PlantUML

by PlantUML project (Arnaud Roques) SDK + MCP in Diagramming

No legal entity found. Copyright Arnaud Roques · plantuml.com since 2010 · who's behind it

PlantUML is open-source software that turns text descriptions into UML, architecture, Gantt, mind map and other diagrams. Agents run it as a Java command-line tool, a Java library, a local HTTP server or the @plantuml/mcp-js MCP server.

Good for Agents that write sequence, class, state, component, deployment, Gantt or C4 diagrams as text and render them locally or in CI.

Is this your product? Claim this listing or verify it

Assessment. One Java command reads diagram text from stdin and writes PNG, SVG, PDF or ASCII with no account, and CI passed on the last eight pushes. The default security profile lets diagram text read any local file and fetch any URL, and the documentation still lists chronology diagrams that release 1.2026.2 switched off.

Facts

Auth
None
Pricing
Free · Free · OSS
x402
No
Licence
GPL-3.0-or-later
Packages
maven net.sourceforge.plantuml:plantuml
npm @plantuml/mcp-js
oci plantuml/plantuml
llms.txt
not found
Last release
GitHub stars
13k
npm / week
207
Surfaces
CLI java -jar plantuml.jar, the Java library net.sourceforge.plantuml:plantuml, the built-in -picoweb HTTP server, and the @plantuml/mcp-js 0.2.2 stdio MCP server for Node.js
Export formats
PNG (default), SVG, PDF, EPS, LaTeX/TikZ, ASCII (--txt, --utxt), VDX, XMI, SCXML and HTML. The MCP server renders SVG only
Diagram types
Sequence, use case, class, object, activity, component, deployment, state and timing, plus Gantt, mind map, WBS, network, wireframe, Archimate, ER, JSON, YAML, EBNF and regex
Commands
-pipe for stdin to stdout, --check-syntax, --stop-on-error, --no-error-image, -stdrpt, --format, --output-dir, --extract-source and --list-keywords
Exit codes
0 success, 50 no file found, 100 no diagram found, 200 some diagrams have syntax errors
Local HTTP server
-picoweb[:port[:bind address]], default port 8080 on all interfaces. GET /plantuml/png/, /plantuml/svg/, /plantuml/txt/ with the encoded diagram, and POST /render
Security profiles
UNSECURE, LEGACY (default), INTERNET, ALLOWLIST and SANDBOX, set with PLANTUML_SECURITY_PROFILE, plus plantuml.allowlist.path and plantuml.allowlist.url
Requirements
Java 11 or later, with a separate Java 8 build. Graphviz for some layouts, with the built-in Smetana engine as fallback since 1.2026.7. The MCP server needs only Node.js
Limits
Images are capped at 4,096 pixels a side unless PLANTUML_LIMIT_SIZE is set. --graphviz-timeout sets the layout timeout
Telemetry
Statistics collection is local and off by default (--enable-stats). No network call was found in the statistics code

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • java -jar plantuml.jar -pipe reads a diagram from stdin and writes PNG, SVG, PDF, EPS, LaTeX or ASCII to stdout, with no account or key
  • --check-syntax and -stdrpt report errors as file:line:error lines, and exit codes 0, 50, 100 and 200 are documented
  • The official @plantuml/mcp-js server has four tools, needs only Node.js, and returns the same SVG bytes for the same source on any machine
  • Version 1.2026.8 of 5 September 2026 is on GitHub, Maven Central, Homebrew and Docker Hub, and the ci workflow passed on the last eight pushes
  • The same source is available under GPL-3.0-or-later, GPL-2.0, LGPL, Apache-2.0, BSD-3-Clause, EPL and MIT, and generated images carry no licence obligation

Weaknesses

  • The default security profile is LEGACY, which gives diagram text full access to local files and URLs through !include. The docs say it will be removed, with no date
  • -picoweb listens on all network interfaces by default and has no authentication
  • Chronology diagrams were switched off in 1.2026.2 on 27 February 2026 and are still listed in the README and documented on plantuml.com
  • The command-line page gives the HTTP server's default port as 4242 in one help listing and 8080 in another. The source uses 8080
  • No llms.txt, no security.txt and no published advisories. The security policy is one email address, and 575 issues are open

Before you call it notes for agents

  1. Set PLANTUML_SECURITY_PROFILE to SANDBOX or ALLOWLIST before rendering text from an untrusted source. The default profile lets !include read local files and fetch URLs
  2. Run java -jar plantuml.jar --check-syntax with -stdrpt first and read the exit status. Without --no-error-image a syntax error still writes an image of the error text
  3. Pass -pipe with --svg, --txt or --utxt to work without files. --txt output suits a text-only model
  4. Start the local server as -picoweb:8080:127.0.0.1. Without the bind address it listens on every interface
  5. Use npx -y @plantuml/mcp-js when no Java runtime is present. It renders SVG only, so use the jar for PNG or PDF

Who's behind it provenance 73/100

  • Legal entity namedNo legal entity found. Copyright Arnaud Roques20/20
  • Domain ageplantuml.com, registered 2010-11-28 (15 years)15/15
  • Endpoint on the vendor's domainno hosted endpointn/a
  • Terms of servicenothing hosted, so the GPL-3.0-or-later licence stands in10/10
  • Privacy policynothing hosted, not scoredn/a
  • Status pagenot found0/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service none to read

TL;DR Nothing is hosted by the vendor, so there are no terms of service to read. The GPL-3.0-or-later licence stands in and the check scores in full.

Privacy policy none to read

TL;DR Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored.

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

LICENSES.md reads Copyright (C) 2009-2026, Arnaud Roques. No company or foundation is named in the repository or on the pages read

No terms or privacy document governs the software. The GPL-3.0-or-later licence, or one of the six alternatives, stands in

https://plantuml.com/.well-known/security.txt answered 404 on 8 October 2026. docs/SECURITY.md asks for reports by email to a Gmail address

The lead named PlantUML as vendor. It is a community project led by one author, with no company behind it that we found

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Notable

  • The official @plantuml/mcp-js MCP server, first published on 8 June 2026, compiles the Java engine to JavaScript and has four tools, plantuml_version, check_syntax, render_diagram and explain_diagram source
  • The default security profile is LEGACY, with full access to local files and URLs. The security page says it will be removed in a future release and the default will become more restricted source
  • Release 1.2026.2 on 27 February 2026 switched off chronology diagrams, and the README and https://plantuml.com/chronology-diagram still list them source
  • Release 1.2026.7 on 25 August 2026 changed the default sequence diagram engine from Puma to Teoz and falls back to the built-in Smetana layout when Graphviz is missing source
  • The command-line options are being redesigned to GNU style. Legacy options stay for a transition period and are no longer documented source
  • The FAQ says the public online server stores no diagrams and that its traffic goes over plain HTTP, and it recommends a local server for sensitive content source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 16.6
Read with the local-software lines, because PlantUML runs on the owner's machine. Release jars on GitHub and Maven Central, Homebrew at 1.2026.8 and a Docker image, with Java 11 stated as the minimum and a separate Java 8 build (20). The ci workflow passed on the last eight pushes to the default branch, the latest on 6 October 2026, and the repository holds 362 Java test classes (25). GitHub's search counts 575 open issues, 17 of them labelled bug. Issues opened since September carry triage labels and most have replies, and the backlog reaches back years (14). CHANGES.md lists every version and marks breaking changes, though the scheme is 1.year.count and not semver as the download page says, and 1.2026.7 changed the default sequence diagram engine in a point release (9). Version 1.2026.8, in a 1.x line since 2017 (15).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 10.6
Read as a CLI and library. No OpenAPI or formal grammar. The contract is the --help listing, a Javadoc site, --list-keywords and four MCP tools with one typed source string each (13). No llms.txt (HTTP 404). Docs pages are HTML, with a PDF guide (2). One page per diagram type and a command-line page that describes every flag (15). Flags are typed in the help text, with formats listed by name (10). Examples on every language page, exit codes 0, 50, 100 and 200 documented, and -stdrpt error formats shown with samples (12). CHANGES.md and GitHub release notes for every version. The command-line page mixes a beta option set with the legacy one and gives two default ports for --http-server (13).
Agent ergonomics 13%16.2 12.7
One command with text in and a diagram out, or four compact MCP tools (23). --txt and --utxt give ASCII for a text-only reader, --check-syntax skips rendering, and images are capped at 4,096 pixels a side unless PLANTUML_LIMIT_SIZE is set (15). Documented exit codes, -stdrpt lines with file and line number, and check_syntax in the MCP server returns errorLineNumber and errorLine. The usual message is 'Syntax Error?' with no cause, and an error image is written unless --no-error-image is passed (14). Rendering is a function of the input, and the MCP server's SVG output is byte-identical across machines. The four MCP tools carry no readOnlyHint (14). java -jar plantuml.jar file works with no flags. It needs a Java runtime, and since 1.2026.7 falls back to the built-in Smetana layout when Graphviz is missing. Official surfaces are the Java library and two npm packages (12).
Security & auth 14%17.5 8.8
No credential exists to leak or scope (20). Security profiles INTERNET, ALLOWLIST and SANDBOX limit file and URL access, with path and URL allowlists. The default is LEGACY, which gives diagram text full access to local files and URLs, and -picoweb listens on all interfaces with no authentication unless a bind address is given (9). The tool renders the caller's own text, though !include can pull in remote text under the default profile (9). --verbose logging only (3). docs/SECURITY.md gives an email address for reports. No security.txt (HTTP 404), no bug bounty and no advisories published on the repository. CHANGES.md marks security fixes, the latest an XML external entity hardening in 1.2026.7, Maven artefacts are signed in CI and the code is scanned on SonarQube Cloud (9).
Payments & pricing 10%12.5 7.5
Read with the self-hosted rule. Free software with nothing to buy and no payment protocol (0). No price to publish (20). No card or trial needed (20). An agent can download the jar or run the npm package with no signup (20).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 6.4
Release 1.2026.8 on 5 September 2026, 33 days before the check (20). Two stable versions in the last 90 days, 1.2026.7 on 25 August and 1.2026.8, plus @plantuml/mcp-js 0.2.1 and 0.2.2 and a rolling snapshot build dated 6 October. Two stable versions is one short of the line (12). 200 commits since 21 July 2026 from more than ten authors, the lead maintainer writing 92, and new issues get labels and replies within days (20). Maven Central, Homebrew and Docker Hub all carry 1.2026.8 and npm has @plantuml/mcp-js 0.2.2. The server is not in the official MCP registry (12). Dependabot runs daily for Gradle and GitHub Actions, and CI runs on every push (9).
Transparency & trusteditorial 73, provenance 73 7%8.8 6.4
GPL-3.0-or-later by default, with the same source under six other open-source licences, and LICENSES.md says generated images belong to the author of the diagram text (30). No privacy policy, and the software runs locally. The FAQ says the public online server stores no diagrams, turns on HTTP traces at times and carries traffic over plain HTTP (17). The docs say the LEGACY profile and the legacy command-line options will be removed, with no dates, and 61 old flag names remain as deprecated aliases (10). Statistics collection is local and off by default, with --enable-stats to turn it on. We found no network call in the statistics code (16).
Negative events≤15-2
Total66.9 · B

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 17 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on PlantUML, or have the agent fetch /fixes/plantuml.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: PlantUML

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/plantuml, the October 2026 research run, assessed 8 October 2026. Grade B, 66.9 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on PlantUML: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Security & auth, 50 out of 100, up to 8.8 more on the total

Why it scored 50: No credential exists to leak or scope (20). Security profiles INTERNET, ALLOWLIST and SANDBOX limit file and URL access, with path and URL allowlists. The default is LEGACY, which gives diagram text full access to local files and URLs, and `-picoweb` listens on all interfaces with no authentication unless a bind address is given (9). The tool renders the caller's own text, though `!include` can pull in remote text under the default profile (9). `--verbose` logging only (3). `docs/SECURITY.md` gives an email address for reports. No security.txt (HTTP 404), no bug bounty and no advisories published on the repository. CHANGES.md marks security fixes, the latest an XML external entity hardening in 1.2026.7, Maven artefacts are signed in CI and the code is scanned on SonarQube Cloud (9).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 2. Schema & documentation, 65 out of 100, up to 5.7 more on the total

Why it scored 65: Read as a CLI and library. No OpenAPI or formal grammar. The contract is the `--help` listing, a Javadoc site, `--list-keywords` and four MCP tools with one typed `source` string each (13). No llms.txt (HTTP 404). Docs pages are HTML, with a PDF guide (2). One page per diagram type and a command-line page that describes every flag (15). Flags are typed in the help text, with formats listed by name (10). Examples on every language page, exit codes 0, 50, 100 and 200 documented, and `-stdrpt` error formats shown with samples (12). CHANGES.md and GitHub release notes for every version. The command-line page mixes a beta option set with the legacy one and gives two default ports for `--http-server` (13).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 3. Payments & pricing, 60 out of 100, up to 5 more on the total

Why it scored 60: Read with the self-hosted rule. Free software with nothing to buy and no payment protocol (0). No price to publish (20). No card or trial needed (20). An agent can download the jar or run the npm package with no signup (20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 4. Agent ergonomics, 78 out of 100, up to 3.6 more on the total

Why it scored 78: One command with text in and a diagram out, or four compact MCP tools (23). `--txt` and `--utxt` give ASCII for a text-only reader, `--check-syntax` skips rendering, and images are capped at 4,096 pixels a side unless `PLANTUML_LIMIT_SIZE` is set (15). Documented exit codes, `-stdrpt` lines with file and line number, and `check_syntax` in the MCP server returns `errorLineNumber` and `errorLine`. The usual message is 'Syntax Error?' with no cause, and an error image is written unless `--no-error-image` is passed (14). Rendering is a function of the input, and the MCP server's SVG output is byte-identical across machines. The four MCP tools carry no `readOnlyHint` (14). `java -jar plantuml.jar file` works with no flags. It needs a Java runtime, and since 1.2026.7 falls back to the built-in Smetana layout when Graphviz is missing. Official surfaces are the Java library and two npm packages (12).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 5. Reliability, 83 out of 100, up to 3.4 more on the total

Why it scored 83: Read with the local-software lines, because PlantUML runs on the owner's machine. Release jars on GitHub and Maven Central, Homebrew at 1.2026.8 and a Docker image, with Java 11 stated as the minimum and a separate Java 8 build (20). The `ci` workflow passed on the last eight pushes to the default branch, the latest on 6 October 2026, and the repository holds 362 Java test classes (25). GitHub's search counts 575 open issues, 17 of them labelled bug. Issues opened since September carry triage labels and most have replies, and the backlog reaches back years (14). CHANGES.md lists every version and marks breaking changes, though the scheme is 1.year.count and not semver as the download page says, and 1.2026.7 changed the default sequence diagram engine in a point release (9). Version 1.2026.8, in a 1.x line since 2017 (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 6. Maintenance & community, 73 out of 100, up to 2.4 more on the total

Why it scored 73: Release 1.2026.8 on 5 September 2026, 33 days before the check (20). Two stable versions in the last 90 days, 1.2026.7 on 25 August and 1.2026.8, plus `@plantuml/mcp-js` 0.2.1 and 0.2.2 and a rolling snapshot build dated 6 October. Two stable versions is one short of the line (12). 200 commits since 21 July 2026 from more than ten authors, the lead maintainer writing 92, and new issues get labels and replies within days (20). Maven Central, Homebrew and Docker Hub all carry 1.2026.8 and npm has `@plantuml/mcp-js` 0.2.2. The server is not in the official MCP registry (12). Dependabot runs daily for Gradle and GitHub Actions, and CI runs on every push (9).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 7. Transparency & trust, 73 out of 100, up to 2.4 more on the total

Made of editorial 73, provenance 73.

Why it scored 73: GPL-3.0-or-later by default, with the same source under six other open-source licences, and `LICENSES.md` says generated images belong to the author of the diagram text (30). No privacy policy, and the software runs locally. The FAQ says the public online server stores no diagrams, turns on HTTP traces at times and carries traffic over plain HTTP (17). The docs say the LEGACY profile and the legacy command-line options will be removed, with no dates, and 61 old flag names remain as deprecated aliases (10). Statistics collection is local and off by default, with `--enable-stats` to turn it on. We found no network call in the statistics code (16).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Status page: not found (0 of 10)
- security.txt: not found (0 of 10)

## Deductions

Each comes off the total. A fixed and documented problem counts for less at the next check.

- 27 February 2026. Release 1.2026.2 switched off chronology diagrams, and its change log calls the removal temporary. On 8 October 2026 the factory is still commented out in `PSystemBuilder.java`, while the README lists the chronology diagram as supported and https://plantuml.com/chronology-diagram documents it. Two points, because the removal is in the change log (https://github.com/plantuml/plantuml/blob/master/CHANGES.md).

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- Whether chronology diagrams will return. The change log calls the February 2026 removal temporary and gives no date
- How many of the 575 open issues are crashes or regressions. Only the 30 newest items and the count of 17 labelled bug were read
- Whether any security advisory exists outside GitHub. The repository's advisory list is empty and no CVE database was searched
- The repository's `package.json` for `@plantuml/mcp-js` says 0.2.0 while npm serves 0.2.2
- unchecked: the public online server at www.plantuml.com/plantuml. robots.txt disallows its render paths and it was not called. The listing grades the software the owner runs
- unchecked: the Java `plantuml-mcp` server and `plantuml-server`, which are separate repositories and were not read
- No legal entity was found. `LICENSES.md` gives the copyright to Arnaud Roques, and no terms or privacy document governs the software

## Weaknesses

- The default security profile is LEGACY, which gives diagram text full access to local files and URLs through `!include`. The docs say it will be removed, with no date
- `-picoweb` listens on all network interfaces by default and has no authentication
- Chronology diagrams were switched off in 1.2026.2 on 27 February 2026 and are still listed in the README and documented on plantuml.com
- The command-line page gives the HTTP server's default port as 4242 in one help listing and 8080 in another. The source uses 8080
- No llms.txt, no security.txt and no published advisories. The security policy is one email address, and 575 issues are open

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Set `PLANTUML_SECURITY_PROFILE` to `SANDBOX` or `ALLOWLIST` before rendering text from an untrusted source. The default profile lets `!include` read local files and fetch URLs
- Run `java -jar plantuml.jar --check-syntax` with `-stdrpt` first and read the exit status. Without `--no-error-image` a syntax error still writes an image of the error text
- Pass `-pipe` with `--svg`, `--txt` or `--utxt` to work without files. `--txt` output suits a text-only model
- Start the local server as `-picoweb:8080:127.0.0.1`. Without the bind address it listens on every interface
- Use `npx -y @plantuml/mcp-js` when no Java runtime is present. It renders SVG only, so use the jar for PNG or PDF

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • Whether chronology diagrams will return. The change log calls the February 2026 removal temporary and gives no date
  • How many of the 575 open issues are crashes or regressions. Only the 30 newest items and the count of 17 labelled bug were read
  • Whether any security advisory exists outside GitHub. The repository's advisory list is empty and no CVE database was searched
  • The repository's package.json for @plantuml/mcp-js says 0.2.0 while npm serves 0.2.2
  • unchecked: the public online server at www.plantuml.com/plantuml. robots.txt disallows its render paths and it was not called. The listing grades the software the owner runs
  • unchecked: the Java plantuml-mcp server and plantuml-server, which are separate repositories and were not read
  • No legal entity was found. LICENSES.md gives the copyright to Arnaud Roques, and no terms or privacy document governs the software

Sources 17

  1. repository, README, licences file, CHANGES.md, security policy, CI workflows and source (shallow clone) github.com · seen 2026-10-08
  2. command-line options, exit codes, `-stdrpt` and `-pipe` plantuml.com · seen 2026-10-08
  3. security profiles and allowlists plantuml.com · seen 2026-10-08
  4. built-in HTTP server plantuml.com · seen 2026-10-08
  5. install requirements and Docker plantuml.com · seen 2026-10-08
  6. licence options and latest version plantuml.com · seen 2026-10-08
  7. FAQ on licences, the online server and image size limit plantuml.com · seen 2026-10-08
  8. chronology diagram page, still published plantuml.com · seen 2026-10-08
  9. MCP server README and tool definitions github.com · seen 2026-10-08
  10. repository statistics, releases, CI runs, advisories and recent issues api.github.com · seen 2026-10-08
  11. npm versions and weekly downloads of the MCP server registry.npmjs.org · seen 2026-10-08
  12. Maven Central versions repo1.maven.org · seen 2026-10-08
  13. Homebrew formula version formulae.brew.sh · seen 2026-10-08
  14. Docker Hub image hub.docker.com · seen 2026-10-08
  15. official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
  16. domain registration rdap.verisign.com · seen 2026-10-08
  17. robots.txt, llms.txt and security.txt checks plantuml.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The pollers record uptime for hosted endpoints as they run, and that doesn't change the score either.

Pricing & changes

Free Free · OSS Free under GPL-3.0-or-later, with the same source also under GPL-2.0, LGPL, Apache-2.0, BSD-3-Clause, EPL and MIT. Nothing to buy. The project takes donations through GitHub Sponsors and Patreon.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/plantuml.xml, or this listing's score history at history.json.

Connect

Install

brew install plantuml   # or download plantuml.jar from https://github.com/plantuml/plantuml/releases, or docker run ghcr.io/plantuml/plantuml

MCP client configuration

{
  "mcpServers": {
    "plantuml-js": {
      "args": [
        "-y",
        "@plantuml/mcp-js"
      ],
      "command": "npx"
    }
  }
}

Through letme picks today, calling later

GET https://letme.dev/plantuml

letme picks this listing for diagram.architecture, because it's the top-graded tool for the job. letme picks this listing for diagram.as-code, because it's the top-graded tool for the job. letme picks this listing for diagram.create, because it's the top-graded tool for the job. letme picks this listing for diagram.export, because it's the top-graded tool for the job.

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
D2 D2 project (The Hack Foundation)B65.3diagram.as-code diagram.create diagram.export diagram.architectureno
draw.io + MCP draw.ioB62.2diagram.create diagram.as-code diagram.export diagram.architectureno
Structurizr + MCP StructurizrC59.9diagram.create diagram.as-code diagram.export diagram.architectureno
Eraser API + MCP EraserE38.6diagram.create diagram.as-code diagram.export diagram.architectureno
tldraw SDK + MCP tldrawC60.7diagram.create diagram.as-code diagram.exportno
Lucid API + MCP Lucid SoftwareC60.6diagram.create diagram.as-code diagram.exportno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    PlantUML on Anchor Terminal, B, 66.9/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/plantuml"><img src="https://www.anchorterminal.com/badges/plantuml.svg" alt="PlantUML on Anchor Terminal" height="20"></a>
    [![PlantUML on Anchor Terminal](https://www.anchorterminal.com/badges/plantuml.svg)](https://www.anchorterminal.com/tools/plantuml)

    It counts on a page on plantuml.com or one of its subdomains, or the README of github.com/plantuml/plantuml.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "plantuml", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.