Legacy / migrateauto-tracked

OpenClaw

The original viral self-hosted AI agent. Post-crisis 2026.4 line is genuinely safer; pre-2026.3 is genuinely dangerous.

GitHub stars
0
Last release
2026.4.7
2026-04-22
CVEs (open / total)
1 / 17
Sandbox default
yes
12-week star trend
+46K stars over 12 weeks

Overview

OpenClaw became the most-installed self-hosted agent of late 2025 / early 2026, peaking around 135,000 installs. The January 2026 security crisis (CVE-2026-25253 et al.) triggered a transfer to a Linux Foundation-hosted foundation and a substantial security overhaul. The 2026.4 line ships sandbox-on, encrypted credentials, authenticated dashboard. Plugin ecosystem is the largest in the category.

Quick verdict

Best for

  • Existing OpenClaw deployments with custom plugins
  • Teams already trained on the OpenClaw model
  • Agents that need the largest plugin marketplace

Not for

  • New deployments — Hermes Agent is the easier on-ramp
  • Pre-2026.3 hosts that haven't migrated (assume compromise)
  • Strict no-cloud requirements (use ZeroClaw)

Security posture

Sandbox by defaultyes
Auth on dashboardyes
Threat model documentedyes
Multi-LLM supportyes
CVEs disclosed (lifetime)17
CVEs open right now1

Links

Run OpenClaw on portable hardware

Verified working on these portable hosts (with the standard caveats — see the per-device pages for power, RAM headroom, browser-tool support):

Raspberry Pi 5
€80–110 · 5–12 W
Intel NUC 13 / Mini PC
€300–600 · 15–55 W
Framework Laptop 13 / 16
€1100–2200 · 15–80 W
Geekom IT13 / generic Intel mini PC
€450–550 · 20–55 W
Lenovo ThinkCentre M75q (used)
€150–250 used · 15–35 W
Minisforum UM790 Pro
€700–900 · 25–65 W
Dell OptiPlex 3070 / 5070 Micro (used)
€100–180 used · 15–35 W

Compare OpenClaw with others

OpenClaw vs Hermes Agent
Safe default
OpenClaw vs Nanobot
Specialist pick
OpenClaw vs NanoClaw
Specialist pick

OpenClaw security advisories (7)

See all 7 OpenClaw CVEs →


Stats refreshed continuously from public sources (GitHub API, NVD CVE feed, CISA KEV, project releases). See our methodology for the full tracking pipeline.

See also: all AI agents, all AI CVEs, AI hardware, scan your AI stack, Pro alerts.