{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "plantuml",
    "name": "PlantUML",
    "vendor": "PlantUML project (Arnaud Roques)",
    "vendorUrl": "https://plantuml.com",
    "kind": "sdk",
    "category": "diagramming",
    "summary": "PlantUML is open-source software that turns text descriptions into UML, architecture, Gantt, mind map and other diagrams. Agents run it as a Java command-line tool, a Java library, a local HTTP server or the `@plantuml/mcp-js` MCP server.",
    "url": "https://www.anchorterminal.com/tools/plantuml",
    "markdownUrl": "https://www.anchorterminal.com/tools/plantuml.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/plantuml.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/plantuml.json",
    "repo": "https://github.com/plantuml/plantuml",
    "license": "GPL-3.0-or-later",
    "transports": [],
    "packages": [
      {
        "registry": "maven",
        "name": "net.sourceforge.plantuml:plantuml"
      },
      {
        "registry": "npm",
        "name": "@plantuml/mcp-js"
      },
      {
        "registry": "oci",
        "name": "plantuml/plantuml"
      }
    ],
    "auth": "none",
    "authNotes": "No account, key or login. The jar, the Java library and the MCP server run on the owner's machine with the owner's file and network rights. The built-in `-picoweb` HTTP server has no authentication and listens on all interfaces unless a bind address is given.",
    "pricing": "free",
    "pricingNotes": "Free under GPL-3.0-or-later, with the same source also under GPL-2.0, LGPL, Apache-2.0, BSD-3-Clause, EPL and MIT. Nothing to buy. The project takes donations through GitHub Sponsors and Patreon.",
    "priceSummary": "Free · OSS",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 13356,
      "npmWeekly": 207,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://plantuml.com/command-line",
    "capabilities": [
      "diagram.as-code",
      "diagram.create",
      "diagram.export",
      "diagram.architecture"
    ],
    "tags": [
      "open-source",
      "local",
      "cli",
      "java",
      "mcp",
      "diagram-as-code",
      "uml",
      "no-auth",
      "free",
      "docker"
    ],
    "lastRelease": "2026-09-05",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 66.9,
      "grade": "B",
      "agentReady": false,
      "rank": 251,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 1,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 78,
        "maintenance": 73,
        "payments": 60,
        "reliability": 83,
        "schema": 65,
        "security": 50,
        "transparency": 73
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 83,
          "points": 16.6,
          "reason": "Read with the local-software lines, because PlantUML runs on the owner's machine. Release jars on GitHub and Maven Central, Homebrew at 1.2026.8 and a Docker image, with Java 11 stated as the minimum and a separate Java 8 build (20). The `ci` workflow passed on the last eight pushes to the default branch, the latest on 6 October 2026, and the repository holds 362 Java test classes (25). GitHub's search counts 575 open issues, 17 of them labelled bug. Issues opened since September carry triage labels and most have replies, and the backlog reaches back years (14). CHANGES.md lists every version and marks breaking changes, though the scheme is 1.year.count and not semver as the download page says, and 1.2026.7 changed the default sequence diagram engine in a point release (9). Version 1.2026.8, in a 1.x line since 2017 (15)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 65,
          "points": 10.56,
          "reason": "Read as a CLI and library. No OpenAPI or formal grammar. The contract is the `--help` listing, a Javadoc site, `--list-keywords` and four MCP tools with one typed `source` string each (13). No llms.txt (HTTP 404). Docs pages are HTML, with a PDF guide (2). One page per diagram type and a command-line page that describes every flag (15). Flags are typed in the help text, with formats listed by name (10). Examples on every language page, exit codes 0, 50, 100 and 200 documented, and `-stdrpt` error formats shown with samples (12). CHANGES.md and GitHub release notes for every version. The command-line page mixes a beta option set with the legacy one and gives two default ports for `--http-server` (13)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "One command with text in and a diagram out, or four compact MCP tools (23). `--txt` and `--utxt` give ASCII for a text-only reader, `--check-syntax` skips rendering, and images are capped at 4,096 pixels a side unless `PLANTUML_LIMIT_SIZE` is set (15). Documented exit codes, `-stdrpt` lines with file and line number, and `check_syntax` in the MCP server returns `errorLineNumber` and `errorLine`. The usual message is 'Syntax Error?' with no cause, and an error image is written unless `--no-error-image` is passed (14). Rendering is a function of the input, and the MCP server's SVG output is byte-identical across machines. The four MCP tools carry no `readOnlyHint` (14). `java -jar plantuml.jar file` works with no flags. It needs a Java runtime, and since 1.2026.7 falls back to the built-in Smetana layout when Graphviz is missing. Official surfaces are the Java library and two npm packages (12)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 50,
          "points": 8.75,
          "reason": "No credential exists to leak or scope (20). Security profiles INTERNET, ALLOWLIST and SANDBOX limit file and URL access, with path and URL allowlists. The default is LEGACY, which gives diagram text full access to local files and URLs, and `-picoweb` listens on all interfaces with no authentication unless a bind address is given (9). The tool renders the caller's own text, though `!include` can pull in remote text under the default profile (9). `--verbose` logging only (3). `docs/SECURITY.md` gives an email address for reports. No security.txt (HTTP 404), no bug bounty and no advisories published on the repository. CHANGES.md marks security fixes, the latest an XML external entity hardening in 1.2026.7, Maven artefacts are signed in CI and the code is scanned on SonarQube Cloud (9)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 60,
          "points": 7.5,
          "reason": "Read with the self-hosted rule. Free software with nothing to buy and no payment protocol (0). No price to publish (20). No card or trial needed (20). An agent can download the jar or run the npm package with no signup (20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 73,
          "points": 6.39,
          "reason": "Release 1.2026.8 on 5 September 2026, 33 days before the check (20). Two stable versions in the last 90 days, 1.2026.7 on 25 August and 1.2026.8, plus `@plantuml/mcp-js` 0.2.1 and 0.2.2 and a rolling snapshot build dated 6 October. Two stable versions is one short of the line (12). 200 commits since 21 July 2026 from more than ten authors, the lead maintainer writing 92, and new issues get labels and replies within days (20). Maven Central, Homebrew and Docker Hub all carry 1.2026.8 and npm has `@plantuml/mcp-js` 0.2.2. The server is not in the official MCP registry (12). Dependabot runs daily for Gradle and GitHub Actions, and CI runs on every push (9)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 73,
          "points": 6.39,
          "note": "editorial 73, provenance 73",
          "reason": "GPL-3.0-or-later by default, with the same source under six other open-source licences, and `LICENSES.md` says generated images belong to the author of the diagram text (30). No privacy policy, and the software runs locally. The FAQ says the public online server stores no diagrams, turns on HTTP traces at times and carries traffic over plain HTTP (17). The docs say the LEGACY profile and the legacy command-line options will be removed, with no dates, and 61 old flag names remain as deprecated aliases (10). Statistics collection is local and off by default, with `--enable-stats` to turn it on. We found no network call in the statistics code (16)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "One command with text in and a diagram out, or four compact MCP tools (23). `--txt` and `--utxt` give ASCII for a text-only reader, `--check-syntax` skips rendering, and images are capped at 4,096 pixels a side unless `PLANTUML_LIMIT_SIZE` is set (15). Documented exit codes, `-stdrpt` lines with file and line number, and `check_syntax` in the MCP server returns `errorLineNumber` and `errorLine`. The usual message is 'Syntax Error?' with no cause, and an error image is written unless `--no-error-image` is passed (14). Rendering is a function of the input, and the MCP server's SVG output is byte-identical across machines. The four MCP tools carry no `readOnlyHint` (14). `java -jar plantuml.jar file` works with no flags. It needs a Java runtime, and since 1.2026.7 falls back to the built-in Smetana layout when Graphviz is missing. Official surfaces are the Java library and two npm packages (12).",
          "maintenance": "Release 1.2026.8 on 5 September 2026, 33 days before the check (20). Two stable versions in the last 90 days, 1.2026.7 on 25 August and 1.2026.8, plus `@plantuml/mcp-js` 0.2.1 and 0.2.2 and a rolling snapshot build dated 6 October. Two stable versions is one short of the line (12). 200 commits since 21 July 2026 from more than ten authors, the lead maintainer writing 92, and new issues get labels and replies within days (20). Maven Central, Homebrew and Docker Hub all carry 1.2026.8 and npm has `@plantuml/mcp-js` 0.2.2. The server is not in the official MCP registry (12). Dependabot runs daily for Gradle and GitHub Actions, and CI runs on every push (9).",
          "payments": "Read with the self-hosted rule. Free software with nothing to buy and no payment protocol (0). No price to publish (20). No card or trial needed (20). An agent can download the jar or run the npm package with no signup (20).",
          "reliability": "Read with the local-software lines, because PlantUML runs on the owner's machine. Release jars on GitHub and Maven Central, Homebrew at 1.2026.8 and a Docker image, with Java 11 stated as the minimum and a separate Java 8 build (20). The `ci` workflow passed on the last eight pushes to the default branch, the latest on 6 October 2026, and the repository holds 362 Java test classes (25). GitHub's search counts 575 open issues, 17 of them labelled bug. Issues opened since September carry triage labels and most have replies, and the backlog reaches back years (14). CHANGES.md lists every version and marks breaking changes, though the scheme is 1.year.count and not semver as the download page says, and 1.2026.7 changed the default sequence diagram engine in a point release (9). Version 1.2026.8, in a 1.x line since 2017 (15).",
          "schema": "Read as a CLI and library. No OpenAPI or formal grammar. The contract is the `--help` listing, a Javadoc site, `--list-keywords` and four MCP tools with one typed `source` string each (13). No llms.txt (HTTP 404). Docs pages are HTML, with a PDF guide (2). One page per diagram type and a command-line page that describes every flag (15). Flags are typed in the help text, with formats listed by name (10). Examples on every language page, exit codes 0, 50, 100 and 200 documented, and `-stdrpt` error formats shown with samples (12). CHANGES.md and GitHub release notes for every version. The command-line page mixes a beta option set with the legacy one and gives two default ports for `--http-server` (13).",
          "security": "No credential exists to leak or scope (20). Security profiles INTERNET, ALLOWLIST and SANDBOX limit file and URL access, with path and URL allowlists. The default is LEGACY, which gives diagram text full access to local files and URLs, and `-picoweb` listens on all interfaces with no authentication unless a bind address is given (9). The tool renders the caller's own text, though `!include` can pull in remote text under the default profile (9). `--verbose` logging only (3). `docs/SECURITY.md` gives an email address for reports. No security.txt (HTTP 404), no bug bounty and no advisories published on the repository. CHANGES.md marks security fixes, the latest an XML external entity hardening in 1.2026.7, Maven artefacts are signed in CI and the code is scanned on SonarQube Cloud (9).",
          "transparency": "GPL-3.0-or-later by default, with the same source under six other open-source licences, and `LICENSES.md` says generated images belong to the author of the diagram text (30). No privacy policy, and the software runs locally. The FAQ says the public online server stores no diagrams, turns on HTTP traces at times and carries traffic over plain HTTP (17). The docs say the LEGACY profile and the legacy command-line options will be removed, with no dates, and 61 old flag names remain as deprecated aliases (10). Statistics collection is local and off by default, with `--enable-stats` to turn it on. We found no network call in the statistics code (16)."
        },
        "sources": [
          {
            "what": "repository, README, licences file, CHANGES.md, security policy, CI workflows and source (shallow clone)",
            "url": "https://github.com/plantuml/plantuml",
            "seen": "2026-10-08"
          },
          {
            "what": "command-line options, exit codes, `-stdrpt` and `-pipe`",
            "url": "https://plantuml.com/command-line",
            "seen": "2026-10-08"
          },
          {
            "what": "security profiles and allowlists",
            "url": "https://plantuml.com/security",
            "seen": "2026-10-08"
          },
          {
            "what": "built-in HTTP server",
            "url": "https://plantuml.com/picoweb",
            "seen": "2026-10-08"
          },
          {
            "what": "install requirements and Docker",
            "url": "https://plantuml.com/starting",
            "seen": "2026-10-08"
          },
          {
            "what": "licence options and latest version",
            "url": "https://plantuml.com/download",
            "seen": "2026-10-08"
          },
          {
            "what": "FAQ on licences, the online server and image size limit",
            "url": "https://plantuml.com/faq",
            "seen": "2026-10-08"
          },
          {
            "what": "chronology diagram page, still published",
            "url": "https://plantuml.com/chronology-diagram",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server README and tool definitions",
            "url": "https://github.com/plantuml/plantuml/tree/master/plantuml-mcp-js",
            "seen": "2026-10-08"
          },
          {
            "what": "repository statistics, releases, CI runs, advisories and recent issues",
            "url": "https://api.github.com/repos/plantuml/plantuml",
            "seen": "2026-10-08"
          },
          {
            "what": "npm versions and weekly downloads of the MCP server",
            "url": "https://registry.npmjs.org/@plantuml/mcp-js",
            "seen": "2026-10-08"
          },
          {
            "what": "Maven Central versions",
            "url": "https://repo1.maven.org/maven2/net/sourceforge/plantuml/plantuml/maven-metadata.xml",
            "seen": "2026-10-08"
          },
          {
            "what": "Homebrew formula version",
            "url": "https://formulae.brew.sh/api/formula/plantuml.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Docker Hub image",
            "url": "https://hub.docker.com/r/plantuml/plantuml",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=plantuml",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.verisign.com/com/v1/domain/plantuml.com",
            "seen": "2026-10-08"
          },
          {
            "what": "robots.txt, llms.txt and security.txt checks",
            "url": "https://plantuml.com/robots.txt",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "Whether chronology diagrams will return. The change log calls the February 2026 removal temporary and gives no date",
          "How many of the 575 open issues are crashes or regressions. Only the 30 newest items and the count of 17 labelled bug were read",
          "Whether any security advisory exists outside GitHub. The repository's advisory list is empty and no CVE database was searched",
          "The repository's `package.json` for `@plantuml/mcp-js` says 0.2.0 while npm serves 0.2.2",
          "unchecked: the public online server at www.plantuml.com/plantuml. robots.txt disallows its render paths and it was not called. The listing grades the software the owner runs",
          "unchecked: the Java `plantuml-mcp` server and `plantuml-server`, which are separate repositories and were not read",
          "No legal entity was found. `LICENSES.md` gives the copyright to Arnaud Roques, and no terms or privacy document governs the software"
        ]
      },
      "negative": -2,
      "negativeNotes": [
        "27 February 2026. Release 1.2026.2 switched off chronology diagrams, and its change log calls the removal temporary. On 8 October 2026 the factory is still commented out in `PSystemBuilder.java`, while the README lists the chronology diagram as supported and https://plantuml.com/chronology-diagram documents it. Two points, because the removal is in the change log (https://github.com/plantuml/plantuml/blob/master/CHANGES.md)."
      ],
      "verdict": "One Java command reads diagram text from stdin and writes PNG, SVG, PDF or ASCII with no account, and CI passed on the last eight pushes. The default security profile lets diagram text read any local file and fetch any URL, and the documentation still lists chronology diagrams that release 1.2026.2 switched off.",
      "bestFor": "Agents that write sequence, class, state, component, deployment, Gantt or C4 diagrams as text and render them locally or in CI.",
      "strengths": [
        "`java -jar plantuml.jar -pipe` reads a diagram from stdin and writes PNG, SVG, PDF, EPS, LaTeX or ASCII to stdout, with no account or key",
        "`--check-syntax` and `-stdrpt` report errors as `file:line:error` lines, and exit codes 0, 50, 100 and 200 are documented",
        "The official `@plantuml/mcp-js` server has four tools, needs only Node.js, and returns the same SVG bytes for the same source on any machine",
        "Version 1.2026.8 of 5 September 2026 is on GitHub, Maven Central, Homebrew and Docker Hub, and the `ci` workflow passed on the last eight pushes",
        "The same source is available under GPL-3.0-or-later, GPL-2.0, LGPL, Apache-2.0, BSD-3-Clause, EPL and MIT, and generated images carry no licence obligation"
      ],
      "weaknesses": [
        "The default security profile is LEGACY, which gives diagram text full access to local files and URLs through `!include`. The docs say it will be removed, with no date",
        "`-picoweb` listens on all network interfaces by default and has no authentication",
        "Chronology diagrams were switched off in 1.2026.2 on 27 February 2026 and are still listed in the README and documented on plantuml.com",
        "The command-line page gives the HTTP server's default port as 4242 in one help listing and 8080 in another. The source uses 8080",
        "No llms.txt, no security.txt and no published advisories. The security policy is one email address, and 575 issues are open"
      ],
      "agentNotes": [
        "Set `PLANTUML_SECURITY_PROFILE` to `SANDBOX` or `ALLOWLIST` before rendering text from an untrusted source. The default profile lets `!include` read local files and fetch URLs",
        "Run `java -jar plantuml.jar --check-syntax` with `-stdrpt` first and read the exit status. Without `--no-error-image` a syntax error still writes an image of the error text",
        "Pass `-pipe` with `--svg`, `--txt` or `--utxt` to work without files. `--txt` output suits a text-only model",
        "Start the local server as `-picoweb:8080:127.0.0.1`. Without the bind address it listens on every interface",
        "Use `npx -y @plantuml/mcp-js` when no Java runtime is present. It renders SVG only, so use the jar for PNG or PDF"
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 66.9
        }
      ],
      "editorialScores": {
        "ergonomics": 78,
        "maintenance": 73,
        "payments": 60,
        "reliability": 83,
        "schema": 65,
        "security": 50,
        "transparency": 73
      },
      "provenanceScore": 73
    },
    "connect": {
      "install": "brew install plantuml   # or download plantuml.jar from https://github.com/plantuml/plantuml/releases, or docker run ghcr.io/plantuml/plantuml",
      "config": {
        "mcpServers": {
          "plantuml-js": {
            "args": [
              "-y",
              "@plantuml/mcp-js"
            ],
            "command": "npx"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/diagram.as-code",
      "tool": "https://letme.dev/plantuml"
    },
    "notable": [
      "The official `@plantuml/mcp-js` MCP server, first published on 8 June 2026, compiles the Java engine to JavaScript and has four tools, `plantuml_version`, `check_syntax`, `render_diagram` and `explain_diagram` (https://github.com/plantuml/plantuml/tree/master/plantuml-mcp-js)",
      "The default security profile is LEGACY, with full access to local files and URLs. The security page says it will be removed in a future release and the default will become more restricted (https://plantuml.com/security)",
      "Release 1.2026.2 on 27 February 2026 switched off chronology diagrams, and the README and https://plantuml.com/chronology-diagram still list them (https://github.com/plantuml/plantuml/blob/master/CHANGES.md)",
      "Release 1.2026.7 on 25 August 2026 changed the default sequence diagram engine from Puma to Teoz and falls back to the built-in Smetana layout when Graphviz is missing (https://github.com/plantuml/plantuml/blob/master/CHANGES.md)",
      "The command-line options are being redesigned to GNU style. Legacy options stay for a transition period and are no longer documented (https://plantuml.com/command-line)",
      "The FAQ says the public online server stores no diagrams and that its traffic goes over plain HTTP, and it recommends a local server for sensitive content (https://plantuml.com/faq)"
    ],
    "area": "design-diagrams",
    "details": [
      {
        "label": "Surfaces",
        "value": "CLI `java -jar plantuml.jar`, the Java library `net.sourceforge.plantuml:plantuml`, the built-in `-picoweb` HTTP server, and the `@plantuml/mcp-js` 0.2.2 stdio MCP server for Node.js"
      },
      {
        "label": "Export formats",
        "value": "PNG (default), SVG, PDF, EPS, LaTeX/TikZ, ASCII (`--txt`, `--utxt`), VDX, XMI, SCXML and HTML. The MCP server renders SVG only"
      },
      {
        "label": "Diagram types",
        "value": "Sequence, use case, class, object, activity, component, deployment, state and timing, plus Gantt, mind map, WBS, network, wireframe, Archimate, ER, JSON, YAML, EBNF and regex"
      },
      {
        "label": "Commands",
        "value": "`-pipe` for stdin to stdout, `--check-syntax`, `--stop-on-error`, `--no-error-image`, `-stdrpt`, `--format`, `--output-dir`, `--extract-source` and `--list-keywords`"
      },
      {
        "label": "Exit codes",
        "value": "0 success, 50 no file found, 100 no diagram found, 200 some diagrams have syntax errors"
      },
      {
        "label": "Local HTTP server",
        "value": "`-picoweb[:port[:bind address]]`, default port 8080 on all interfaces. GET `/plantuml/png/`, `/plantuml/svg/`, `/plantuml/txt/` with the encoded diagram, and POST `/render`"
      },
      {
        "label": "Security profiles",
        "value": "UNSECURE, LEGACY (default), INTERNET, ALLOWLIST and SANDBOX, set with `PLANTUML_SECURITY_PROFILE`, plus `plantuml.allowlist.path` and `plantuml.allowlist.url`"
      },
      {
        "label": "Requirements",
        "value": "Java 11 or later, with a separate Java 8 build. Graphviz for some layouts, with the built-in Smetana engine as fallback since 1.2026.7. The MCP server needs only Node.js"
      },
      {
        "label": "Limits",
        "value": "Images are capped at 4,096 pixels a side unless `PLANTUML_LIMIT_SIZE` is set. `--graphviz-timeout` sets the layout timeout"
      },
      {
        "label": "Telemetry",
        "value": "Statistics collection is local and off by default (`--enable-stats`). No network call was found in the statistics code"
      }
    ],
    "provenance": {
      "legalEntity": "No legal entity found. Copyright Arnaud Roques",
      "domain": "plantuml.com",
      "domainRegistered": "2010-11-28",
      "endpointOnVendorDomain": null,
      "terms": "",
      "privacy": "",
      "statusPage": "",
      "changelog": "https://github.com/plantuml/plantuml/blob/master/CHANGES.md",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "`LICENSES.md` reads Copyright (C) 2009-2026, Arnaud Roques. No company or foundation is named in the repository or on the pages read",
        "No terms or privacy document governs the software. The GPL-3.0-or-later licence, or one of the six alternatives, stands in",
        "https://plantuml.com/.well-known/security.txt answered 404 on 8 October 2026. `docs/SECURITY.md` asks for reports by email to a Gmail address",
        "The lead named PlantUML as vendor. It is a community project led by one author, with no company behind it that we found"
      ],
      "score": 73,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "No legal entity found. Copyright Arnaud Roques",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "plantuml.com, registered 2010-11-28 (15 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "no hosted endpoint",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Terms of service",
          "value": "nothing hosted, so the GPL-3.0-or-later licence stands in",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "nothing hosted, not scored",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/plantuml.json"
  }
}
