PulseGateCategoriesMethodologyCompanyThe global software index— through the gate this hour
Coverage—in the index
Freshness—newest listing
Cadence—last week average · — today
Index9 markets90 categories · 139 niches
PulseGate

The global index of software taking shape now.

Stores show what passed through a store. Launch sites show what launched there. Catalogs show what entered their catalog. Each sees the market through its own gate. PulseGate reads across them.

FollowGitHubX (Twitter)LinkedIn
Platform
IndexIndex by setCategoriesIndustry UpdatesMethodologySupply IndexData SourcesCoverage RulesGlossaryEmbed Widget
Support
Help CenterSubmit your projectReport an Issue
Company
AboutTeamDimaxiaPress & DataContactPlatform Status
Legal
PrivacyTermsDisclaimer
Dimaxia · Dymaxio s.r.o. · Prague, Czechia · © 2026WatchlistSitemapSystem status
PulseGateMCMCPSafe
Visit↗
Skip to content
  1. Index›
  2. Security & compliance platforms›
  3. MCPSafe
← Back to the index
MC

MCPSafe

mcpsafe.io·Security & compliance platforms·🇩🇪

MCPSafe is a free MCP server security scanner for checking whether a server is safe to install. It is built for developers vetting MCP servers before installation and for registry operators publishing safe catalogs. The service describes its checks as being backed by static analysis and five LLMs, and it offers both a fast verdict in about three minutes and a deeper LLM-judge consensus run in about twenty minutes.

Its checks cover several named areas. Typosquatting flags lookalike package names, unverified publishers, and unpinned dependencies before they reach an install chain. Static analysis is used to detect command injection, SQL injection, SSRF, path traversal, and hardcoded secrets. The LLM consensus layer uses five independent LLM judges to uncover tool poisoning, silent rug pulls, indirect prompt injection, and obfuscated intent that pattern matching misses. A permission audit examines each tool’s real-world reach and flags excessive permissions, weak authentication, and network exposure beyond its stated purpose.

MCPSafe accepts multiple source types. The scan flow says users can paste an MCP source from GitHub, an npm scoped package, or a pip package, and the FAQ adds support for GitHub URLs, npm packages, PyPI packages, Docker images from Docker Hub or GHCR, and MCP registry IDs. It normalizes those inputs, runs typosquat, static, behavioral, readiness, and 5-LLM consensus analysis in parallel, and returns an AIVSS 0–10 score with per-tool findings, CWE mapping, and copy-safe config. It also notes that already-scanned servers return in under a second and that it re-verifies on every new commit.

The scanner is free to use, with no credit card required and no signup required for scanning. Signed-in users get higher rate limits and scan history. It is delivered as a web service, includes a live SVG badge for scanned packages, and is marked as made in Germany. The page also describes public packages as free and private repos as available for teams shipping their own.

FreeWeb
MMCPSafe preview
Visit mcpsafe.io↗

Overview

5 features

In the Security & compliance platforms space, MCPSafe takes a focused approach. It helps developers and registry operators verify the security of MCP servers before installation, reducing risk from vulnerabilities. MCPSafe is a B2B product aimed at developers and registry operators using MCP servers. MCPSafe costs nothing to use. It runs on the web.

It is developed by MCPSafe (Germany), and it first shipped in 2026. Key capabilities include security scanning, static analysis, and LLM consensus. It exposes integrations via an MCP server.

Summary written by a language model from the project’s public pages.

  • ✓Security scanning
  • ✓Static analysis
  • ✓LLM consensus
  • ✓Permission audit
  • ✓Typosquatting detection
Tags
mcp-serversecurity-auditllm-analysis

Built with & integrations

Framework
Next.js
Hosting
AWS
Connectors
MCP
Runs on
Browser
Detected from
AWS
x-amz-cf-id header · x-amz-cf-pop header · via header
Next.js
/_next/static/ in the HTML · __next_f in the HTML

Trust & compliance

Verified signals
✓HTTPS✓Privacy Policy✓Terms of Service✓Free tier
Legal
Privacy Policy →Terms of Service →

Indexing history

1

What PulseGate has recorded for this listing

  1. Indexed26 Jun · 19:22 UTC
    Listing verified against its public source
    Source: PulseGate · Open ↗

Frequently asked questions about MCPSafe

What does MCPSafe do?
MCPSafe helps developers and registry operators verify the security of MCP servers before installation, reducing risk from vulnerabilities. It is catalogued under Security & compliance platforms on PulseGate.
Who is MCPSafe for?
MCPSafe is a B2B product built for developers and registry operators using MCP servers.
Does MCPSafe have a free plan?
Yes — MCPSafe is free to use.
What platforms does MCPSafe run on?
MCPSafe runs on the web.
Is MCPSafe still maintained?
Unverified. MCPSafe has not been re-checked since it entered the index, so there is no finding either way — and only a positive finding would say otherwise.
What projects are similar to MCPSafe?
Similar projects tracked by PulseGate include mcp-guardian-scan, mcpsnare, and mcp-check-security.mcp-guardian-scanmcpsnaremcp-check-securitySee all 18 alternatives
Who develops MCPSafe?
MCPSafe is developed by MCPSafe, based in Germany.
How long has MCPSafe been around?
MCPSafe first shipped in 2026.

At a glance

Pricing
Free
Platforms
Web
Languages
English
Built for
Developers and registry operators using MCP servers
Model
B2B
Solves
Helps developers and registry operators verify the security of MCP servers before installation, reducing risk from vulnerabilities.

Index record

Identity confidence
High · 95.6
Indexed
26 Jun 2026
Lifecycle
Alive
Last seen
26 Jun 2026
Identity audit (12)
Slug
mcpsafe-free-mcp-server-security-scanner-mcpsafe-io
Lifecycle last checked
8 Aug 2026
Verification state
Indexed for public listing
Listing state
Listed: yes
Index status
Included in index
Latest evidence snapshot
26 Jun 2026
Timeline basis
Indexed-at chronology. This listing's first-seen date was written by the catalog backfill, not observed here, so it is not treated as a sighting.
Name from
Derived from the project's own page and URL.
Category from
Assigned by a language model.
Summary from
Written by a language model from public pages.
Languages from
Detected by a language model, checked against the page's own declaration.
Canonical URL
https://mcpsafe.io/

Ship this? Send a correction — no account, and you get a link to follow it.

Similar projects

Closest matches by what these projects do

  • MCmcp-guardian-scanpypi.org
  • MCmcpsnarepypi.org
  • MCmcp-check-securitypypi.org
  • MCmcpscan-clipypi.org
  • MCmcpscorepypi.org
  • SHShieldMCPshieldmcp.net

See 18 alternatives to MCPSafe →