AI & Agents
VulnClaw
Last updated 2026-07-27 · benchmark measured 2026-07-27 — deterministic & reproducible
VulnClaw is an open-source, AI-driven penetration testing CLI tool for Python 3.10+.
Overall production-readiness score — reserved
Legit.Show benchmarked VulnClaw across all seven frames. The single overall score is shown to the verified maker; the frame-by-frame breakdown is public below.
Is VulnClaw production-ready?
Legit.Show ran its deterministic 7-Frame production-readiness benchmark on VulnClaw (public-surface assessment), measured from the public surface with no LLM in the scoring path. Its strongest frame is Standards; its weakest is Privacy. The per-frame breakdown is public on the Legit.Show listing; the single overall production-readiness score is reserved for the verified maker.
The 7 Frames
- Performance — 62/100
- Accessibility — 85/100
- Security — 45/100
- Privacy — 25/100
- Reliability — 80/100
- Standards — 92/100
- Discoverability — 75/100
What we measured
- Security headers present: HSTS.
- No Content-Security-Policy.
- Served over HTTPS with a valid certificate.
- Real Lighthouse performance run — 126 ms to first byte.
- Returns a proper 404 for unknown routes.
- 1 of 3 sampled routes reachable.
- No privacy policy found.
- Sets cookies / loads scripts with no consent prompt.
Who it's for
Security researchers · Penetration testers · CTF participants · Security engineers · DevSecOps teams
Pricing
Open source, MIT License