WebMCP adoption is not zero. It is vendor-distributed.

In May 2026, a scan of 111,076 domains from the top 200k found no site running WebMCP in production. That sample is popular sites, which are the ones that would have to write an implementation themselves. Our crawl list covers 5,369,528 domains; we have fetched 5,369,482 of them so far and found 76,250 sites exposing tools to AI agents.

72,197 of them simply carry a tool set their platform distributes to them — Shopify to its storefronts, Cloudflare at the edge. Documented platform features, not vulnerabilities. 4,053 sites wrote their own, and between them those are 3,500 distinct implementations.

Reported as a single number, the total would be misleading. So we report it as two. Aggregate findings, methodology, and limitations below — free, no sign-up.

On 2026-08-06 Cloudflare shipped a one-switch WebMCP injection in developer preview, which requires no change at the origin. That is consistent with what we measure, and it is the second instance of it: when WebMCP spreads, it spreads because infrastructure ships a switch, not because sites write an implementation. We found 169 sites already carrying it. We expect the vendor-distributed share to grow, and we report vendors separately as they appear.

Current Status Live

Aggregate, anonymized snapshot. Individual entries do not reveal the scanned domain.

Last updated: —
—
Domains Fetched
—
Sites Exposing Tools to AI Agents
—
Independent Implementations
—
Registry Entries Contradicted by Reality

Every domain is re-scanned on a tier-based schedule. Sites that wrote their own implementation are re-checked daily; copies of a vendor-distributed template are re-checked on a seven-day rotation, because every copy carries the same implementation.

MCP Server Registry

Separate from the website crawl above: we score every server published to the official MCP registry, and connect to the ones that declare no authentication to read their advertised tool list. We never invoke a tool.

—
Registry Servers Scored
—
Reached & Read
—
Listed State-Changing Tools
—
Listed Delete / Execute Tools

 

We read what each server advertises; we never invoke a tool, so this is not evidence that those tools can be executed anonymously — many ask for an API key in their own description. Capability is inferred from tool names and descriptions. We have not yet published an accuracy measurement for this inference. Treat these as measured indicators, not audits.

Where the risk actually lands

These are three different problems. Reading them as one number hides which of them applies to you.

YOUR OWN MACHINE
—
servers that run locally (stdio)

Started by your MCP client as a child process with your own user rights. It can read the files that matter — SSH keys, cloud credentials, .env, your source tree — and send them out. None of those paths are covered by the operating system's consent prompts, and nothing warns you when the package is fetched.

SOMEONE ELSE'S SYSTEM
—
remote servers advertising state-changing tools

Writes land on the operator's backend and whatever it controls — SaaS accounts, ad spend, wallets. This cannot reach your machine: it is an HTTP service, not a process on your computer. The exposure here is to the systems behind the server, not to the laptop running the agent.

YOUR OTHER TOOLS
Any server
indirect prompt injection

The one that matters most in practice, and the one no score captures. A low-privilege server does not need to break anything itself — text it returns can steer the agent into using the credentials of a different, fully trusted server that is connected at the same time. Weak servers become a route to strong ones.

The operating system is not the control point here. A local MCP server is a process you asked your own tooling to start, running as you — to the OS it looks entirely normal. What decides the outcome is what you approve, what you pin, and what you keep connected.

Methodology and limitations

Dated snapshots and how to cite

The live figures on this page change every day. Each day is also frozen as a dated file so that a number you cite stays the number you cited. Dated files are never rewritten — corrections are appended to the errata in the index, and every file is listed with its sha256 so you can verify it is byte-identical to the one you read. Aggregate data is published under CC BY 4.0.

/data/latest.json  — latest, changes daily
/data/index.json  — every snapshot, with sha256 and errata
/v1/public-status  — live JSON, no sign-up

Cite as:

WebMCP Shield, “WebMCP Exposure Census”, YYYY-MM-DD. https://webmcpshield.com/data/YYYY-MM-DD.json

What these AI tools ask you for

Every WebMCP tool declares the inputs it wants. An AI agent fills those fields with whatever the user has told it — so a tool that asks for an email address will receive the user’s email address. This is read from the declaration itself, so it covers every site we have analyzed.

—
Ask for no personal data
—
Ask for personal data
—
Could not be determined

Newly observed by our crawler

Crawl progress — not adoption growth

Date Vendor-distributed Independent Total

What these categories mean

Findings

 

 

Anonymized ID Risk Category Severity First Detected
Loading current status…

Connecting to the live scan API…

Why findings are anonymized by default

Publishing real domain names alongside unresolved risks could expose those organizations to harm. WebMCP Shield anonymizes public entries and shares fully attributed findings only with the affected organization directly, or with vetted requesters who need the complete dataset.

Get the data

Aggregate data is free and needs no sign-up. Attributed findings (real domain names) are shared only with the affected site's own team, or with vetted defenders.

Journalists & researchers

Download the dataset

Every day is frozen as a dated file that is never rewritten, so a number you cite stays the number you cited. CC BY 4.0. No sign-up, no form.

Site operators

Is my site in here?

We do not publish domain names. If you operate a site, we will share its full report with you once you can show you control the domain.

Claim your report
Security teams

Attributed dataset

Findings with real domain names, for defensive use. Requests are reviewed manually.

Request access

Request attributed data

Only needed for data with real domain names. Aggregate data above requires none of this.

Requests are reviewed manually. We only grant attributed data to verified defenders.