{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/d2.json",
        "name": "D2",
        "score": 65.3,
        "shared": [
          "diagram.as-code",
          "diagram.create",
          "diagram.export",
          "diagram.architecture"
        ],
        "slug": "d2"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/drawio.json",
        "name": "draw.io + MCP",
        "score": 62.2,
        "shared": [
          "diagram.create",
          "diagram.as-code",
          "diagram.export",
          "diagram.architecture"
        ],
        "slug": "drawio"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/structurizr.json",
        "name": "Structurizr + MCP",
        "score": 59.9,
        "shared": [
          "diagram.create",
          "diagram.as-code",
          "diagram.export",
          "diagram.architecture"
        ],
        "slug": "structurizr"
      },
      {
        "grade": "E",
        "json": "https://www.anchorterminal.com/tools/eraser.json",
        "name": "Eraser API + MCP",
        "score": 38.6,
        "shared": [
          "diagram.create",
          "diagram.as-code",
          "diagram.export",
          "diagram.architecture"
        ],
        "slug": "eraser"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/tldraw.json",
        "name": "tldraw SDK + MCP",
        "score": 60.7,
        "shared": [
          "diagram.create",
          "diagram.as-code",
          "diagram.export"
        ],
        "slug": "tldraw"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/lucid.json",
        "name": "Lucid API + MCP",
        "score": 60.6,
        "shared": [
          "diagram.create",
          "diagram.as-code",
          "diagram.export"
        ],
        "slug": "lucid"
      }
    ],
    "tool": {
      "slug": "plantuml",
      "name": "PlantUML",
      "vendor": "PlantUML project (Arnaud Roques)",
      "vendorUrl": "https://plantuml.com",
      "kind": "sdk",
      "category": "diagramming",
      "summary": "PlantUML is open-source software that turns text descriptions into UML, architecture, Gantt, mind map and other diagrams. Agents run it as a Java command-line tool, a Java library, a local HTTP server or the `@plantuml/mcp-js` MCP server.",
      "url": "https://www.anchorterminal.com/tools/plantuml",
      "markdownUrl": "https://www.anchorterminal.com/tools/plantuml.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/plantuml.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/plantuml.json",
      "repo": "https://github.com/plantuml/plantuml",
      "license": "GPL-3.0-or-later",
      "transports": [],
      "packages": [
        {
          "registry": "maven",
          "name": "net.sourceforge.plantuml:plantuml"
        },
        {
          "registry": "npm",
          "name": "@plantuml/mcp-js"
        },
        {
          "registry": "oci",
          "name": "plantuml/plantuml"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or login. The jar, the Java library and the MCP server run on the owner's machine with the owner's file and network rights. The built-in `-picoweb` HTTP server has no authentication and listens on all interfaces unless a bind address is given.",
      "pricing": "free",
      "pricingNotes": "Free under GPL-3.0-or-later, with the same source also under GPL-2.0, LGPL, Apache-2.0, BSD-3-Clause, EPL and MIT. Nothing to buy. The project takes donations through GitHub Sponsors and Patreon.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 13356,
        "npmWeekly": 207,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://plantuml.com/command-line",
      "capabilities": [
        "diagram.as-code",
        "diagram.create",
        "diagram.export",
        "diagram.architecture"
      ],
      "tags": [
        "open-source",
        "local",
        "cli",
        "java",
        "mcp",
        "diagram-as-code",
        "uml",
        "no-auth",
        "free",
        "docker"
      ],
      "lastRelease": "2026-09-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 66.9,
        "grade": "B",
        "agentReady": false,
        "rank": 251,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 73,
          "payments": 60,
          "reliability": 83,
          "schema": 65,
          "security": 50,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 83,
            "points": 16.6,
            "reason": "Read with the local-software lines, because PlantUML runs on the owner's machine. Release jars on GitHub and Maven Central, Homebrew at 1.2026.8 and a Docker image, with Java 11 stated as the minimum and a separate Java 8 build (20). The `ci` workflow passed on the last eight pushes to the default branch, the latest on 6 October 2026, and the repository holds 362 Java test classes (25). GitHub's search counts 575 open issues, 17 of them labelled bug. Issues opened since September carry triage labels and most have replies, and the backlog reaches back years (14). CHANGES.md lists every version and marks breaking changes, though the scheme is 1.year.count and not semver as the download page says, and 1.2026.7 changed the default sequence diagram engine in a point release (9). Version 1.2026.8, in a 1.x line since 2017 (15)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 65,
            "points": 10.56,
            "reason": "Read as a CLI and library. No OpenAPI or formal grammar. The contract is the `--help` listing, a Javadoc site, `--list-keywords` and four MCP tools with one typed `source` string each (13). No llms.txt (HTTP 404). Docs pages are HTML, with a PDF guide (2). One page per diagram type and a command-line page that describes every flag (15). Flags are typed in the help text, with formats listed by name (10). Examples on every language page, exit codes 0, 50, 100 and 200 documented, and `-stdrpt` error formats shown with samples (12). CHANGES.md and GitHub release notes for every version. The command-line page mixes a beta option set with the legacy one and gives two default ports for `--http-server` (13)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 78,
            "points": 12.68,
            "reason": "One command with text in and a diagram out, or four compact MCP tools (23). `--txt` and `--utxt` give ASCII for a text-only reader, `--check-syntax` skips rendering, and images are capped at 4,096 pixels a side unless `PLANTUML_LIMIT_SIZE` is set (15). Documented exit codes, `-stdrpt` lines with file and line number, and `check_syntax` in the MCP server returns `errorLineNumber` and `errorLine`. The usual message is 'Syntax Error?' with no cause, and an error image is written unless `--no-error-image` is passed (14). Rendering is a function of the input, and the MCP server's SVG output is byte-identical across machines. The four MCP tools carry no `readOnlyHint` (14). `java -jar plantuml.jar file` works with no flags. It needs a Java runtime, and since 1.2026.7 falls back to the built-in Smetana layout when Graphviz is missing. Official surfaces are the Java library and two npm packages (12)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 50,
            "points": 8.75,
            "reason": "No credential exists to leak or scope (20). Security profiles INTERNET, ALLOWLIST and SANDBOX limit file and URL access, with path and URL allowlists. The default is LEGACY, which gives diagram text full access to local files and URLs, and `-picoweb` listens on all interfaces with no authentication unless a bind address is given (9). The tool renders the caller's own text, though `!include` can pull in remote text under the default profile (9). `--verbose` logging only (3). `docs/SECURITY.md` gives an email address for reports. No security.txt (HTTP 404), no bug bounty and no advisories published on the repository. CHANGES.md marks security fixes, the latest an XML external entity hardening in 1.2026.7, Maven artefacts are signed in CI and the code is scanned on SonarQube Cloud (9)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 60,
            "points": 7.5,
            "reason": "Read with the self-hosted rule. Free software with nothing to buy and no payment protocol (0). No price to publish (20). No card or trial needed (20). An agent can download the jar or run the npm package with no signup (20)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 73,
            "points": 6.39,
            "reason": "Release 1.2026.8 on 5 September 2026, 33 days before the check (20). Two stable versions in the last 90 days, 1.2026.7 on 25 August and 1.2026.8, plus `@plantuml/mcp-js` 0.2.1 and 0.2.2 and a rolling snapshot build dated 6 October. Two stable versions is one short of the line (12). 200 commits since 21 July 2026 from more than ten authors, the lead maintainer writing 92, and new issues get labels and replies within days (20). Maven Central, Homebrew and Docker Hub all carry 1.2026.8 and npm has `@plantuml/mcp-js` 0.2.2. The server is not in the official MCP registry (12). Dependabot runs daily for Gradle and GitHub Actions, and CI runs on every push (9)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 73,
            "points": 6.39,
            "note": "editorial 73, provenance 73",
            "reason": "GPL-3.0-or-later by default, with the same source under six other open-source licences, and `LICENSES.md` says generated images belong to the author of the diagram text (30). No privacy policy, and the software runs locally. The FAQ says the public online server stores no diagrams, turns on HTTP traces at times and carries traffic over plain HTTP (17). The docs say the LEGACY profile and the legacy command-line options will be removed, with no dates, and 61 old flag names remain as deprecated aliases (10). Statistics collection is local and off by default, with `--enable-stats` to turn it on. We found no network call in the statistics code (16)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "One command with text in and a diagram out, or four compact MCP tools (23). `--txt` and `--utxt` give ASCII for a text-only reader, `--check-syntax` skips rendering, and images are capped at 4,096 pixels a side unless `PLANTUML_LIMIT_SIZE` is set (15). Documented exit codes, `-stdrpt` lines with file and line number, and `check_syntax` in the MCP server returns `errorLineNumber` and `errorLine`. The usual message is 'Syntax Error?' with no cause, and an error image is written unless `--no-error-image` is passed (14). Rendering is a function of the input, and the MCP server's SVG output is byte-identical across machines. The four MCP tools carry no `readOnlyHint` (14). `java -jar plantuml.jar file` works with no flags. It needs a Java runtime, and since 1.2026.7 falls back to the built-in Smetana layout when Graphviz is missing. Official surfaces are the Java library and two npm packages (12).",
            "maintenance": "Release 1.2026.8 on 5 September 2026, 33 days before the check (20). Two stable versions in the last 90 days, 1.2026.7 on 25 August and 1.2026.8, plus `@plantuml/mcp-js` 0.2.1 and 0.2.2 and a rolling snapshot build dated 6 October. Two stable versions is one short of the line (12). 200 commits since 21 July 2026 from more than ten authors, the lead maintainer writing 92, and new issues get labels and replies within days (20). Maven Central, Homebrew and Docker Hub all carry 1.2026.8 and npm has `@plantuml/mcp-js` 0.2.2. The server is not in the official MCP registry (12). Dependabot runs daily for Gradle and GitHub Actions, and CI runs on every push (9).",
            "payments": "Read with the self-hosted rule. Free software with nothing to buy and no payment protocol (0). No price to publish (20). No card or trial needed (20). An agent can download the jar or run the npm package with no signup (20).",
            "reliability": "Read with the local-software lines, because PlantUML runs on the owner's machine. Release jars on GitHub and Maven Central, Homebrew at 1.2026.8 and a Docker image, with Java 11 stated as the minimum and a separate Java 8 build (20). The `ci` workflow passed on the last eight pushes to the default branch, the latest on 6 October 2026, and the repository holds 362 Java test classes (25). GitHub's search counts 575 open issues, 17 of them labelled bug. Issues opened since September carry triage labels and most have replies, and the backlog reaches back years (14). CHANGES.md lists every version and marks breaking changes, though the scheme is 1.year.count and not semver as the download page says, and 1.2026.7 changed the default sequence diagram engine in a point release (9). Version 1.2026.8, in a 1.x line since 2017 (15).",
            "schema": "Read as a CLI and library. No OpenAPI or formal grammar. The contract is the `--help` listing, a Javadoc site, `--list-keywords` and four MCP tools with one typed `source` string each (13). No llms.txt (HTTP 404). Docs pages are HTML, with a PDF guide (2). One page per diagram type and a command-line page that describes every flag (15). Flags are typed in the help text, with formats listed by name (10). Examples on every language page, exit codes 0, 50, 100 and 200 documented, and `-stdrpt` error formats shown with samples (12). CHANGES.md and GitHub release notes for every version. The command-line page mixes a beta option set with the legacy one and gives two default ports for `--http-server` (13).",
            "security": "No credential exists to leak or scope (20). Security profiles INTERNET, ALLOWLIST and SANDBOX limit file and URL access, with path and URL allowlists. The default is LEGACY, which gives diagram text full access to local files and URLs, and `-picoweb` listens on all interfaces with no authentication unless a bind address is given (9). The tool renders the caller's own text, though `!include` can pull in remote text under the default profile (9). `--verbose` logging only (3). `docs/SECURITY.md` gives an email address for reports. No security.txt (HTTP 404), no bug bounty and no advisories published on the repository. CHANGES.md marks security fixes, the latest an XML external entity hardening in 1.2026.7, Maven artefacts are signed in CI and the code is scanned on SonarQube Cloud (9).",
            "transparency": "GPL-3.0-or-later by default, with the same source under six other open-source licences, and `LICENSES.md` says generated images belong to the author of the diagram text (30). No privacy policy, and the software runs locally. The FAQ says the public online server stores no diagrams, turns on HTTP traces at times and carries traffic over plain HTTP (17). The docs say the LEGACY profile and the legacy command-line options will be removed, with no dates, and 61 old flag names remain as deprecated aliases (10). Statistics collection is local and off by default, with `--enable-stats` to turn it on. We found no network call in the statistics code (16)."
          },
          "sources": [
            {
              "what": "repository, README, licences file, CHANGES.md, security policy, CI workflows and source (shallow clone)",
              "url": "https://github.com/plantuml/plantuml",
              "seen": "2026-10-08"
            },
            {
              "what": "command-line options, exit codes, `-stdrpt` and `-pipe`",
              "url": "https://plantuml.com/command-line",
              "seen": "2026-10-08"
            },
            {
              "what": "security profiles and allowlists",
              "url": "https://plantuml.com/security",
              "seen": "2026-10-08"
            },
            {
              "what": "built-in HTTP server",
              "url": "https://plantuml.com/picoweb",
              "seen": "2026-10-08"
            },
            {
              "what": "install requirements and Docker",
              "url": "https://plantuml.com/starting",
              "seen": "2026-10-08"
            },
            {
              "what": "licence options and latest version",
              "url": "https://plantuml.com/download",
              "seen": "2026-10-08"
            },
            {
              "what": "FAQ on licences, the online server and image size limit",
              "url": "https://plantuml.com/faq",
              "seen": "2026-10-08"
            },
            {
              "what": "chronology diagram page, still published",
              "url": "https://plantuml.com/chronology-diagram",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server README and tool definitions",
              "url": "https://github.com/plantuml/plantuml/tree/master/plantuml-mcp-js",
              "seen": "2026-10-08"
            },
            {
              "what": "repository statistics, releases, CI runs, advisories and recent issues",
              "url": "https://api.github.com/repos/plantuml/plantuml",
              "seen": "2026-10-08"
            },
            {
              "what": "npm versions and weekly downloads of the MCP server",
              "url": "https://registry.npmjs.org/@plantuml/mcp-js",
              "seen": "2026-10-08"
            },
            {
              "what": "Maven Central versions",
              "url": "https://repo1.maven.org/maven2/net/sourceforge/plantuml/plantuml/maven-metadata.xml",
              "seen": "2026-10-08"
            },
            {
              "what": "Homebrew formula version",
              "url": "https://formulae.brew.sh/api/formula/plantuml.json",
              "seen": "2026-10-08"
            },
            {
              "what": "Docker Hub image",
              "url": "https://hub.docker.com/r/plantuml/plantuml",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=plantuml",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.verisign.com/com/v1/domain/plantuml.com",
              "seen": "2026-10-08"
            },
            {
              "what": "robots.txt, llms.txt and security.txt checks",
              "url": "https://plantuml.com/robots.txt",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "Whether chronology diagrams will return. The change log calls the February 2026 removal temporary and gives no date",
            "How many of the 575 open issues are crashes or regressions. Only the 30 newest items and the count of 17 labelled bug were read",
            "Whether any security advisory exists outside GitHub. The repository's advisory list is empty and no CVE database was searched",
            "The repository's `package.json` for `@plantuml/mcp-js` says 0.2.0 while npm serves 0.2.2",
            "unchecked: the public online server at www.plantuml.com/plantuml. robots.txt disallows its render paths and it was not called. The listing grades the software the owner runs",
            "unchecked: the Java `plantuml-mcp` server and `plantuml-server`, which are separate repositories and were not read",
            "No legal entity was found. `LICENSES.md` gives the copyright to Arnaud Roques, and no terms or privacy document governs the software"
          ]
        },
        "negative": -2,
        "negativeNotes": [
          "27 February 2026. Release 1.2026.2 switched off chronology diagrams, and its change log calls the removal temporary. On 8 October 2026 the factory is still commented out in `PSystemBuilder.java`, while the README lists the chronology diagram as supported and https://plantuml.com/chronology-diagram documents it. Two points, because the removal is in the change log (https://github.com/plantuml/plantuml/blob/master/CHANGES.md)."
        ],
        "verdict": "One Java command reads diagram text from stdin and writes PNG, SVG, PDF or ASCII with no account, and CI passed on the last eight pushes. The default security profile lets diagram text read any local file and fetch any URL, and the documentation still lists chronology diagrams that release 1.2026.2 switched off.",
        "bestFor": "Agents that write sequence, class, state, component, deployment, Gantt or C4 diagrams as text and render them locally or in CI.",
        "strengths": [
          "`java -jar plantuml.jar -pipe` reads a diagram from stdin and writes PNG, SVG, PDF, EPS, LaTeX or ASCII to stdout, with no account or key",
          "`--check-syntax` and `-stdrpt` report errors as `file:line:error` lines, and exit codes 0, 50, 100 and 200 are documented",
          "The official `@plantuml/mcp-js` server has four tools, needs only Node.js, and returns the same SVG bytes for the same source on any machine",
          "Version 1.2026.8 of 5 September 2026 is on GitHub, Maven Central, Homebrew and Docker Hub, and the `ci` workflow passed on the last eight pushes",
          "The same source is available under GPL-3.0-or-later, GPL-2.0, LGPL, Apache-2.0, BSD-3-Clause, EPL and MIT, and generated images carry no licence obligation"
        ],
        "weaknesses": [
          "The default security profile is LEGACY, which gives diagram text full access to local files and URLs through `!include`. The docs say it will be removed, with no date",
          "`-picoweb` listens on all network interfaces by default and has no authentication",
          "Chronology diagrams were switched off in 1.2026.2 on 27 February 2026 and are still listed in the README and documented on plantuml.com",
          "The command-line page gives the HTTP server's default port as 4242 in one help listing and 8080 in another. The source uses 8080",
          "No llms.txt, no security.txt and no published advisories. The security policy is one email address, and 575 issues are open"
        ],
        "agentNotes": [
          "Set `PLANTUML_SECURITY_PROFILE` to `SANDBOX` or `ALLOWLIST` before rendering text from an untrusted source. The default profile lets `!include` read local files and fetch URLs",
          "Run `java -jar plantuml.jar --check-syntax` with `-stdrpt` first and read the exit status. Without `--no-error-image` a syntax error still writes an image of the error text",
          "Pass `-pipe` with `--svg`, `--txt` or `--utxt` to work without files. `--txt` output suits a text-only model",
          "Start the local server as `-picoweb:8080:127.0.0.1`. Without the bind address it listens on every interface",
          "Use `npx -y @plantuml/mcp-js` when no Java runtime is present. It renders SVG only, so use the jar for PNG or PDF"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 66.9
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 73,
          "payments": 60,
          "reliability": 83,
          "schema": 65,
          "security": 50,
          "transparency": 73
        },
        "provenanceScore": 73
      },
      "connect": {
        "install": "brew install plantuml   # or download plantuml.jar from https://github.com/plantuml/plantuml/releases, or docker run ghcr.io/plantuml/plantuml",
        "config": {
          "mcpServers": {
            "plantuml-js": {
              "args": [
                "-y",
                "@plantuml/mcp-js"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/diagram.as-code",
        "tool": "https://letme.dev/plantuml"
      },
      "notable": [
        "The official `@plantuml/mcp-js` MCP server, first published on 8 June 2026, compiles the Java engine to JavaScript and has four tools, `plantuml_version`, `check_syntax`, `render_diagram` and `explain_diagram` (https://github.com/plantuml/plantuml/tree/master/plantuml-mcp-js)",
        "The default security profile is LEGACY, with full access to local files and URLs. The security page says it will be removed in a future release and the default will become more restricted (https://plantuml.com/security)",
        "Release 1.2026.2 on 27 February 2026 switched off chronology diagrams, and the README and https://plantuml.com/chronology-diagram still list them (https://github.com/plantuml/plantuml/blob/master/CHANGES.md)",
        "Release 1.2026.7 on 25 August 2026 changed the default sequence diagram engine from Puma to Teoz and falls back to the built-in Smetana layout when Graphviz is missing (https://github.com/plantuml/plantuml/blob/master/CHANGES.md)",
        "The command-line options are being redesigned to GNU style. Legacy options stay for a transition period and are no longer documented (https://plantuml.com/command-line)",
        "The FAQ says the public online server stores no diagrams and that its traffic goes over plain HTTP, and it recommends a local server for sensitive content (https://plantuml.com/faq)"
      ],
      "area": "design-diagrams",
      "details": [
        {
          "label": "Surfaces",
          "value": "CLI `java -jar plantuml.jar`, the Java library `net.sourceforge.plantuml:plantuml`, the built-in `-picoweb` HTTP server, and the `@plantuml/mcp-js` 0.2.2 stdio MCP server for Node.js"
        },
        {
          "label": "Export formats",
          "value": "PNG (default), SVG, PDF, EPS, LaTeX/TikZ, ASCII (`--txt`, `--utxt`), VDX, XMI, SCXML and HTML. The MCP server renders SVG only"
        },
        {
          "label": "Diagram types",
          "value": "Sequence, use case, class, object, activity, component, deployment, state and timing, plus Gantt, mind map, WBS, network, wireframe, Archimate, ER, JSON, YAML, EBNF and regex"
        },
        {
          "label": "Commands",
          "value": "`-pipe` for stdin to stdout, `--check-syntax`, `--stop-on-error`, `--no-error-image`, `-stdrpt`, `--format`, `--output-dir`, `--extract-source` and `--list-keywords`"
        },
        {
          "label": "Exit codes",
          "value": "0 success, 50 no file found, 100 no diagram found, 200 some diagrams have syntax errors"
        },
        {
          "label": "Local HTTP server",
          "value": "`-picoweb[:port[:bind address]]`, default port 8080 on all interfaces. GET `/plantuml/png/`, `/plantuml/svg/`, `/plantuml/txt/` with the encoded diagram, and POST `/render`"
        },
        {
          "label": "Security profiles",
          "value": "UNSECURE, LEGACY (default), INTERNET, ALLOWLIST and SANDBOX, set with `PLANTUML_SECURITY_PROFILE`, plus `plantuml.allowlist.path` and `plantuml.allowlist.url`"
        },
        {
          "label": "Requirements",
          "value": "Java 11 or later, with a separate Java 8 build. Graphviz for some layouts, with the built-in Smetana engine as fallback since 1.2026.7. The MCP server needs only Node.js"
        },
        {
          "label": "Limits",
          "value": "Images are capped at 4,096 pixels a side unless `PLANTUML_LIMIT_SIZE` is set. `--graphviz-timeout` sets the layout timeout"
        },
        {
          "label": "Telemetry",
          "value": "Statistics collection is local and off by default (`--enable-stats`). No network call was found in the statistics code"
        }
      ],
      "provenance": {
        "legalEntity": "No legal entity found. Copyright Arnaud Roques",
        "domain": "plantuml.com",
        "domainRegistered": "2010-11-28",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/plantuml/plantuml/blob/master/CHANGES.md",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "`LICENSES.md` reads Copyright (C) 2009-2026, Arnaud Roques. No company or foundation is named in the repository or on the pages read",
          "No terms or privacy document governs the software. The GPL-3.0-or-later licence, or one of the six alternatives, stands in",
          "https://plantuml.com/.well-known/security.txt answered 404 on 8 October 2026. `docs/SECURITY.md` asks for reports by email to a Gmail address",
          "The lead named PlantUML as vendor. It is a community project led by one author, with no company behind it that we found"
        ],
        "score": 73,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "No legal entity found. Copyright Arnaud Roques",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "plantuml.com, registered 2010-11-28 (15 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "no hosted endpoint",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Terms of service",
            "value": "nothing hosted, so the GPL-3.0-or-later licence stands in",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Privacy policy",
            "value": "nothing hosted, not scored",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/plantuml.json"
    },
    "verify": {
      "accepts": "a page on plantuml.com or one of its subdomains, or the README of github.com/plantuml/plantuml",
      "badgeUrl": "https://www.anchorterminal.com/badges/plantuml.svg",
      "body": {
        "slug": "plantuml",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/plantuml",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/plantuml\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/plantuml.svg\" alt=\"PlantUML on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![PlantUML on Anchor Terminal](https://www.anchorterminal.com/badges/plantuml.svg)](https://www.anchorterminal.com/tools/plantuml)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/plantuml\"\u003ePlantUML on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/plantuml",
    "json": "https://www.anchorterminal.com/tools/plantuml.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/plantuml.md",
    "slim": "https://www.anchorterminal.com/tools/plantuml.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 66.9/100 · rank #251 of 842 · #1 in Diagramming · not agent-ready · confidence medium**\n\n\n## Assessment\n\nOne Java command reads diagram text from stdin and writes PNG, SVG, PDF or ASCII with no account, and CI passed on the last eight pushes. The default security profile lets diagram text read any local file and fetch any URL, and the documentation still lists chronology diagrams that release 1.2026.2 switched off.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | PlantUML project (Arnaud Roques) (https://plantuml.com) |\n| Kind | SDK + MCP |\n| Category | Diagramming (https://www.anchorterminal.com/categories/diagramming) |\n| Auth | None · No account, key or login. The jar, the Java library and the MCP server run on the owner's machine with the owner's file and network rights. The built-in `-picoweb` HTTP server has no authentication and listens on all interfaces unless a bind address is given. |\n| Pricing | Free (Free · OSS) · Free under GPL-3.0-or-later, with the same source also under GPL-2.0, LGPL, Apache-2.0, BSD-3-Clause, EPL and MIT. Nothing to buy. The project takes donations through GitHub Sponsors and Patreon. |\n| x402 | No · No x402, MPP or L402 in the docs or the source (checked 2026-10-08). |\n| Licence | GPL-3.0-or-later |\n| Packages | maven: `net.sourceforge.plantuml:plantuml`; npm: `@plantuml/mcp-js`; oci: `plantuml/plantuml` |\n| Source | https://github.com/plantuml/plantuml |\n| Docs | https://plantuml.com/command-line |\n| llms.txt | not found |\n| Last release | 2026-09-05 |\n| GitHub stars | 13,356 (as of 2026-10-08) |\n| npm downloads / week | 207 |\n| Surfaces | CLI `java -jar plantuml.jar`, the Java library `net.sourceforge.plantuml:plantuml`, the built-in `-picoweb` HTTP server, and the `@plantuml/mcp-js` 0.2.2 stdio MCP server for Node.js |\n| Export formats | PNG (default), SVG, PDF, EPS, LaTeX/TikZ, ASCII (`--txt`, `--utxt`), VDX, XMI, SCXML and HTML. The MCP server renders SVG only |\n| Diagram types | Sequence, use case, class, object, activity, component, deployment, state and timing, plus Gantt, mind map, WBS, network, wireframe, Archimate, ER, JSON, YAML, EBNF and regex |\n| Commands | `-pipe` for stdin to stdout, `--check-syntax`, `--stop-on-error`, `--no-error-image`, `-stdrpt`, `--format`, `--output-dir`, `--extract-source` and `--list-keywords` |\n| Exit codes | 0 success, 50 no file found, 100 no diagram found, 200 some diagrams have syntax errors |\n| Local HTTP server | `-picoweb[:port[:bind address]]`, default port 8080 on all interfaces. GET `/plantuml/png/`, `/plantuml/svg/`, `/plantuml/txt/` with the encoded diagram, and POST `/render` |\n| Security profiles | UNSECURE, LEGACY (default), INTERNET, ALLOWLIST and SANDBOX, set with `PLANTUML_SECURITY_PROFILE`, plus `plantuml.allowlist.path` and `plantuml.allowlist.url` |\n| Requirements | Java 11 or later, with a separate Java 8 build. Graphviz for some layouts, with the built-in Smetana engine as fallback since 1.2026.7. The MCP server needs only Node.js |\n| Limits | Images are capped at 4,096 pixels a side unless `PLANTUML_LIMIT_SIZE` is set. `--graphviz-timeout` sets the layout timeout |\n| Telemetry | Statistics collection is local and off by default (`--enable-stats`). No network call was found in the statistics code |\n| Capabilities | diagram.as-code, diagram.create, diagram.export, diagram.architecture |\n| Tags | open-source, local, cli, java, mcp, diagram-as-code, uml, no-auth, free, docker |\n| JSON | https://www.anchorterminal.com/api/v1/tools/plantuml.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 83 | 16.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 65 | 10.6 |\n| Agent ergonomics | 13% | 16.2 | 78 | 12.7 |\n| Security \u0026 auth | 14% | 17.5 | 50 | 8.8 |\n| Payments \u0026 pricing | 10% | 12.5 | 60 | 7.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 73 | 6.4 |\n| Transparency \u0026 trust (editorial 73, provenance 73) | 7% | 8.8 | 73 | 6.4 |\n| Negative events | up to −15 | up to −15 | 27 February 2026. Release 1.2026.2 switched off chronology diagrams, and its change log calls the removal temporary. On 8 October 2026 the factory is still commented out in `PSystemBuilder.java`, while the README lists the chronology diagram as supported and https://plantuml.com/chronology-diagram documents it. Two points, because the removal is in the change log (https://github.com/plantuml/plantuml/blob/master/CHANGES.md).  | -2 |\n| **Total** | | | | **66.9 → B** |\n\n### Why each score\n\n- Reliability 83: Read with the local-software lines, because PlantUML runs on the owner's machine. Release jars on GitHub and Maven Central, Homebrew at 1.2026.8 and a Docker image, with Java 11 stated as the minimum and a separate Java 8 build (20). The `ci` workflow passed on the last eight pushes to the default branch, the latest on 6 October 2026, and the repository holds 362 Java test classes (25). GitHub's search counts 575 open issues, 17 of them labelled bug. Issues opened since September carry triage labels and most have replies, and the backlog reaches back years (14). CHANGES.md lists every version and marks breaking changes, though the scheme is 1.year.count and not semver as the download page says, and 1.2026.7 changed the default sequence diagram engine in a point release (9). Version 1.2026.8, in a 1.x line since 2017 (15).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 65: Read as a CLI and library. No OpenAPI or formal grammar. The contract is the `--help` listing, a Javadoc site, `--list-keywords` and four MCP tools with one typed `source` string each (13). No llms.txt (HTTP 404). Docs pages are HTML, with a PDF guide (2). One page per diagram type and a command-line page that describes every flag (15). Flags are typed in the help text, with formats listed by name (10). Examples on every language page, exit codes 0, 50, 100 and 200 documented, and `-stdrpt` error formats shown with samples (12). CHANGES.md and GitHub release notes for every version. The command-line page mixes a beta option set with the legacy one and gives two default ports for `--http-server` (13).\n- Agent ergonomics 78: One command with text in and a diagram out, or four compact MCP tools (23). `--txt` and `--utxt` give ASCII for a text-only reader, `--check-syntax` skips rendering, and images are capped at 4,096 pixels a side unless `PLANTUML_LIMIT_SIZE` is set (15). Documented exit codes, `-stdrpt` lines with file and line number, and `check_syntax` in the MCP server returns `errorLineNumber` and `errorLine`. The usual message is 'Syntax Error?' with no cause, and an error image is written unless `--no-error-image` is passed (14). Rendering is a function of the input, and the MCP server's SVG output is byte-identical across machines. The four MCP tools carry no `readOnlyHint` (14). `java -jar plantuml.jar file` works with no flags. It needs a Java runtime, and since 1.2026.7 falls back to the built-in Smetana layout when Graphviz is missing. Official surfaces are the Java library and two npm packages (12).\n- Security \u0026 auth 50: No credential exists to leak or scope (20). Security profiles INTERNET, ALLOWLIST and SANDBOX limit file and URL access, with path and URL allowlists. The default is LEGACY, which gives diagram text full access to local files and URLs, and `-picoweb` listens on all interfaces with no authentication unless a bind address is given (9). The tool renders the caller's own text, though `!include` can pull in remote text under the default profile (9). `--verbose` logging only (3). `docs/SECURITY.md` gives an email address for reports. No security.txt (HTTP 404), no bug bounty and no advisories published on the repository. CHANGES.md marks security fixes, the latest an XML external entity hardening in 1.2026.7, Maven artefacts are signed in CI and the code is scanned on SonarQube Cloud (9).\n- Payments \u0026 pricing 60: Read with the self-hosted rule. Free software with nothing to buy and no payment protocol (0). No price to publish (20). No card or trial needed (20). An agent can download the jar or run the npm package with no signup (20).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 73: Release 1.2026.8 on 5 September 2026, 33 days before the check (20). Two stable versions in the last 90 days, 1.2026.7 on 25 August and 1.2026.8, plus `@plantuml/mcp-js` 0.2.1 and 0.2.2 and a rolling snapshot build dated 6 October. Two stable versions is one short of the line (12). 200 commits since 21 July 2026 from more than ten authors, the lead maintainer writing 92, and new issues get labels and replies within days (20). Maven Central, Homebrew and Docker Hub all carry 1.2026.8 and npm has `@plantuml/mcp-js` 0.2.2. The server is not in the official MCP registry (12). Dependabot runs daily for Gradle and GitHub Actions, and CI runs on every push (9).\n- Transparency \u0026 trust 73: GPL-3.0-or-later by default, with the same source under six other open-source licences, and `LICENSES.md` says generated images belong to the author of the diagram text (30). No privacy policy, and the software runs locally. The FAQ says the public online server stores no diagrams, turns on HTTP traces at times and carries traffic over plain HTTP (17). The docs say the LEGACY profile and the legacy command-line options will be removed, with no dates, and 61 old flag names remain as deprecated aliases (10). Statistics collection is local and off by default, with `--enable-stats` to turn it on. We found no network call in the statistics code (16).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/plantuml.md (JSON https://www.anchorterminal.com/fixes/plantuml.json)\n\n### What we couldn't check\n\n- Whether chronology diagrams will return. The change log calls the February 2026 removal temporary and gives no date\n- How many of the 575 open issues are crashes or regressions. Only the 30 newest items and the count of 17 labelled bug were read\n- Whether any security advisory exists outside GitHub. The repository's advisory list is empty and no CVE database was searched\n- The repository's `package.json` for `@plantuml/mcp-js` says 0.2.0 while npm serves 0.2.2\n- unchecked: the public online server at www.plantuml.com/plantuml. robots.txt disallows its render paths and it was not called. The listing grades the software the owner runs\n- unchecked: the Java `plantuml-mcp` server and `plantuml-server`, which are separate repositories and were not read\n- No legal entity was found. `LICENSES.md` gives the copyright to Arnaud Roques, and no terms or privacy document governs the software\n\n### Sources\n\n- repository, README, licences file, CHANGES.md, security policy, CI workflows and source (shallow clone): \u003chttps://github.com/plantuml/plantuml\u003e (seen 2026-10-08)\n- command-line options, exit codes, `-stdrpt` and `-pipe`: \u003chttps://plantuml.com/command-line\u003e (seen 2026-10-08)\n- security profiles and allowlists: \u003chttps://plantuml.com/security\u003e (seen 2026-10-08)\n- built-in HTTP server: \u003chttps://plantuml.com/picoweb\u003e (seen 2026-10-08)\n- install requirements and Docker: \u003chttps://plantuml.com/starting\u003e (seen 2026-10-08)\n- licence options and latest version: \u003chttps://plantuml.com/download\u003e (seen 2026-10-08)\n- FAQ on licences, the online server and image size limit: \u003chttps://plantuml.com/faq\u003e (seen 2026-10-08)\n- chronology diagram page, still published: \u003chttps://plantuml.com/chronology-diagram\u003e (seen 2026-10-08)\n- MCP server README and tool definitions: \u003chttps://github.com/plantuml/plantuml/tree/master/plantuml-mcp-js\u003e (seen 2026-10-08)\n- repository statistics, releases, CI runs, advisories and recent issues: \u003chttps://api.github.com/repos/plantuml/plantuml\u003e (seen 2026-10-08)\n- npm versions and weekly downloads of the MCP server: \u003chttps://registry.npmjs.org/@plantuml/mcp-js\u003e (seen 2026-10-08)\n- Maven Central versions: \u003chttps://repo1.maven.org/maven2/net/sourceforge/plantuml/plantuml/maven-metadata.xml\u003e (seen 2026-10-08)\n- Homebrew formula version: \u003chttps://formulae.brew.sh/api/formula/plantuml.json\u003e (seen 2026-10-08)\n- Docker Hub image: \u003chttps://hub.docker.com/r/plantuml/plantuml\u003e (seen 2026-10-08)\n- official MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=plantuml\u003e (seen 2026-10-08)\n- domain registration: \u003chttps://rdap.verisign.com/com/v1/domain/plantuml.com\u003e (seen 2026-10-08)\n- robots.txt, llms.txt and security.txt checks: \u003chttps://plantuml.com/robots.txt\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 73/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | No legal entity found. Copyright Arnaud Roques | 20/20 |\n| Domain age | plantuml.com, registered 2010-11-28 (15 years) | 15/15 |\n| Endpoint on the vendor's domain | no hosted endpoint | n/a |\n| Terms of service | nothing hosted, so the GPL-3.0-or-later licence stands in | 10/10 |\n| Privacy policy | nothing hosted, not scored | n/a |\n| Status page | not found | 0/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\n`LICENSES.md` reads Copyright (C) 2009-2026, Arnaud Roques. No company or foundation is named in the repository or on the pages read\n\nNo terms or privacy document governs the software. The GPL-3.0-or-later licence, or one of the six alternatives, stands in\n\nhttps://plantuml.com/.well-known/security.txt answered 404 on 8 October 2026. `docs/SECURITY.md` asks for reports by email to a Gmail address\n\nThe lead named PlantUML as vendor. It is a community project led by one author, with no company behind it that we found\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service**. Nothing is hosted by the vendor, so there are no terms of service to read. The GPL-3.0-or-later licence stands in and the check scores in full.\n\n\n**Privacy policy**. Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored.\n\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- `java -jar plantuml.jar -pipe` reads a diagram from stdin and writes PNG, SVG, PDF, EPS, LaTeX or ASCII to stdout, with no account or key\n- `--check-syntax` and `-stdrpt` report errors as `file:line:error` lines, and exit codes 0, 50, 100 and 200 are documented\n- The official `@plantuml/mcp-js` server has four tools, needs only Node.js, and returns the same SVG bytes for the same source on any machine\n- Version 1.2026.8 of 5 September 2026 is on GitHub, Maven Central, Homebrew and Docker Hub, and the `ci` workflow passed on the last eight pushes\n- The same source is available under GPL-3.0-or-later, GPL-2.0, LGPL, Apache-2.0, BSD-3-Clause, EPL and MIT, and generated images carry no licence obligation\n\n## Weaknesses\n\n- The default security profile is LEGACY, which gives diagram text full access to local files and URLs through `!include`. The docs say it will be removed, with no date\n- `-picoweb` listens on all network interfaces by default and has no authentication\n- Chronology diagrams were switched off in 1.2026.2 on 27 February 2026 and are still listed in the README and documented on plantuml.com\n- The command-line page gives the HTTP server's default port as 4242 in one help listing and 8080 in another. The source uses 8080\n- No llms.txt, no security.txt and no published advisories. The security policy is one email address, and 575 issues are open\n\n## Before you call it (notes for agents)\n\n1. Set `PLANTUML_SECURITY_PROFILE` to `SANDBOX` or `ALLOWLIST` before rendering text from an untrusted source. The default profile lets `!include` read local files and fetch URLs\n2. Run `java -jar plantuml.jar --check-syntax` with `-stdrpt` first and read the exit status. Without `--no-error-image` a syntax error still writes an image of the error text\n3. Pass `-pipe` with `--svg`, `--txt` or `--utxt` to work without files. `--txt` output suits a text-only model\n4. Start the local server as `-picoweb:8080:127.0.0.1`. Without the bind address it listens on every interface\n5. Use `npx -y @plantuml/mcp-js` when no Java runtime is present. It renders SVG only, so use the jar for PNG or PDF\n\n## Connect\n\nInstall:\n\n```bash\nbrew install plantuml   # or download plantuml.jar from https://github.com/plantuml/plantuml/releases, or docker run ghcr.io/plantuml/plantuml\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"plantuml-js\": {\n      \"args\": [\n        \"-y\",\n        \"@plantuml/mcp-js\"\n      ],\n      \"command\": \"npx\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/plantuml (letme picks it for diagram.architecture, the top-graded tool for the job, letme picks it for diagram.as-code, the top-graded tool for the job, letme picks it for diagram.create, the top-graded tool for the job, letme picks it for diagram.export, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| D2 | B | 65.3 | 295 | diagram.as-code, diagram.create, diagram.export, diagram.architecture | no | https://www.anchorterminal.com/tools/d2.md |\n| draw.io + MCP | B | 62.2 | 397 | diagram.create, diagram.as-code, diagram.export, diagram.architecture | no | https://www.anchorterminal.com/tools/drawio.md |\n| Structurizr + MCP | C | 59.9 | 483 | diagram.create, diagram.as-code, diagram.export, diagram.architecture | no | https://www.anchorterminal.com/tools/structurizr.md |\n| Eraser API + MCP | E | 38.6 | 811 | diagram.create, diagram.as-code, diagram.export, diagram.architecture | no | https://www.anchorterminal.com/tools/eraser.md |\n| tldraw SDK + MCP | C | 60.7 | 451 | diagram.create, diagram.as-code, diagram.export | no | https://www.anchorterminal.com/tools/tldraw.md |\n| Lucid API + MCP | C | 60.6 | 455 | diagram.create, diagram.as-code, diagram.export | no | https://www.anchorterminal.com/tools/lucid.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The official `@plantuml/mcp-js` MCP server, first published on 8 June 2026, compiles the Java engine to JavaScript and has four tools, `plantuml_version`, `check_syntax`, `render_diagram` and `explain_diagram` (source: \u003chttps://github.com/plantuml/plantuml/tree/master/plantuml-mcp-js\u003e)\n- The default security profile is LEGACY, with full access to local files and URLs. The security page says it will be removed in a future release and the default will become more restricted (source: \u003chttps://plantuml.com/security\u003e)\n- Release 1.2026.2 on 27 February 2026 switched off chronology diagrams, and the README and https://plantuml.com/chronology-diagram still list them (source: \u003chttps://github.com/plantuml/plantuml/blob/master/CHANGES.md\u003e)\n- Release 1.2026.7 on 25 August 2026 changed the default sequence diagram engine from Puma to Teoz and falls back to the built-in Smetana layout when Graphviz is missing (source: \u003chttps://github.com/plantuml/plantuml/blob/master/CHANGES.md\u003e)\n- The command-line options are being redesigned to GNU style. Legacy options stay for a transition period and are no longer documented (source: \u003chttps://plantuml.com/command-line\u003e)\n- The FAQ says the public online server stores no diagrams and that its traffic goes over plain HTTP, and it recommends a local server for sensitive content (source: \u003chttps://plantuml.com/faq\u003e)\n\n## Compare\n\n- [Cloudviz API vs PlantUML](https://www.anchorterminal.com/compare/cloudviz-vs-plantuml.md): F 37.7 vs B 66.9\n- [Diagrams.so API + MCP vs PlantUML](https://www.anchorterminal.com/compare/diagrams-so-vs-plantuml.md): C 60 vs B 66.9\n- [draw.io + MCP vs PlantUML](https://www.anchorterminal.com/compare/drawio-vs-plantuml.md): B 62.2 vs B 66.9\n- [Eraser API + MCP vs PlantUML](https://www.anchorterminal.com/compare/eraser-vs-plantuml.md): E 38.6 vs B 66.9\n- [Lucid API + MCP vs PlantUML](https://www.anchorterminal.com/compare/lucid-vs-plantuml.md): C 60.6 vs B 66.9\n- [Mermaid Chart MCP vs PlantUML](https://www.anchorterminal.com/compare/mermaid-chart-vs-plantuml.md): F 31.4 vs B 66.9\n- [Mural MCP vs PlantUML](https://www.anchorterminal.com/compare/mural-mcp-vs-plantuml.md): E 41.9 vs B 66.9\n- [PlantUML vs Whimsical MCP](https://www.anchorterminal.com/compare/plantuml-vs-whimsical.md): B 66.9 vs D 52.6\n- [D2 vs PlantUML](https://www.anchorterminal.com/compare/d2-vs-plantuml.md): B 65.3 vs B 66.9\n- [PlantUML vs Structurizr + MCP](https://www.anchorterminal.com/compare/plantuml-vs-structurizr.md): B 66.9 vs C 59.9\n- [PlantUML vs tldraw SDK + MCP](https://www.anchorterminal.com/compare/plantuml-vs-tldraw.md): B 66.9 vs C 60.7\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on plantuml.com or one of its subdomains, or the README of github.com/plantuml/plantuml. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"plantuml\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/plantuml\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/plantuml.svg\" alt=\"PlantUML on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![PlantUML on Anchor Terminal](https://www.anchorterminal.com/badges/plantuml.svg)](https://www.anchorterminal.com/tools/plantuml)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/plantuml\"\u003ePlantUML on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say PlantUML is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/plantuml-dark.png\n- Light: https://www.anchorterminal.com/assets/share/plantuml-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Diagramming",
        "url": "https://www.anchorterminal.com/categories/diagramming"
      },
      {
        "name": "PlantUML",
        "url": ""
      }
    ],
    "description": "PlantUML is open-source software that turns text descriptions into UML, architecture, Gantt, mind map and other diagrams. Agents run it as a Java command-line tool, a Java library, a local HTTP server or the @plantuml/mcp-js MCP server.",
    "facts": [
      "rank #251 of 842",
      "None auth",
      "0 desk reviews"
    ],
    "h1": "PlantUML",
    "image": "https://www.anchorterminal.com/assets/og/tools-plantuml.png",
    "path": "/tools/plantuml",
    "published": "2026-10-01",
    "section": "tools",
    "title": "PlantUML review for AI agents, grade B (66.9/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/plantuml"
  },
  "tokens": {
    "markdown": 6200,
    "slim": 1580
  },
  "version": 1
}
