Developer Tools
OpenTrustBench
Last updated 2026-09-11 · benchmark measured 2026-09-11 — deterministic & reproducible
Free, local security scanner that grades AI agents and MCP servers A–F.
Is OpenTrustBench production-ready?
Legit.Show scores OpenTrustBench 57 out of 100 — the simple average of its 5 measured frames. Legit.Show ran its deterministic 7-Frame production-readiness benchmark on OpenTrustBench (public-surface assessment), measured from the public surface with no LLM in the scoring path. Its strongest frame is Discoverability; its weakest is Privacy. 5 of the seven frames returned a score; Performance and Accessibility were not measurable on this service and are recorded as null — not as zero. Every frame it averages is published with its evidence on the Legit.Show listing.
The 7 Frames
- Performance — not measurable on this service (null — not scored as 0)
- Accessibility — not measurable on this service (null — not scored as 0)
- Security — 25/100
- Privacy — 25/100
- Reliability — 92/100
- Standards — 45/100
- Discoverability — 100/100
What we measured
- No Content-Security-Policy and no HSTS.
- Served over HTTPS with a valid certificate.
- Real Lighthouse performance run — 157 ms to first byte.
- Returns a proper 404 for unknown routes.
- 0 of 0 sampled routes reachable.
- No privacy policy found.
- Sets cookies / loads scripts with no consent prompt.
- Discoverable: structured data, sitemap, OpenGraph image, canonical URL.
Who it's for
AI agent developers · MCP server maintainers · Security teams · DevOps engineers · Open source projects
Pricing
Free forever - CLI is free with unlimited local scans, no account required, open source (Apache-2.0)
Visit OpenTrustBench → · Alternatives to OpenTrustBench → · How this was measured →