read their advertised tool list. We never invoke a tool.
We read what each server advertises; we never invoke a tool, so this is not evidence that those tools can be executed anonymously — many ask for an API key in their own description. Capability is inferred from tool names and descriptions. We have not yet published an accuracy measurement for this inference. Treat these as measured indicators, not audits.
These are three different problems. Reading them as one number hides which of them applies to you.
Started by your MCP client as a child process with your own user rights. It can read
the files that matter — SSH keys, cloud credentials, .env,
your source tree — and send them out. None of those paths are covered by the operating
system's consent prompts, and nothing warns you when the package is fetched.
Writes land on the operator's backend and whatever it controls — SaaS accounts, ad spend, wallets. This cannot reach your machine: it is an HTTP service, not a process on your computer. The exposure here is to the systems behind the server, not to the laptop running the agent.
The one that matters most in practice, and the one no score captures. A low-privilege server does not need to break anything itself — text it returns can steer the agent into using the credentials of a different, fully trusted server that is connected at the same time. Weak servers become a route to strong ones.
The operating system is not the control point here. A local MCP server is a process you asked your own tooling to start, running as you — to the OS it looks entirely normal. What decides the outcome is what you approve, what you pin, and what you keep connected.
The live figures on this page change every day. Each day is also frozen as a dated file so that a number you cite stays the number you cited. Dated files are never rewritten — corrections are appended to the errata in the index, and every file is listed with its sha256 so you can verify it is byte-identical to the one you read. Aggregate data is published under CC BY 4.0.
Cite as:
Every WebMCP tool declares the inputs it wants. An AI agent fills those fields with whatever the user has told it — so a tool that asks for an email address will receive the user’s email address. This is read from the declaration itself, so it covers every site we have analyzed.
Crawl progress — not adoption growth
| Date | Vendor-distributed | Independent | Total |
|---|
| Anonymized ID | Risk Category | Severity | First Detected |
|---|---|---|---|
| Loading current status… | |||
Connecting to the live scan API…
Publishing real domain names alongside unresolved risks could expose those organizations to harm. WebMCP Shield anonymizes public entries and shares fully attributed findings only with the affected organization directly, or with vetted requesters who need the complete dataset.
Aggregate data is free and needs no sign-up. Attributed findings (real domain names) are shared only with the affected site's own team, or with vetted defenders.
Every day is frozen as a dated file that is never rewritten, so a number you cite stays the number you cited. CC BY 4.0. No sign-up, no form.
We do not publish domain names. If you operate a site, we will share its full report with you once you can show you control the domain.
Claim your reportFindings with real domain names, for defensive use. Requests are reviewed manually.
Request accessOnly needed for data with real domain names. Aggregate data above requires none of this.