Risk grades
composite score inferred
Risk: servers ranked by their composite exposure score — synthesised from CVEs, inferred permissions, drift, supply-chain and abandonment signals. Heuristic and banded; a high grade is a 'review this' signal, never a verdict.
A fix already ships upstream but the server still runs an older, vulnerable version — remediation lag, actionable today.
- agentfront/frontmcp HIGH CVE-2026-39885 1.5.2 → 2.3.0
Grades are inferred review prompts, not verdicts. Every claim is tagged by what backs it: attested a verifiable record reported a third party's claim inferred our own heuristic methodology →
- 1 E PrefectHQ/fastmcp 100
- 2 E clidey/whodb 100
- 3 E modelcontextprotocol/inspector 97
- 4 E IBM/mcp-context-forge 96
- 5 E awslabs/mcp 94
- 6 E dep0we/atomic-agents-stack 94
- 7 E electerm/electerm 91
- 8 E strands-agents/tools 91
- 9 E ThinkInAIXYZ/deepchat 89
- 10 E dagucloud/dagu 89
- 11 E modelcontextprotocol/inspector 89
- 12 E modelcontextprotocol/typescript-sdk 89
- 13 E opena2a-org/hackmyagent 89
- 14 E cuga-project/cuga-agent 87
- 15 E danielealbano/android-remote-control-mcp 87