what if MCP servers had a Lighthouse-style security score?

TL;DR AI
2 min readKey summary
194 packages scanned; 118 had security findings (60.8% failure rate).
MCP Security Score: 72/100.
Subscores — Input validation 18/25; Execution safety 22/25; Environment isolation 14/20; Dependency hygiene 12/15; Output sanitization 6/15.
437K downloads of compromised packages before takedowns; 30 CVEs against MCP packages in the last 60 days.
97M total npm SDK downloads.
