Live intelligence on exposed MCP servers across the public web

WebMCP Shield continuously scans public WebMCP endpoints for misconfigurations and exposure risk, and publishes aggregate, anonymized findings below — free, no sign-up required.

Current Status Live

Aggregate, anonymized snapshot. Individual entries do not reveal the scanned domain.

Last updated: —
Domains Monitored
WebMCP Sites Found
High-Risk Sites
Tools Analyzed

Every domain is re-scanned on a tier-based schedule; sites with WebMCP are checked daily.

Anonymized ID Risk Category Severity First Detected
Loading current status…

Connecting to the live scan API…

Why findings are anonymized by default

Publishing real domain names alongside unresolved risks could expose those organizations to harm. WebMCP Shield anonymizes public entries and shares fully attributed findings only with the affected organization directly, or with vetted requesters who need the complete dataset.

Request Full Data Access

Attributed findings (real domains) are only shared with the affected site's own team, or with vetted security/defense use cases. Tell us a bit about your request.

Requests are reviewed manually. We only grant attributed data to verified defenders.