{
  "schema_version": 1,
  "snapshot_date": "2026-10-09",
  "sealed": true,
  "generated_at": "2026-10-10T00:16:35.689Z",
  "as_of_note": "Values are cumulative as of generated_at. snapshot_date is the day this file seals, not a per-day delta. Per-day figures are in data.crawl_first_seen.",
  "license": "CC BY 4.0",
  "license_url": "https://creativecommons.org/licenses/by/4.0/",
  "cite_as": "WebMCP Shield, \"WebMCP Exposure Census\", 2026-10-09. https://webmcpshield.com/data/2026-10-09.json",
  "canonical_url": "https://webmcpshield.com/data/2026-10-09.json",
  "method": {
    "tools_invoked": false,
    "tools_invoked_note": "We read what sites and servers declare. We never invoke a tool.",
    "capability_inference": "Capability is inferred from tool names and descriptions. We have not yet published an accuracy measurement for this inference. Treat these as measured indicators, not audits.",
    "robots_txt": "We honour robots.txt. Sites that disallow us are excluded and counted separately.",
    "daily_series": "crawl_first_seen counts when our crawler first observed a site, not when the site implemented WebMCP. This is crawl progress, not adoption growth.",
    "adoption_growth": "Not published. Measuring adoption growth requires a frozen cohort re-scanned on a fixed schedule. We do not have enough history yet.",
    "collection_gaps": "Days when collection failed are marked status=\"collection_gap\". We do not backfill them and we do not merge them into adjacent days.",
    "anonymization": "Individual sites are not named. Findings are published as anonymized identifiers and aggregates.",
    "methodology_url": "https://webmcpshield.com/#methodology"
  },
  "data": {
    "updated_at": "2026-10-10T00:16:35.689Z",
    "observing_since": "2026-08-09T12:20:07.503Z",
    "stats": {
      "domains_monitored": 6208853,
      "domains_crawled": 6208805,
      "domains_not_yet_crawled": 48,
      "domains_monitored_note": "domains_monitored is the size of our crawl list, not the number of domains fetched. Use domains_crawled for statements about what we have actually looked at.",
      "sites_analyzed": 166634,
      "webmcp_detected": 104496,
      "webmcp_detected_ever": 104496,
      "webmcp_detected_latest_scan": 103769,
      "not_observed_on_latest_scan": 727,
      "not_observed_note": "Detected on an earlier scan but not observed on the most recent one. This is not a removal: transient failures are common, and we only treat a site as having removed WebMCP after three consecutive misses.",
      "high_risk_sites": 21,
      "tools_analyzed": 9423986,
      "distinct_tools": 1224571,
      "distinct_tool_names": 15263,
      "tools_analyzed_note": "tools_analyzed counts tool observations across all snapshots, not distinct tools: the same tool on the same site is counted once per scan. Use distinct_tools for unique (site, tool) pairs and distinct_tool_names for unique names.",
      "alerts_30d": 12505,
      "alerts_30d_sites": 6753,
      "alerts_counted_since": "2026-08-30T06:07:13.445Z",
      "alerts_excluded_not_attributable": 466921,
      "alerts_30d_note": "Counts only risk increases attributable to the site, not to changes in our own scoring rules: a risk_increased event is counted only when the two snapshots compared were scored by the same scorer version. Events recorded before alerts_counted_since carry no version stamp and are excluded (alerts_excluded_not_attributable). The 30-day window is therefore only fully covered once alerts_counted_since is more than 30 days old."
    },
    "adoption_breakdown": {
      "detected": 103769,
      "template_sites": 98102,
      "custom_sites": 5667,
      "custom_implementations": 4922,
      "largest_template_sites": 87231,
      "templates": [
        {
          "tool_names": [
            "add_to_cart",
            "browse_store",
            "cancel_cart",
            "get_cart",
            "get_product",
            "manage_orders",
            "proceed_to_checkout",
            "search_catalog",
            "search_shop_policies_and_faqs",
            "show_variant",
            "update_cart_lines"
          ],
          "sites": 87231
        },
        {
          "tool_names": [
            "add_to_cart",
            "browse_store",
            "cancel_cart",
            "get_cart",
            "get_product",
            "get_ucp_profile",
            "manage_orders",
            "proceed_to_checkout",
            "search_catalog",
            "search_shop_policies_and_faqs",
            "show_variant",
            "update_cart_lines"
          ],
          "sites": 6503
        },
        {
          "vendor": "Shopify",
          "vendor_doc_url": "https://shopify.dev/docs/api/web-mcp",
          "note": "Documented platform feature, not a vulnerability. Individual merchants did not opt in to it one by one.",
          "tool_names": [
            "browse_store",
            "cancel_cart",
            "get_cart",
            "get_product",
            "manage_orders",
            "proceed_to_checkout",
            "search_catalog",
            "search_shop_policies_and_faqs",
            "show_variant",
            "update_cart"
          ],
          "sites": 4110
        }
      ]
    },
    "findings_total": 2976,
    "findings_shown": 20,
    "findings_truncated": true,
    "findings_denominator": 5667,
    "findings_note": "Findings are independent implementations where a scoring rule fired, out of all independent implementations. Copies of a vendor-distributed template are collapsed into template_derived_observation instead of being listed one by one. Most findings are unverifiable_execute, which records that we could not read the implementation — not that we found something dangerous.",
    "template_derived_observation": {
      "vendor": null,
      "vendor_doc_url": null,
      "sites": 87231,
      "sites_with_a_scoring_signal": 11,
      "implementation_analysed": false,
      "tool_names": [
        "add_to_cart",
        "browse_store",
        "cancel_cart",
        "get_cart",
        "get_product",
        "manage_orders",
        "proceed_to_checkout",
        "search_catalog",
        "search_shop_policies_and_faqs",
        "show_variant",
        "update_cart_lines"
      ],
      "note": "One implementation, distributed by the vendor. The same rules fire on every copy, so we count it once rather than listing it 87,231 times. This is a documented platform feature, not a vulnerability. We have not yet analysed this vendor's bundle, so 11 of these sites still carry unverifiable_execute — that records what we have not verified, not something we found."
    },
    "template_derived_observations": [
      {
        "vendor": null,
        "vendor_doc_url": null,
        "sites": 87231,
        "sites_with_a_scoring_signal": 11,
        "implementation_analysed": false,
        "tool_names": [
          "add_to_cart",
          "browse_store",
          "cancel_cart",
          "get_cart",
          "get_product",
          "manage_orders",
          "proceed_to_checkout",
          "search_catalog",
          "search_shop_policies_and_faqs",
          "show_variant",
          "update_cart_lines"
        ],
        "note": "One implementation, distributed by the vendor. The same rules fire on every copy, so we count it once rather than listing it 87,231 times. This is a documented platform feature, not a vulnerability. We have not yet analysed this vendor's bundle, so 11 of these sites still carry unverifiable_execute — that records what we have not verified, not something we found."
      },
      {
        "vendor": null,
        "vendor_doc_url": null,
        "sites": 6503,
        "sites_with_a_scoring_signal": 6503,
        "implementation_analysed": false,
        "tool_names": [
          "add_to_cart",
          "browse_store",
          "cancel_cart",
          "get_cart",
          "get_product",
          "get_ucp_profile",
          "manage_orders",
          "proceed_to_checkout",
          "search_catalog",
          "search_shop_policies_and_faqs",
          "show_variant",
          "update_cart_lines"
        ],
        "note": "One implementation, distributed by the vendor. The same rules fire on every copy, so we count it once rather than listing it 6,503 times. This is a documented platform feature, not a vulnerability. We have not yet analysed this vendor's bundle, so 6,503 of these sites still carry unverifiable_execute — that records what we have not verified, not something we found."
      },
      {
        "vendor": "Shopify",
        "vendor_doc_url": "https://shopify.dev/docs/api/web-mcp",
        "sites": 4110,
        "sites_with_a_scoring_signal": 20,
        "implementation_analysed": true,
        "tool_names": [
          "browse_store",
          "cancel_cart",
          "get_cart",
          "get_product",
          "manage_orders",
          "proceed_to_checkout",
          "search_catalog",
          "search_shop_policies_and_faqs",
          "show_variant",
          "update_cart"
        ],
        "note": "One implementation, distributed by the vendor. The same rules fire on every copy, so we count it once rather than listing it 4,110 times. This is a documented platform feature, not a vulnerability. We fetched and analysed the distributed bundle, so these copies carry no unverified-implementation signal."
      }
    ],
    "scored_sites": {
      "detected_latest_scan": 103769,
      "with_a_scoring_signal": 9511,
      "independent": 2976,
      "template_derived": 6535
    },
    "crawl_first_seen": {
      "metric": "crawl_first_seen",
      "disclaimer": "Counts when our crawler first observed a site, not when the site implemented WebMCP. This is crawl progress, not adoption growth.",
      "series": [
        {
          "date": "2026-09-10",
          "vendor_distributed": 821,
          "independent": 53,
          "total": 874
        },
        {
          "date": "2026-09-11",
          "vendor_distributed": 1001,
          "independent": 67,
          "total": 1068
        },
        {
          "date": "2026-09-12",
          "vendor_distributed": 1624,
          "independent": 136,
          "total": 1760
        },
        {
          "date": "2026-09-13",
          "vendor_distributed": 1263,
          "independent": 138,
          "total": 1401
        },
        {
          "date": "2026-09-14",
          "vendor_distributed": 474,
          "independent": 37,
          "total": 511
        },
        {
          "date": "2026-09-15",
          "vendor_distributed": 1150,
          "independent": 93,
          "total": 1243
        },
        {
          "date": "2026-09-16",
          "vendor_distributed": 1086,
          "independent": 122,
          "total": 1208
        },
        {
          "date": "2026-09-17",
          "vendor_distributed": 1076,
          "independent": 89,
          "total": 1165
        },
        {
          "date": "2026-09-18",
          "vendor_distributed": 930,
          "independent": 112,
          "total": 1042
        },
        {
          "date": "2026-09-19",
          "vendor_distributed": 1697,
          "independent": 152,
          "total": 1849
        },
        {
          "date": "2026-09-20",
          "vendor_distributed": 3040,
          "independent": 200,
          "total": 3240
        },
        {
          "date": "2026-09-21",
          "vendor_distributed": 4599,
          "independent": 234,
          "total": 4833
        },
        {
          "date": "2026-09-22",
          "vendor_distributed": 1615,
          "independent": 96,
          "total": 1711
        },
        {
          "date": "2026-09-23",
          "vendor_distributed": 1121,
          "independent": 98,
          "total": 1219
        },
        {
          "date": "2026-09-24",
          "vendor_distributed": 943,
          "independent": 118,
          "total": 1061
        },
        {
          "date": "2026-09-25",
          "vendor_distributed": 1376,
          "independent": 127,
          "total": 1503
        },
        {
          "date": "2026-09-26",
          "vendor_distributed": 1247,
          "independent": 101,
          "total": 1348
        },
        {
          "date": "2026-09-27",
          "vendor_distributed": 1513,
          "independent": 226,
          "total": 1739
        },
        {
          "date": "2026-09-28",
          "vendor_distributed": 1327,
          "independent": 136,
          "total": 1463
        },
        {
          "date": "2026-09-29",
          "vendor_distributed": 1204,
          "independent": 143,
          "total": 1347
        },
        {
          "date": "2026-09-30",
          "vendor_distributed": 1168,
          "independent": 156,
          "total": 1324
        },
        {
          "date": "2026-10-01",
          "vendor_distributed": 1390,
          "independent": 144,
          "total": 1534
        },
        {
          "date": "2026-10-02",
          "vendor_distributed": 1371,
          "independent": 119,
          "total": 1490
        },
        {
          "date": "2026-10-03",
          "vendor_distributed": 1359,
          "independent": 122,
          "total": 1481
        },
        {
          "date": "2026-10-04",
          "vendor_distributed": 1215,
          "independent": 167,
          "total": 1382
        },
        {
          "date": "2026-10-05",
          "vendor_distributed": 2631,
          "independent": 147,
          "total": 2778
        },
        {
          "date": "2026-10-06",
          "vendor_distributed": 8387,
          "independent": 222,
          "total": 8609
        },
        {
          "date": "2026-10-07",
          "vendor_distributed": 4876,
          "independent": 217,
          "total": 5093
        },
        {
          "date": "2026-10-08",
          "vendor_distributed": 1306,
          "independent": 145,
          "total": 1451
        },
        {
          "date": "2026-10-09",
          "vendor_distributed": 1207,
          "independent": 131,
          "total": 1338
        },
        {
          "date": "2026-10-10",
          "vendor_distributed": 21,
          "independent": 4,
          "total": 25
        }
      ]
    },
    "requested_data": {
      "examples": [
        {
          "tool": "get_product",
          "sites": 98036,
          "description": "Get product details, OR navigate the browser to the product page. Set catalog.navigate=true whenever the user wants to see/view the product in the browser (triggers: \"show me\", \"open\", \"view\", \"go to\", \"take me to\", \"navigate to\" a product). Set catalog.navigate=false (default) only when you need data (description, options, variants, prices, availability) to answer a question or to prepare an add_",
          "fields": [
            {
              "key": "catalog.id",
              "type": "string",
              "description": "Storefront API Product GID, product handle, or product URL path. Custom app product paths and Shopify standard /products/<handle> paths are supported. The id fi",
              "personal": false,
              "label": null
            },
            {
              "key": "catalog.navigate",
              "type": "boolean",
              "description": "When true, navigate the browser to the product page after fetching details. Set true for user intents like \"show me\", \"open\", \"view\", \"go to\", \"take me to\" a pr",
              "personal": false,
              "label": null
            },
            {
              "key": "catalog.selected_options",
              "type": "array",
              "description": "Known product option selections to filter available_options. Use exact option names and values from search_catalog options or a prior get_product available_opti",
              "personal": false,
              "label": null
            }
          ]
        },
        {
          "tool": "search_catalog",
          "sites": 98014,
          "description": "Search the store catalog for products, collections, articles, and pages. Does NOT add anything to the cart; use add_to_cart for cart changes. If the user asks for a specific product variant, call get_product after search_catalog to inspect available variants, then show_variant to display one.",
          "fields": [
            {
              "key": "catalog.query",
              "type": "string",
              "description": "Search query string.",
              "personal": false,
              "label": null
            },
            {
              "key": "catalog.pagination.limit",
              "type": "integer",
              "description": "Max results per type (1-10). Defaults to 5.",
              "personal": false,
              "label": null
            }
          ]
        },
        {
          "tool": "get_cart",
          "sites": 98000,
          "description": "Get the current shopping cart contents — line items with product titles, variant titles, handles, URLs, images, unit prices, quantities, and totals. Everything needed to describe the cart to the user in natural language, without a follow-up get_product call per line. Works from any page.",
          "fields": []
        }
      ],
      "personal_examples": [
        {
          "sites": 1,
          "fields": [
            {
              "key": "employee_email",
              "type": "string",
              "personal": true,
              "label": "Email address"
            },
            {
              "key": "passport_expiry",
              "type": "string",
              "personal": true,
              "label": "Government ID (passport / SSN)"
            },
            {
              "key": "passport_number",
              "type": "string",
              "personal": true,
              "label": "Government ID (passport / SSN)"
            }
          ]
        },
        {
          "sites": 1,
          "fields": [
            {
              "key": "fields.iban",
              "type": "string",
              "personal": true,
              "label": "Payment details"
            },
            {
              "key": "fields.ownerTaxId",
              "type": "string",
              "personal": true,
              "label": "Government ID (passport / SSN)"
            },
            {
              "key": "fields.tenantTaxId",
              "type": "string",
              "personal": true,
              "label": "Government ID (passport / SSN)"
            }
          ]
        }
      ],
      "sites_with_tools": 103769,
      "no_personal_data": 102895,
      "requests_personal_data": 757,
      "undetermined": 117,
      "fields": [
        {
          "label": "Email address",
          "sites": 556
        },
        {
          "label": "Name",
          "sites": 317
        },
        {
          "label": "Phone number",
          "sites": 299
        },
        {
          "label": "Postal code",
          "sites": 36
        },
        {
          "label": "Government ID (passport / SSN)",
          "sites": 4
        },
        {
          "label": "Date of birth",
          "sites": 4
        },
        {
          "label": "Postal address",
          "sites": 3
        },
        {
          "label": "Payment details",
          "sites": 2
        }
      ]
    },
    "mcp_registry": {
      "servers_monitored": 39135,
      "servers_probed": 11034,
      "tool_lists_retrieved": 6541,
      "listing_state_changing_tools": 4247,
      "listing_destructive_tools": 2443,
      "auth_metadata_mismatch": 2842,
      "auth_metadata_mismatch_denominator": 9383,
      "auth_metadata_mismatch_note": "Servers that declared no authentication in the registry and responded to us. Servers that did not respond are excluded: we cannot tell whether their declaration was accurate.",
      "local_execution": 15905,
      "tools_analyzed": 110155,
      "observing_since": "2026-08-11T13:11:37.094Z"
    },
    "findings": [
      {
        "id": "site-#6BE8A4",
        "risk_category": "external_data_transmission",
        "severity": "high",
        "first_detected": "2026-10-07T06:00:13.416Z"
      },
      {
        "id": "site-#FF7B96",
        "risk_category": "output_concealed_from_user",
        "severity": "high",
        "first_detected": "2026-08-14T03:52:00.550Z"
      },
      {
        "id": "site-#4C2859",
        "risk_category": "prompt_injection",
        "severity": "high",
        "first_detected": "2026-10-09T12:18:18.062Z"
      },
      {
        "id": "site-#2F6D25",
        "risk_category": "unverifiable_execute",
        "severity": "high",
        "first_detected": "2026-09-30T06:06:18.399Z"
      },
      {
        "id": "site-#DA6C9B",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-09-20T06:13:27.094Z"
      },
      {
        "id": "site-#A2CEED",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-09-21T16:06:12.029Z"
      },
      {
        "id": "site-#2B94DD",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-09-28T04:05:14.677Z"
      },
      {
        "id": "site-#145CB1",
        "risk_category": "unverifiable_execute_declared_readonly",
        "severity": "high",
        "first_detected": "2026-09-06T07:59:27.236Z"
      },
      {
        "id": "site-#19F4FC",
        "risk_category": "unverifiable_execute",
        "severity": "high",
        "first_detected": "2026-09-06T06:23:14.940Z"
      },
      {
        "id": "site-#92359A",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-09-29T02:28:00.029Z"
      },
      {
        "id": "site-#D3E94A",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-09-27T04:31:25.836Z"
      },
      {
        "id": "site-#B53D1D",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-08-15T01:39:42.246Z"
      },
      {
        "id": "site-#BCC9EF",
        "risk_category": "unverifiable_execute_declared_readonly",
        "severity": "high",
        "first_detected": "2026-09-01T04:28:04.653Z"
      },
      {
        "id": "site-#F1C873",
        "risk_category": "unverifiable_execute_with_personal_data",
        "severity": "high",
        "first_detected": "2026-09-28T06:36:43.079Z"
      },
      {
        "id": "site-#E2F645",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-09-06T07:45:36.697Z"
      },
      {
        "id": "site-#DC41D9",
        "risk_category": "unverifiable_execute_with_personal_data",
        "severity": "high",
        "first_detected": "2026-10-07T02:38:01.911Z"
      },
      {
        "id": "site-#986B64",
        "risk_category": "unverifiable_execute",
        "severity": "high",
        "first_detected": "2026-09-19T22:55:35.774Z"
      },
      {
        "id": "site-#50B394",
        "risk_category": "unverifiable_execute",
        "severity": "high",
        "first_detected": "2026-08-16T22:59:29.990Z"
      },
      {
        "id": "site-#0EA3EC",
        "risk_category": "unverifiable_execute",
        "severity": "high",
        "first_detected": "2026-09-21T04:37:37.022Z"
      },
      {
        "id": "site-#F7EFE8",
        "risk_category": "unverifiable_execute",
        "severity": "high",
        "first_detected": "2026-09-06T07:45:24.662Z"
      }
    ]
  }
}
