Ecosystem report · 43 tracked · data as of Oct 2, 2026

State of the ecosystem.

What moved across every tracked OpenClaw alternative, how the architecture cohorts actually compare, and where the security and deployment posture sits. Numbers are computed from the same data the profiles use — no figure on this page is written by a model.

Measured · tables built at compile timeAI-written summary · Sep 27, 2026Summary written against older data

Tracked

43

projects in every table below

New stars

3,419

across 7 days

Flat

17

gained nothing in the window

Hardened

5

security ≥ 85 and shell risk ≤ 4

The short version

Five things worth knowing before you open the index. Everything below expands on them with the full tables.

  1. 01Hermes Agent led absolute gains at +1870; OpenClaw added +458 to 390599.
  2. 02Edge and minimalist tools are the largest cohort at 22 projects with a median 12.5 MB footprint.
  3. 03Compiled runtimes average a security score of 78 versus 66 for scripting runtimes.
  4. 0436 projects are local-first and only 4 require a cloud account.

What moved

Star movement, Sep 25, 2026 → Oct 2, 2026.

Measured from the daily star history for 43 of 43 tracked projects. Absolute growth favours the large repos, so the relative column is listed beside it.

17 of 43 projects gained nothing over the window.

Architecture

Three cohorts, assigned by rule.

Rules are applied in order and the first match wins, so all 43 projects land in exactly one cohort and none can appear twice. Medians are computed per cohort.

Edge & minimalist22 of 43

Single-binary runtimes small enough for a tiny VPS, an ARM board, or an always-on background process.

Rule: Memory ≤ 20 MB and boot ≤ 50 ms

Mem
12.5 MB
Boot
30 ms
Sec
78

+ 17 more in this cohort

Team & multi-tenant12 of 43

Heavier runtimes that carry shared workspaces, tenant separation, or channel fan-out for a group.

Rule: Multi-user declared, above the edge footprint

Mem
90 MB
Boot
220 ms
Sec
67

+ 7 more in this cohort

Full-runtime assistant9 of 43

Single-operator assistants that keep the reference feature surface and pay for it in memory and boot time.

Rule: Everything else

Mem
90 MB
Boot
220 ms
Sec
68

+ 4 more in this cohort

Security

The runtime split, in real numbers.

Averages and medians over the five security sub-scores every profile carries. Sandboxing and telemetry safety are protection axes where higher is better; shell risk runs the other way. How the axes are scored.

CohortProjectsAvg securitySandboxingShell riskTelemetry
Compiled runtimesRust, Go, Zig, C, C++, Kotlin20787 / 105 / 108 / 10
Scripting runtimesPython, TypeScript, JavaScript and friends23665 / 107 / 106 / 10

Median score

72 / 100

Across all 43 tracked projects

Hardened

5

Security ≥ 85 with shell risk ≤ 4

Open shell

9

Shell risk ≥ 8, largely unsupervised execution

Posture

Where the data actually runs, and under what licence.

Local-first

36 / 43

Cloud required

4 / 43

Cloud optional

38 / 43

Multi-user

18 / 43

Licences

  • MIT20
  • Apache-2.010
  • AGPL-3.02
  • GPL-3.01
  • Not published10

Runtimes by median footprint

Rust12 projects · median 15 MB
Python10 projects · median 90 MB
TypeScript10 projects · median 85 MB
Go4 projects · median 14 MB
C2 projects · median 1 MB
JavaScript1 project · median 90 MB
Kotlin1 project · median 300 MB
n8n Workflow (JSON)1 project · median 150 MB
Shell1 project · median 8 MB
Zig1 project · median 1 MB

20 projects run on a compiled runtime and 23 on a scripting runtime — the split that drives most of the footprint and containment difference above.

Next

The report shows the shape. The index gets you to a shortlist.

Every project named above links to its profile. Sort the full index by what you care about, then send two candidates into a side-by-side comparison.

Nominate a clone

Add a new Claw

Paste a GitHub repository and tell us why it belongs on the tracker.

Opens a prefilled issue on GitHub — every nomination is public. Comfortable with a PR? Adding the repo to projects.json is faster.