StillOS Digital Holdings · Neutral Ratings

RatingsFindingsDependency floorDirectoryPricingMethodologyExternal view

The MCP dependency floor

Every MCP trust index grades servers. This grades the ground they stand on. Measured 2026-10-03 · population 10,071 servers · 90 packages profiled, 90 resolved, 0 undetermined.

The finding

13 packages sit beneath ~80% of the 10,071 MCP servers we measure, are controlled by exactly one maintainer, and have not been published in 5+ years. 8 individuals solely control all 13 of them.

These are not MCP servers. They are the transitive dependencies underneath them — which is why a per-server scan cannot surface them: a single-maintainer bottleneck under eight thousand servers is a property of the dependency graph, not of any one package. That is the xz-utils shape: the surface was never the application, it was the sole dormant maintainer beneath thousands of them.

Criterion — exactly 1 maintainer AND last publish >= 5 years before as_of
packageMCP serversreachmaintainersdormantlast publishsole maintainer
once8,18181.23%110.1y2016-09-06isaacs
wrappy8,18181.23%110.4y2016-05-17isaacs
path-key8,09280.35%15.5y2021-04-09sindresorhus
shebang-command8,08480.27%17.1y2019-09-06kevva
shebang-regex8,08480.27%15.1y2021-08-13sindresorhus
safer-buffer8,06880.11%18.5y2018-04-08chalker
inherits8,05579.98%17.3y2019-06-19isaacs
depd8,04879.91%17.9y2018-10-26dougwilson
escape-html8,04879.91%111.1y2015-09-01dougwilson
setprototypeof8,04879.91%17.2y2019-07-18wesleytodd
fast-deep-equal7,95378.97%16.3y2020-06-08esp
require-from-string7,95378.97%18.5y2018-04-09floatdrop
json-schema-traverse7,94878.92%15.8y2020-12-13esp
Negative controls — 14 packages, same reach, same sole control, ACTIVELY maintained

Sole maintainership is not the finding. These carry the same ~80% reach with one maintainer and ship within the year. The finding is the conjunction of reach, sole control and multi-year dormancy — the controls are published here so the criterion can be checked against cases it must not fire on.

packageMCP serversreachmaintainersdormantlast publishsole maintainer
zod8,53484.74%10.1y2026-09-13colinhacks
@hono/node-server8,13380.76%10y2026-09-29yusukebe
jose8,11080.53%10.1y2026-09-05panva
isexe8,08780.3%10.6y2026-02-09isaacs
eventsource-parser8,08680.29%10y2026-09-15rexxars
es-object-atoms8,08280.25%10.4y2026-05-22ljharb
pkce-challenge8,08180.24%10.7y2026-02-01crouchcd
side-channel8,05179.94%10.3y2026-06-08ljharb
side-channel-list8,05179.94%10.5y2026-04-08ljharb
hono8,05079.93%10y2026-09-30yusukebe
ipaddr.js8,04879.91%10.2y2026-08-04whitequark
ip-address7,93078.74%10y2026-10-01beaugunderson
zod-to-json-schema7,91678.6%10.5y2026-03-27stefan-terdell
json-schema-typed7,91078.54%10.9y2025-11-17remyrylan
Maintainer concentration
individualchokepointspackages
isaacs3once · wrappy · inherits
sindresorhus2path-key · shebang-regex
dougwilson2depd · escape-html
esp2fast-deep-equal · json-schema-traverse
kevva1shebang-command
chalker1safer-buffer
wesleytodd1setprototypeof
floatdrop1require-from-string
What is already known — this contributes to an active literature

Dependency monoculture in MCP is not news and is not presented here as news. The work below established it, and is cited first deliberately.

workcontribution
arXiv 2509.25292Multi-market crawl, 8,401 valid projects; names dependency monoculture as a structural risk
MCPwnDeep scan of 14 servers; all five CRITICAL packages were single-maintainer
arXiv 2506.13538MCP at First Glance — first large-scale study (1,899 servers); frames transitive-dependency risk
arXiv 2510.16558DSN 2026 — 67,057 servers across six registries, SDK-based dependency filtering
DEV registry study6,030 servers; median 94 packages per server; 88% pull an HTTP framework into a stdio process
StacklokThe 2025 npm compromises hit indirect dependencies of the official MCP TypeScript SDK

What this page adds, specifically: the maintainer-concentration cut — that 8 named individuals solely control all 13 dormant chokepoints; the published negative controls, so the criterion can be checked against the cases it must not fire on; and a dated measurement, re-taken on a schedule, because a day nobody recorded cannot be backfilled by anyone. It does not claim to have discovered that MCP depends on a narrow base.

How to check this yourself

Reach is measured against our own dated MCP census; maintainer count and last-publish date come from public npm registry metadata and are re-derivable by anyone with npm view <pkg> maintainers time.modified. Machine-readable: /floor.json. The as_of date is stamped by the producer that collected the data, never by the page that renders it.

Exposure, not accusation. This asserts measured reach, maintainer count and publish recency. It asserts no wrongdoing by any maintainer and no vulnerability in any package. A dormant package is not a compromised package — it is an unattended one, and the distinction is the entire point of publishing the negative controls beside the hits.

© Still OS Digital Holdings LLC · Wyoming · Rating methodology · Pricing · Verify any figure · info@stillosdigitalholdings.com