AI & Agents
VulnClaw
Last updated 2026-07-27 · benchmark measured 2026-08-09 — deterministic & reproducible
VulnClaw is an open-source, AI-driven penetration testing CLI tool for Python 3.10+.
Is VulnClaw production-ready?
Legit.Show scores VulnClaw 66 out of 100 — the simple average of its 7 measured frames. Legit.Show ran its deterministic 7-Frame production-readiness benchmark on VulnClaw (public-surface assessment), measured from the public surface with no LLM in the scoring path. Its strongest frame is Standards; its weakest is Privacy. Every frame it averages is published with its evidence on the Legit.Show listing.
The 7 Frames
- Performance — 62/100
- Accessibility — 85/100
- Security — 45/100
- Privacy — 25/100
- Reliability — 80/100
- Standards — 92/100
- Discoverability — 75/100
What we measured
- Security headers present: HSTS.
- No Content-Security-Policy.
- Served over HTTPS with a valid certificate.
- Real Lighthouse performance run — 240 ms to first byte.
- Returns a proper 404 for unknown routes.
- 1 of 3 sampled routes reachable.
- No privacy policy found.
- Sets cookies / loads scripts with no consent prompt.
Who it's for
Security researchers · Penetration testers · CTF participants · Security engineers · DevSecOps teams
Pricing
Open source, MIT License
Visit VulnClaw → · Alternatives to VulnClaw → · How this was measured →