Research · reports and findings
Research
Reports, methodology, and findings on MCP server security — from the register that grades every server in the registry.
- Migrating an MCP server to 2026-07-28A checklist for moving a server to the stateless revision without breaking the clients you already have. The short answer is don't migrate — go dual-era — and here is why, plus what to change, remove, and verify.
- What the 2026-07-28 MCP revision changes for securityThe biggest MCP revision yet removed sessions and the initialize handshake. Read as a security change it closes some real holes, opens at least one new one, and makes servers harder to scan. A skimmable breakdown.
- The state of MCP securityWe graded every server in the MCP registry A–F on six security checks. Most are clean on what's visible, few earn top marks, and a small tail ships real problems. Here's what the ecosystem looks like.
- Where to publish your MCP serverA practical map of where MCP servers get listed in 2026 — the official registry, the package registries, and the third-party directories. The short version: publish once, to the registry, and most of the rest mirror it.
- How mcpgrade grades MCP serversThe six security checks behind every A–F grade, how coverage caps the grade, and why static analysis is paired with runtime probing.