{
  "fixes": {
    "slug": "strapi",
    "name": "Strapi",
    "listing": "https://www.anchorterminal.com/tools/strapi",
    "markdown": "# Fix list: Strapi\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/strapi, the October 2026 research run, assessed 7 October 2026. Grade B, 65.7 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on Strapi: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Payments \u0026 pricing, 50 out of 100, up to 6.3 more on the total\n\nWhy it scored 50: Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). The Community Edition is free, Growth is $45 a month, and Strapi Cloud lists $35, $90 and $450 a project a month with $1.50 per further 25,000 API requests, all public (20). The Community Edition needs no card and Growth has a 30-day trial without one. Strapi Cloud asks for a card at project creation (20). Install and the first administrator can be scripted (`create-strapi`, `strapi admin:create-user`) with no account at Strapi, but the docs create API and Admin tokens only in the admin panel, so half (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 2. Security \u0026 auth, 66 out of 100, up to 6 more on the total\n\nWhy it scored 66: API tokens are read-only, full access or custom per content type and action. Admin tokens hold a chosen subset of the owner's permissions down to field and locale. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel only in the Authorization header. No OAuth (28 of 30). Read-only tokens hide every write tool, permissions are checked again at run time, MCP create writes a draft and media deletes preview first. Nothing asks a person to approve a publish or a delete, and Review Workflows are Enterprise only (15 of 20). Entries hold text written by other people, and we found no prompt-injection guidance in the MCP docs. Media responses are cut to an allowlist of fields (3 of 15). Audit Logs mark MCP actions with `origin: mcp` but need the Enterprise plan and skip reads (7 of 15). SECURITY.md sets supported versions and a GitHub advisory route, advisories are published with CVEs, and the security page says SOC 2 certified. No bug bounty by stated policy, and strapi.io/.well-known/security.txt returned 404 (13 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 3. Agent ergonomics, 65 out of 100, up to 5.7 more on the total\n\nWhy it scored 65: A project with five collection types and Draft \u0026 Publish exposes about 50 MCP tools, 40 generated plus 10 for media, which is the more-than-30 band (5). We added 8 because a token only sees the tools its permissions allow, so a narrow token cuts the list, and 2 for REST `fields` selection (15 of 25). Page and offset pagination with a default of 25, filters with more than 20 operators, sort and field selection (20). One error shape with status, name, message and details, and partial-failure reports on bulk media tools (16 of 20). No idempotency keys, and we found no `readOnlyHint` or `destructiveHint` in the MCP source. PUT by `documentId` is repeatable and media deletes have `dryRun` (6 of 20). Few required parameters and sensible defaults, with one official client library, @strapi/client for JavaScript (8 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 4. Reliability, 82 out of 100, up to 3.6 more on the total\n\nWhy it scored 82: Read with the local-software lines, since the graded surface is the Community Edition its owner hosts. Strapi Cloud's status page isn't scored here. Official npm packages, with Node.js 20 to 26 stated in `engines` (20). A Tests workflow runs unit, API, CLI and end-to-end suites. The latest push run on develop passed on 7 October 2026, and on main the 30 September run passed and the 7 October run failed (20 of 25). 217 open issues, 45 labelled severity high and one critical, with 283 closed against 208 opened since 9 July (15 of 25). Semver releases with notes per version and each v5 breaking change documented on its own page, but OpenAPI generation is declared outside semver (12 of 15). 5.x is the stable line and SECURITY.md marks it LTS (15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 5. Schema \u0026 documentation, 80 out of 100, up to 3.3 more on the total\n\nWhy it scored 80: No published OpenAPI file, because endpoints depend on each project's content types. `strapi openapi generate` writes an OpenAPI 3.1.0 file for a project and is marked experimental, and every MCP tool carries JSON Schema 2020-12 input and output schemas built from the content model (20 of 25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). The 10 media tools say when to use each one and when not to, while generated content tools get a single line such as `Content-manager list for api::article.article` (14 of 20). Schemas are narrowed per field, action and locale and sort values are enums, but dynamic zones are untyped arrays and circular components fall back to an open record (12 of 15). REST pages pair curl examples with responses, and the error format and error classes are documented, without a list of status codes per endpoint (12 of 15). Semver with release notes on GitHub. The REST paths carry no API version (12 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 6. Transparency \u0026 trust, 72 out of 100, up to 2.5 more on the total\n\nMade of editorial 75, provenance 68.\n\nWhy it scored 72: MIT for the Community Edition, with ee/ directories under a separate Enterprise Edition licence that the LICENSE file explains (26 of 30). A self-hosted install keeps content on its owner's servers. For Strapi Cloud the terms delete customer content at termination but keep backups for unstated \"standard periods\", a DPA dated 21 November 2024 is part of the cloud terms, and the privacy policy is dated 1 March 2023. The Cloud Policies still describe a Free plan that the pricing page and docs no longer list (20 of 30). SECURITY.md dates each major's support, with v4 ended in October 2025 and security fixes until April 2026, and v5 breaking changes are documented one by one. No stated notice period for API changes (14 of 20). Telemetry is on by default and documented with an opt-out command and flag. The MCP usage events added in May 2026 aren't named on that page (15 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Endpoint on the vendor's domain:  is not on strapi.io (0 of 15)\n- Terms of service: read, states 7 of the 7 things a reader expects, and has 3 clauses that cost points (4 of 10)\n- Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10)\n- security.txt: not found (0 of 10)\n\n## 7. Maintenance \u0026 community, 87 out of 100, up to 1.1 more on the total\n\nWhy it scored 87: v5.57.0 was tagged and published to npm on 7 October 2026, the day of this check (30). 13 tagged versions between 15 July and 7 October, about one a week (20). 283 issues closed against 208 opened since 9 July, and the newest pull requests carry labels and a reply the same day. 217 issues stay open, 45 labelled severity high (18 of 25). @strapi/client 1.6.2 dates from 4 June 2026 and is the only official client. The official MCP registry lists third-party Strapi servers only, which fits a server built into the product (10 of 15). Dependabot pull requests open daily and CI runs on every push. The 7 October Tests run on main failed (9 of 10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## Deductions\n\nEach comes off the total. A fixed and documented problem counts for less at the next check.\n\n- 13 May 2026. Strapi published two critical advisories. GHSA-rjg2-95x7-8qmx (CVE-2026-27886) leaked sensitive data through relation filters in versions 4.0.0 to 5.36.1, and GHSA-3xcq-8mjw-h6mx (CVE-2026-22599) was SQL injection in the Content-Type Builder up to 5.33.1 and 4.26.0. Both were fixed in earlier releases (5.37.0, 5.33.2 and 4.26.1) and published by the vendor, and we found no report of exploitation, so we deduct 6 of a possible 15. https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx ; https://github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: strapi.io refused our shell requests with a CloudFront 403, so pricing, security, privacy and cloud terms were read through a page reader's summary and not as raw text\n- unchecked: the third-party service provider list linked from the privacy policy (a Notion page) and Strapi Cloud's hosting providers\n- unchecked: what the SOC 2 claim on strapi.io/security covers (type, scope and report date)\n- unchecked: the answer to the responsible disclosure question on strapi.io/security, which our reader didn't return\n- The Cloud Policies (effective 10 July 2026) describe a Free plan with 2,500 API requests a month, while the pricing page and docs list only Starter, Pro and Business. We treated Strapi Cloud as having no free plan\n- The MCP server's first version (5.47.0) is inferred from the 27 May 2026 commit and the npm publish date of 28 May, not from a release note we read\n- We didn't run an instance, so MCP tool counts and annotations come from the docs and the source at v5.57.0\n- The dossier grades the self-hosted Community Edition. A reader on Strapi Cloud should weigh the status history and the card requirement noted for reviewers\n\n## Weaknesses\n\n- Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans\n- Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed\n- A REST POST or PUT publishes immediately unless the request passes `status=draft`\n- The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations\n- Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once\n- Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes\n- Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload\n- Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`\n- Keep your own copy of an entry before updating it. API and MCP writes create no Content History version\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "B",
    "score": 65.7,
    "assessed": "2026-10-07",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 50,
        "maxGain": 6.3,
        "reason": "Scored with the self-hosted rule, taking prices from the paid options beside the free edition. No x402, MPP or L402 (0). The Community Edition is free, Growth is $45 a month, and Strapi Cloud lists $35, $90 and $450 a project a month with $1.50 per further 25,000 API requests, all public (20). The Community Edition needs no card and Growth has a 30-day trial without one. Strapi Cloud asks for a card at project creation (20). Install and the first administrator can be scripted (`create-strapi`, `strapi admin:create-user`) with no account at Strapi, but the docs create API and Admin tokens only in the admin panel, so half (10).",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 66,
        "maxGain": 6,
        "reason": "API tokens are read-only, full access or custom per content type and action. Admin tokens hold a chosen subset of the owner's permissions down to field and locale. Both expire after 7, 30 or 90 days or never, can be regenerated, and travel only in the Authorization header. No OAuth (28 of 30). Read-only tokens hide every write tool, permissions are checked again at run time, MCP create writes a draft and media deletes preview first. Nothing asks a person to approve a publish or a delete, and Review Workflows are Enterprise only (15 of 20). Entries hold text written by other people, and we found no prompt-injection guidance in the MCP docs. Media responses are cut to an allowlist of fields (3 of 15). Audit Logs mark MCP actions with `origin: mcp` but need the Enterprise plan and skip reads (7 of 15). SECURITY.md sets supported versions and a GitHub advisory route, advisories are published with CVEs, and the security page says SOC 2 certified. No bug bounty by stated policy, and strapi.io/.well-known/security.txt returned 404 (13 of 20).",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 65,
        "maxGain": 5.7,
        "reason": "A project with five collection types and Draft \u0026 Publish exposes about 50 MCP tools, 40 generated plus 10 for media, which is the more-than-30 band (5). We added 8 because a token only sees the tools its permissions allow, so a narrow token cuts the list, and 2 for REST `fields` selection (15 of 25). Page and offset pagination with a default of 25, filters with more than 20 operators, sort and field selection (20). One error shape with status, name, message and details, and partial-failure reports on bulk media tools (16 of 20). No idempotency keys, and we found no `readOnlyHint` or `destructiveHint` in the MCP source. PUT by `documentId` is repeatable and media deletes have `dryRun` (6 of 20). Few required parameters and sensible defaults, with one official client library, @strapi/client for JavaScript (8 of 15).",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 82,
        "maxGain": 3.6,
        "reason": "Read with the local-software lines, since the graded surface is the Community Edition its owner hosts. Strapi Cloud's status page isn't scored here. Official npm packages, with Node.js 20 to 26 stated in `engines` (20). A Tests workflow runs unit, API, CLI and end-to-end suites. The latest push run on develop passed on 7 October 2026, and on main the 30 September run passed and the 7 October run failed (20 of 25). 217 open issues, 45 labelled severity high and one critical, with 283 closed against 208 opened since 9 July (15 of 25). Semver releases with notes per version and each v5 breaking change documented on its own page, but OpenAPI generation is declared outside semver (12 of 15). 5.x is the stable line and SECURITY.md marks it LTS (15).",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 80,
        "maxGain": 3.3,
        "reason": "No published OpenAPI file, because endpoints depend on each project's content types. `strapi openapi generate` writes an OpenAPI 3.1.0 file for a project and is marked experimental, and every MCP tool carries JSON Schema 2020-12 input and output schemas built from the content model (20 of 25). llms.txt, llms-full.txt and a Markdown copy of every docs page (10). The 10 media tools say when to use each one and when not to, while generated content tools get a single line such as `Content-manager list for api::article.article` (14 of 20). Schemas are narrowed per field, action and locale and sort values are enums, but dynamic zones are untyped arrays and circular components fall back to an open record (12 of 15). REST pages pair curl examples with responses, and the error format and error classes are documented, without a list of status codes per endpoint (12 of 15). Semver with release notes on GitHub. The REST paths carry no API version (12 of 15).",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 72,
        "maxGain": 2.5,
        "reason": "MIT for the Community Edition, with ee/ directories under a separate Enterprise Edition licence that the LICENSE file explains (26 of 30). A self-hosted install keeps content on its owner's servers. For Strapi Cloud the terms delete customer content at termination but keep backups for unstated \"standard periods\", a DPA dated 21 November 2024 is part of the cloud terms, and the privacy policy is dated 1 March 2023. The Cloud Policies still describe a Free plan that the pricing page and docs no longer list (20 of 30). SECURITY.md dates each major's support, with v4 ended in October 2025 and security fixes until April 2026, and v5 breaking changes are documented one by one. No stated notice period for API changes (14 of 20). Telemetry is on by default and documented with an opt-out command and flag. The MCP usage events added in May 2026 aren't named on that page (15 of 20).",
        "blend": "editorial 75, provenance 68",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 87,
        "maxGain": 1.1,
        "reason": "v5.57.0 was tagged and published to npm on 7 October 2026, the day of this check (30). 13 tagged versions between 15 July and 7 October, about one a week (20). 283 issues closed against 208 opened since 9 July, and the newest pull requests carry labels and a reply the same day. 217 issues stay open, 45 labelled severity high (18 of 25). @strapi/client 1.6.2 dates from 4 June 2026 and is the only official client. The official MCP registry lists third-party Strapi servers only, which fits a server built into the product (10 of 15). Dependabot pull requests open daily and CI runs on every push. The 7 October Tests run on main failed (9 of 10).",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      }
    ],
    "provenance": [
      {
        "label": "Endpoint on the vendor's domain",
        "value": " is not on strapi.io",
        "points": 0,
        "max": 15
      },
      {
        "label": "Terms of service",
        "value": "read, states 7 of the 7 things a reader expects, and has 3 clauses that cost points",
        "points": 4,
        "max": 10
      },
      {
        "label": "Privacy policy",
        "value": "read, states 6 of the 8 things a reader expects",
        "points": 8.5,
        "max": 10
      },
      {
        "label": "security.txt",
        "value": "not found",
        "points": 0,
        "max": 10
      }
    ],
    "deductions": [
      "13 May 2026. Strapi published two critical advisories. GHSA-rjg2-95x7-8qmx (CVE-2026-27886) leaked sensitive data through relation filters in versions 4.0.0 to 5.36.1, and GHSA-3xcq-8mjw-h6mx (CVE-2026-22599) was SQL injection in the Content-Type Builder up to 5.33.1 and 4.26.0. Both were fixed in earlier releases (5.37.0, 5.33.2 and 4.26.1) and published by the vendor, and we found no report of exploitation, so we deduct 6 of a possible 15. https://github.com/strapi/strapi/security/advisories/GHSA-rjg2-95x7-8qmx ; https://github.com/strapi/strapi/security/advisories/GHSA-3xcq-8mjw-h6mx"
    ],
    "unchecked": [
      "unchecked: strapi.io refused our shell requests with a CloudFront 403, so pricing, security, privacy and cloud terms were read through a page reader's summary and not as raw text",
      "unchecked: the third-party service provider list linked from the privacy policy (a Notion page) and Strapi Cloud's hosting providers",
      "unchecked: what the SOC 2 claim on strapi.io/security covers (type, scope and report date)",
      "unchecked: the answer to the responsible disclosure question on strapi.io/security, which our reader didn't return",
      "The Cloud Policies (effective 10 July 2026) describe a Free plan with 2,500 API requests a month, while the pricing page and docs list only Starter, Pro and Business. We treated Strapi Cloud as having no free plan",
      "The MCP server's first version (5.47.0) is inferred from the 27 May 2026 commit and the npm publish date of 28 May, not from a release note we read",
      "We didn't run an instance, so MCP tool counts and annotations come from the docs and the source at v5.57.0",
      "The dossier grades the self-hosted Community Edition. A reader on Strapi Cloud should weigh the status history and the card requirement noted for reviewers"
    ],
    "weaknesses": [
      "Content History keeps no version for REST, GraphQL or MCP writes, and exists only on Growth and Enterprise plans",
      "Audit Logs and Review Workflows are Enterprise only, so the free edition has no record of what an agent changed",
      "A REST POST or PUT publishes immediately unless the request passes `status=draft`",
      "The MCP server can't upload files, describes dynamic zones as untyped arrays and sets no read-only or destructive annotations",
      "Two critical advisories were published on 13 May 2026, a data leak through relation filters and SQL injection in the Content-Type Builder, both fixed earlier"
    ],
    "agentNotes": [
      "Pass `status=draft` on every REST POST and PUT. Without it the Content API publishes the entry at once",
      "Use an Admin token for `/mcp` and admin routes and an API token for `/api`. Each kind is rejected on the other's routes",
      "Upload files with multipart POST to `/api/upload` first, then reference the returned file id in the entry. MCP tools can't upload",
      "Call `media_delete_assets` and `media_delete_folder` without `dryRun` first to preview, and take asset ids only from `media_list_assets`",
      "Keep your own copy of an entry before updating it. API and MCP writes create no Content History version"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
