{
  "schema_version": 1,
  "snapshot_date": "2026-10-10",
  "sealed": true,
  "generated_at": "2026-10-11T00:16:19.845Z",
  "as_of_note": "Values are cumulative as of generated_at. snapshot_date is the day this file seals, not a per-day delta. Per-day figures are in data.crawl_first_seen.",
  "license": "CC BY 4.0",
  "license_url": "https://creativecommons.org/licenses/by/4.0/",
  "cite_as": "WebMCP Shield, \"WebMCP Exposure Census\", 2026-10-10. https://webmcpshield.com/data/2026-10-10.json",
  "canonical_url": "https://webmcpshield.com/data/2026-10-10.json",
  "method": {
    "tools_invoked": false,
    "tools_invoked_note": "We read what sites and servers declare. We never invoke a tool.",
    "capability_inference": "Capability is inferred from tool names and descriptions. We have not yet published an accuracy measurement for this inference. Treat these as measured indicators, not audits.",
    "robots_txt": "We honour robots.txt. Sites that disallow us are excluded and counted separately.",
    "daily_series": "crawl_first_seen counts when our crawler first observed a site, not when the site implemented WebMCP. This is crawl progress, not adoption growth.",
    "adoption_growth": "Not published. Measuring adoption growth requires a frozen cohort re-scanned on a fixed schedule. We do not have enough history yet.",
    "collection_gaps": "Days when collection failed are marked status=\"collection_gap\". We do not backfill them and we do not merge them into adjacent days.",
    "anonymization": "Individual sites are not named. Findings are published as anonymized identifiers and aggregates.",
    "methodology_url": "https://webmcpshield.com/#methodology"
  },
  "data": {
    "updated_at": "2026-10-11T00:16:19.845Z",
    "observing_since": "2026-08-09T12:20:07.503Z",
    "stats": {
      "domains_monitored": 6279156,
      "domains_crawled": 6279103,
      "domains_not_yet_crawled": 53,
      "domains_monitored_note": "domains_monitored is the size of our crawl list, not the number of domains fetched. Use domains_crawled for statements about what we have actually looked at.",
      "sites_analyzed": 168180,
      "webmcp_detected": 105577,
      "webmcp_detected_ever": 105577,
      "webmcp_detected_latest_scan": 104881,
      "not_observed_on_latest_scan": 696,
      "not_observed_note": "Detected on an earlier scan but not observed on the most recent one. This is not a removal: transient failures are common, and we only treat a site as having removed WebMCP after three consecutive misses.",
      "high_risk_sites": 22,
      "tools_analyzed": 9648867,
      "distinct_tools": 1249386,
      "distinct_tool_names": 15442,
      "tools_analyzed_note": "tools_analyzed counts tool observations across all snapshots, not distinct tools: the same tool on the same site is counted once per scan. Use distinct_tools for unique (site, tool) pairs and distinct_tool_names for unique names.",
      "alerts_30d": 23648,
      "alerts_30d_sites": 17765,
      "alerts_counted_since": "2026-08-30T06:07:13.445Z",
      "alerts_excluded_not_attributable": 466921,
      "alerts_30d_note": "Counts only risk increases attributable to the site, not to changes in our own scoring rules: a risk_increased event is counted only when the two snapshots compared were scored by the same scorer version. Events recorded before alerts_counted_since carry no version stamp and are excluded (alerts_excluded_not_attributable). The 30-day window is therefore only fully covered once alerts_counted_since is more than 30 days old."
    },
    "adoption_breakdown": {
      "detected": 104881,
      "template_sites": 99080,
      "custom_sites": 5801,
      "custom_implementations": 5027,
      "largest_template_sites": 76065,
      "templates": [
        {
          "vendor": "Shopify",
          "vendor_doc_url": "https://shopify.dev/docs/api/web-mcp",
          "note": "Documented platform feature, not a vulnerability. Individual merchants did not opt in to it one by one.",
          "tool_names": [
            "add_to_cart",
            "browse_store",
            "cancel_cart",
            "get_cart",
            "get_product",
            "manage_orders",
            "proceed_to_checkout",
            "search_catalog",
            "search_shop_policies_and_faqs",
            "show_variant",
            "update_cart_lines"
          ],
          "sites": 76065
        },
        {
          "tool_names": [
            "add_to_cart",
            "browse_store",
            "cancel_cart",
            "get_cart",
            "get_product",
            "get_ucp_profile",
            "manage_orders",
            "proceed_to_checkout",
            "search_catalog",
            "search_shop_policies_and_faqs",
            "show_variant",
            "update_cart_lines"
          ],
          "sites": 18661
        },
        {
          "vendor": "Shopify",
          "vendor_doc_url": "https://shopify.dev/docs/api/web-mcp",
          "note": "Documented platform feature, not a vulnerability. Individual merchants did not opt in to it one by one.",
          "tool_names": [
            "browse_store",
            "cancel_cart",
            "get_cart",
            "get_product",
            "manage_orders",
            "proceed_to_checkout",
            "search_catalog",
            "search_shop_policies_and_faqs",
            "show_variant",
            "update_cart"
          ],
          "sites": 4093
        }
      ]
    },
    "findings_total": 3099,
    "findings_shown": 20,
    "findings_truncated": true,
    "findings_denominator": 5801,
    "findings_note": "Findings are independent implementations where a scoring rule fired, out of all independent implementations. Copies of a vendor-distributed template are collapsed into template_derived_observation instead of being listed one by one. Most findings are unverifiable_execute, which records that we could not read the implementation — not that we found something dangerous.",
    "template_derived_observation": {
      "vendor": "Shopify",
      "vendor_doc_url": "https://shopify.dev/docs/api/web-mcp",
      "sites": 76065,
      "sites_with_a_scoring_signal": 9,
      "implementation_analysed": true,
      "tool_names": [
        "add_to_cart",
        "browse_store",
        "cancel_cart",
        "get_cart",
        "get_product",
        "manage_orders",
        "proceed_to_checkout",
        "search_catalog",
        "search_shop_policies_and_faqs",
        "show_variant",
        "update_cart_lines"
      ],
      "note": "One implementation, distributed by the vendor. The same rules fire on every copy, so we count it once rather than listing it 76,065 times. This is a documented platform feature, not a vulnerability. We fetched and analysed the distributed bundle, so these copies carry no unverified-implementation signal. 9 of these sites still show a scoring signal."
    },
    "template_derived_observations": [
      {
        "vendor": "Shopify",
        "vendor_doc_url": "https://shopify.dev/docs/api/web-mcp",
        "sites": 76065,
        "sites_with_a_scoring_signal": 9,
        "implementation_analysed": true,
        "tool_names": [
          "add_to_cart",
          "browse_store",
          "cancel_cart",
          "get_cart",
          "get_product",
          "manage_orders",
          "proceed_to_checkout",
          "search_catalog",
          "search_shop_policies_and_faqs",
          "show_variant",
          "update_cart_lines"
        ],
        "note": "One implementation, distributed by the vendor. The same rules fire on every copy, so we count it once rather than listing it 76,065 times. This is a documented platform feature, not a vulnerability. We fetched and analysed the distributed bundle, so these copies carry no unverified-implementation signal. 9 of these sites still show a scoring signal."
      },
      {
        "vendor": null,
        "vendor_doc_url": null,
        "sites": 18661,
        "sites_with_a_scoring_signal": 18661,
        "implementation_analysed": false,
        "tool_names": [
          "add_to_cart",
          "browse_store",
          "cancel_cart",
          "get_cart",
          "get_product",
          "get_ucp_profile",
          "manage_orders",
          "proceed_to_checkout",
          "search_catalog",
          "search_shop_policies_and_faqs",
          "show_variant",
          "update_cart_lines"
        ],
        "note": "One implementation, distributed by the vendor. The same rules fire on every copy, so we count it once rather than listing it 18,661 times. This is a documented platform feature, not a vulnerability. We have not yet analysed this vendor's bundle, so 18,661 of these sites still carry unverifiable_execute — that records what we have not verified, not something we found."
      },
      {
        "vendor": "Shopify",
        "vendor_doc_url": "https://shopify.dev/docs/api/web-mcp",
        "sites": 4093,
        "sites_with_a_scoring_signal": 19,
        "implementation_analysed": true,
        "tool_names": [
          "browse_store",
          "cancel_cart",
          "get_cart",
          "get_product",
          "manage_orders",
          "proceed_to_checkout",
          "search_catalog",
          "search_shop_policies_and_faqs",
          "show_variant",
          "update_cart"
        ],
        "note": "One implementation, distributed by the vendor. The same rules fire on every copy, so we count it once rather than listing it 4,093 times. This is a documented platform feature, not a vulnerability. We fetched and analysed the distributed bundle, so these copies carry no unverified-implementation signal. 19 of these sites still show a scoring signal."
      }
    ],
    "scored_sites": {
      "detected_latest_scan": 104881,
      "with_a_scoring_signal": 21789,
      "independent": 3099,
      "template_derived": 18690
    },
    "crawl_first_seen": {
      "metric": "crawl_first_seen",
      "disclaimer": "Counts when our crawler first observed a site, not when the site implemented WebMCP. This is crawl progress, not adoption growth.",
      "series": [
        {
          "date": "2026-09-11",
          "vendor_distributed": 1000,
          "independent": 65,
          "total": 1065
        },
        {
          "date": "2026-09-12",
          "vendor_distributed": 1626,
          "independent": 129,
          "total": 1755
        },
        {
          "date": "2026-09-13",
          "vendor_distributed": 1256,
          "independent": 141,
          "total": 1397
        },
        {
          "date": "2026-09-14",
          "vendor_distributed": 472,
          "independent": 36,
          "total": 508
        },
        {
          "date": "2026-09-15",
          "vendor_distributed": 1145,
          "independent": 90,
          "total": 1235
        },
        {
          "date": "2026-09-16",
          "vendor_distributed": 1077,
          "independent": 130,
          "total": 1207
        },
        {
          "date": "2026-09-17",
          "vendor_distributed": 1076,
          "independent": 84,
          "total": 1160
        },
        {
          "date": "2026-09-18",
          "vendor_distributed": 928,
          "independent": 109,
          "total": 1037
        },
        {
          "date": "2026-09-19",
          "vendor_distributed": 1695,
          "independent": 150,
          "total": 1845
        },
        {
          "date": "2026-09-20",
          "vendor_distributed": 3041,
          "independent": 191,
          "total": 3232
        },
        {
          "date": "2026-09-21",
          "vendor_distributed": 4599,
          "independent": 232,
          "total": 4831
        },
        {
          "date": "2026-09-22",
          "vendor_distributed": 1615,
          "independent": 96,
          "total": 1711
        },
        {
          "date": "2026-09-23",
          "vendor_distributed": 1118,
          "independent": 101,
          "total": 1219
        },
        {
          "date": "2026-09-24",
          "vendor_distributed": 945,
          "independent": 115,
          "total": 1060
        },
        {
          "date": "2026-09-25",
          "vendor_distributed": 1376,
          "independent": 128,
          "total": 1504
        },
        {
          "date": "2026-09-26",
          "vendor_distributed": 1242,
          "independent": 103,
          "total": 1345
        },
        {
          "date": "2026-09-27",
          "vendor_distributed": 1506,
          "independent": 232,
          "total": 1738
        },
        {
          "date": "2026-09-28",
          "vendor_distributed": 1324,
          "independent": 133,
          "total": 1457
        },
        {
          "date": "2026-09-29",
          "vendor_distributed": 1196,
          "independent": 149,
          "total": 1345
        },
        {
          "date": "2026-09-30",
          "vendor_distributed": 1164,
          "independent": 155,
          "total": 1319
        },
        {
          "date": "2026-10-01",
          "vendor_distributed": 1388,
          "independent": 140,
          "total": 1528
        },
        {
          "date": "2026-10-02",
          "vendor_distributed": 1367,
          "independent": 118,
          "total": 1485
        },
        {
          "date": "2026-10-03",
          "vendor_distributed": 1356,
          "independent": 123,
          "total": 1479
        },
        {
          "date": "2026-10-04",
          "vendor_distributed": 1216,
          "independent": 165,
          "total": 1381
        },
        {
          "date": "2026-10-05",
          "vendor_distributed": 2632,
          "independent": 140,
          "total": 2772
        },
        {
          "date": "2026-10-06",
          "vendor_distributed": 8379,
          "independent": 225,
          "total": 8604
        },
        {
          "date": "2026-10-07",
          "vendor_distributed": 4875,
          "independent": 215,
          "total": 5090
        },
        {
          "date": "2026-10-08",
          "vendor_distributed": 1305,
          "independent": 147,
          "total": 1452
        },
        {
          "date": "2026-10-09",
          "vendor_distributed": 1201,
          "independent": 137,
          "total": 1338
        },
        {
          "date": "2026-10-10",
          "vendor_distributed": 1113,
          "independent": 128,
          "total": 1241
        },
        {
          "date": "2026-10-11",
          "vendor_distributed": 15,
          "independent": 4,
          "total": 19
        }
      ]
    },
    "requested_data": {
      "examples": [
        {
          "tool": "get_product",
          "sites": 99019,
          "description": "Get product details, OR navigate the browser to the product page. Set catalog.navigate=true whenever the user wants to see/view the product in the browser (triggers: \"show me\", \"open\", \"view\", \"go to\", \"take me to\", \"navigate to\" a product). Set catalog.navigate=false (default) only when you need data (description, options, variants, prices, availability) to answer a question or to prepare an add_",
          "fields": [
            {
              "key": "catalog.id",
              "type": "string",
              "description": "Storefront API Product GID, product handle, or product URL path. Custom app product paths and Shopify standard /products/<handle> paths are supported. The id fi",
              "personal": false,
              "label": null
            },
            {
              "key": "catalog.navigate",
              "type": "boolean",
              "description": "When true, navigate the browser to the product page after fetching details. Set true for user intents like \"show me\", \"open\", \"view\", \"go to\", \"take me to\" a pr",
              "personal": false,
              "label": null
            },
            {
              "key": "catalog.selected_options",
              "type": "array",
              "description": "Known product option selections to filter available_options. Use exact option names and values from search_catalog options or a prior get_product available_opti",
              "personal": false,
              "label": null
            }
          ]
        },
        {
          "tool": "search_catalog",
          "sites": 98998,
          "description": "Search the store catalog for products, collections, articles, and pages. Does NOT add anything to the cart; use add_to_cart for cart changes. If the user asks for a specific product variant, call get_product after search_catalog to inspect available variants, then show_variant to display one.",
          "fields": [
            {
              "key": "catalog.query",
              "type": "string",
              "description": "Search query string.",
              "personal": false,
              "label": null
            },
            {
              "key": "catalog.pagination.limit",
              "type": "integer",
              "description": "Max results per type (1-10). Defaults to 5.",
              "personal": false,
              "label": null
            }
          ]
        },
        {
          "tool": "get_cart",
          "sites": 98984,
          "description": "Get the current shopping cart contents — line items with product titles, variant titles, handles, URLs, images, unit prices, quantities, and totals. Everything needed to describe the cart to the user in natural language, without a follow-up get_product call per line. Works from any page.",
          "fields": []
        }
      ],
      "personal_examples": [
        {
          "sites": 1,
          "fields": [
            {
              "key": "employee_email",
              "type": "string",
              "personal": true,
              "label": "Email address"
            },
            {
              "key": "passport_expiry",
              "type": "string",
              "personal": true,
              "label": "Government ID (passport / SSN)"
            },
            {
              "key": "passport_number",
              "type": "string",
              "personal": true,
              "label": "Government ID (passport / SSN)"
            }
          ]
        },
        {
          "sites": 1,
          "fields": [
            {
              "key": "fields.iban",
              "type": "string",
              "personal": true,
              "label": "Payment details"
            },
            {
              "key": "fields.ownerTaxId",
              "type": "string",
              "personal": true,
              "label": "Government ID (passport / SSN)"
            },
            {
              "key": "fields.tenantTaxId",
              "type": "string",
              "personal": true,
              "label": "Government ID (passport / SSN)"
            }
          ]
        }
      ],
      "sites_with_tools": 104881,
      "no_personal_data": 103981,
      "requests_personal_data": 777,
      "undetermined": 123,
      "fields": [
        {
          "label": "Email address",
          "sites": 569
        },
        {
          "label": "Name",
          "sites": 318
        },
        {
          "label": "Phone number",
          "sites": 307
        },
        {
          "label": "Postal code",
          "sites": 35
        },
        {
          "label": "Government ID (passport / SSN)",
          "sites": 4
        },
        {
          "label": "Date of birth",
          "sites": 4
        },
        {
          "label": "Postal address",
          "sites": 3
        },
        {
          "label": "Payment details",
          "sites": 2
        }
      ]
    },
    "mcp_registry": {
      "servers_monitored": 41913,
      "servers_probed": 11334,
      "tool_lists_retrieved": 6704,
      "listing_state_changing_tools": 4334,
      "listing_destructive_tools": 2471,
      "auth_metadata_mismatch": 2966,
      "auth_metadata_mismatch_denominator": 9670,
      "auth_metadata_mismatch_note": "Servers that declared no authentication in the registry and responded to us. Servers that did not respond are excluded: we cannot tell whether their declaration was accurate.",
      "local_execution": 16596,
      "tools_analyzed": 112022,
      "observing_since": "2026-08-11T13:11:37.094Z"
    },
    "findings": [
      {
        "id": "site-#6BE8A4",
        "risk_category": "external_data_transmission",
        "severity": "high",
        "first_detected": "2026-10-07T06:00:13.416Z"
      },
      {
        "id": "site-#FF7B96",
        "risk_category": "output_concealed_from_user",
        "severity": "high",
        "first_detected": "2026-08-14T03:52:00.550Z"
      },
      {
        "id": "site-#4C2859",
        "risk_category": "prompt_injection",
        "severity": "high",
        "first_detected": "2026-10-09T12:18:18.062Z"
      },
      {
        "id": "site-#2F6D25",
        "risk_category": "unverifiable_execute",
        "severity": "high",
        "first_detected": "2026-09-30T06:06:18.399Z"
      },
      {
        "id": "site-#DA6C9B",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-09-20T06:13:27.094Z"
      },
      {
        "id": "site-#A2CEED",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-09-21T16:06:12.029Z"
      },
      {
        "id": "site-#2B94DD",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-09-28T04:05:14.677Z"
      },
      {
        "id": "site-#145CB1",
        "risk_category": "unverifiable_execute_declared_readonly",
        "severity": "high",
        "first_detected": "2026-09-06T07:59:27.236Z"
      },
      {
        "id": "site-#19F4FC",
        "risk_category": "unverifiable_execute",
        "severity": "high",
        "first_detected": "2026-09-06T06:23:14.940Z"
      },
      {
        "id": "site-#92359A",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-09-29T02:28:00.029Z"
      },
      {
        "id": "site-#D3E94A",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-09-27T04:31:25.836Z"
      },
      {
        "id": "site-#B53D1D",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-08-15T01:39:42.246Z"
      },
      {
        "id": "site-#BCC9EF",
        "risk_category": "unverifiable_execute_declared_readonly",
        "severity": "high",
        "first_detected": "2026-09-01T04:28:04.653Z"
      },
      {
        "id": "site-#F1C873",
        "risk_category": "unverifiable_execute",
        "severity": "high",
        "first_detected": "2026-09-28T06:36:43.079Z"
      },
      {
        "id": "site-#D00A85",
        "risk_category": "credential_input",
        "severity": "high",
        "first_detected": "2026-10-10T22:58:35.004Z"
      },
      {
        "id": "site-#E2F645",
        "risk_category": "unverifiable_execute_declared_readonly",
        "severity": "high",
        "first_detected": "2026-09-06T07:45:36.697Z"
      },
      {
        "id": "site-#DC41D9",
        "risk_category": "unverifiable_execute_with_personal_data",
        "severity": "high",
        "first_detected": "2026-10-07T02:38:01.911Z"
      },
      {
        "id": "site-#986B64",
        "risk_category": "unverifiable_execute",
        "severity": "high",
        "first_detected": "2026-09-19T22:55:35.774Z"
      },
      {
        "id": "site-#50B394",
        "risk_category": "unverifiable_execute",
        "severity": "high",
        "first_detected": "2026-08-16T22:59:29.990Z"
      },
      {
        "id": "site-#0EA3EC",
        "risk_category": "unverifiable_execute",
        "severity": "high",
        "first_detected": "2026-09-21T04:37:37.022Z"
      }
    ]
  }
}
