OpenClaw Review: Setup, Results and Limitations

OpenClaw is one of 2026's most talked-about AI projects: an open-source assistant that lives in your chat apps and actually does things. It's also had one of the year's roughest security records. This review weighs what it does well, what people report after weeks of daily use, and where it falls short.

Verdict

7.5/10. The most capable free personal AI agent you can run yourself, and genuinely useful once it's set up. But setup takes effort, costs depend on your model choice, and security is your job. It's great for technical users who'll run it on a dedicated machine. It's not for anyone who wants it to just work.

Scores

OpenClaw review scores

Capabilities9/10

Chat apps, memory, schedules, browser, shell and any model, all in one tool.

Flexibility9.5/10

MIT license, 29 channels, hosted or local models, skills and plugins.

Value8.5/10

Free software. Personal setups often cost $20–$50 a month in total.

Reliability7/10

Solid day to day, but users report occasional hallucinations and breaking updates.

Documentation7/10

Extensive and current, though advanced setups have gaps.

Ease of setup5.5/10

Much better in 2.0, but you still need terminal and server skills.

Security by default4.5/10

Hardening is possible but manual, and the 2026 track record is rough.

These are our editorial scores, based on the evidence on this page. They weren't produced by lab benchmarks. The overall 7.5 is our judgment, not an average.

At a glance

Pros and cons

What we like

  • Works in apps you already use: WhatsApp, Telegram, Slack, iMessage and more
  • Long-term memory that users say "knows" them after about a week
  • Real actions: browser, files, shell and scheduled jobs
  • Any model, including free local ones, or your ChatGPT or Claude plan
  • Free, MIT-licensed, with a foundation behind it

What we don't

  • Setup and debugging need real technical skill
  • A serious 2026 security record, including malicious ClawHub skills
  • API bills can surprise you in the first week
  • Fast release pace means occasional breaking changes
  • No official support. You rely on docs and the community.
Quick facts

OpenClaw at a glance

What it is
Self-hosted personal AI assistant and agent
Creator
Peter Steinberger. Now stewarded by the OpenClaw Foundation.
First released
November 2025. Formerly Clawdbot and Moltbot. Name history
Latest major
OpenClaw 2.0 (v2026.8.1), August 30, 2026
License and price
MIT open source, $0
Runs on
macOS, Windows, Linux, Docker, Raspberry Pi
Chat channels
29, including WhatsApp, Telegram, Discord, Slack and iMessage
Models
Claude, GPT, Gemini, OpenRouter, Ollama and other local models
Popularity
247,000 GitHub stars by March 2026 (Wikipedia)
Setup

The setup experience

Reported setup times vary widely with skill level and hosting choice:

MinutesCybernews, using a one-click VPS template, February 2026
~30 minComputerTech, plus under 10 minutes per chat app
1–3 hoursClawTank's 30-day test, plus time spent debugging

OpenClaw 2.0 made this easier. According to The Rundown's review of v2026.8.1, onboarding now detects the model access you already have, checks it with a real response, and leaves non-essential settings until after your first conversation. The rebuilt Control UI is now a proper control center rather than an afterthought.

You'll still need to be comfortable with a terminal, editing a config file and, for 24/7 use, a VPS. Our step-by-step guides cover each part: install, connect a model, add Telegram and your first workflow.

Results

What people report after daily use

"After the first week, OpenClaw knew my work schedule, my client names, my communication style, and my preferences."
ClawTank, 30 days of daily use
"The weekend you spend getting it configured will pay back in months."
ComputerTech, six months running a website's operations
"You shouldn't run it on your personal computer unless you really know what you're doing."
Cybernews review
Briefings and triage

A 30-day tester replaced several morning checks with one briefing that took about 90 seconds to read, and said about 90% of drafts needed only small edits.

Scheduled automation

One site owner runs content pipelines, cron jobs and Telegram alerts on a single $24 a month server.

Monitoring

Cybernews set up stock tracking with weekly scheduled reports. Most tasks ran quickly, and web scraping was slower but completed.

ClawTank sells OpenClaw hosting, and several review sites earn from affiliate links, so weigh their enthusiasm accordingly. The patterns above match across independent sources.

Limitations

Where OpenClaw falls short

Learning curve

"Days 1–3 are slow and you question whether it is worth the effort" (ClawTank). It gets better as memory builds up.

Hallucinations

A daily user saw wrong facts about 2–3 times a week. Check anything important.

Surprise costs

$45 in API charges in the first week before tuning. Cheaper models and spending limits fixed it.

Not real-time

Proactive checks run on schedules, often 5 minutes to an hour apart, not instantly.

Debugging

When a cron job fails, you read logs and trace tool calls. There's no support desk.

Breaking changes

Rapid releases can break configs or integrations. Back up before updating.

Local models

Free and private, but smaller models struggle with long, multi-step tasks.

Prompt injection

Emails, web pages and files can carry hidden instructions. Roles and approvals help, but they aren't a full security boundary.

Helpful guides: update and back up safely · local model trade-offs.

Security record

OpenClaw's 2026 security incidents

Rapid growth made OpenClaw a target. Most incidents were fixed or come down to configuration, but they show why setup matters.

CVE-2026-25253: visiting a malicious web page could steal tokens and give an attacker operator access. Fixed in 2026.1.29.

30,000+ exposed instances found online without authentication (SecurityScorecard), leaking API keys and chat histories. Gateway token auth is now on by default.

Malicious ClawHub skills: Koi Security found 341 malicious skills out of 2,857 audited. IBM X-Force reports more than 1,100 in the "ClawHavoc" campaign, some among the most downloaded.

"ClawJacked": malicious sites could brute-force and hijack local instances. Patched in 2026.2.26.

Moltbook breach: this third-party social network for AI agents exposed about 1.5 million API tokens.

China restricted state enterprises, agencies and banks from using OpenClaw.

The Register criticized 2.0 for lacking "security by default", citing unencrypted credentials and sandboxing off by default.

Our take

The core is now much harder to attack than in January, but OpenClaw is still powerful software that trusts you to configure it well. Never install unvetted skills, keep the gateway off the public internet, and run it on a dedicated machine or VPS. Full checklist: OpenClaw security guide.

Readiness check

Are you ready to run OpenClaw?

Tick everything that's true for you.

Result
    Next step
    Money

    What it really costs

    ReviewerSetupReported monthly cost
    ClawTank (30 days)Claude Sonnet as the main model$18–$25 API + $5–$12 hosting
    ComputerTech (6 months)$24 DigitalOcean server, Claude and OpenAI$10–$30 API (light) to $50–$150 (heavy), plus $24 server

    The software is free, and the model is the main variable. Estimate your own costs with our OpenClaw cost calculator.

    Final verdict

    7.5/10: powerful, personal, not plug-and-play

    OpenClaw delivers what most "AI assistants" only promise. It lives where you already chat, remembers you, and does real work on a schedule, with the model of your choice and no subscription. People who stick with it report real time savings. The price is effort and responsibility: setup, tuning costs, and above all security. If that sounds fun rather than frightening, it's the best free option in its class.

    • Get it if: you're technical, want automation in your chat apps, and will run it on a dedicated machine
    • Skip it if: you want zero setup, managed security or official support. Try ChatGPT or see alternatives
    • For business pipelines: compare OpenClaw vs n8n
    Transparency

    How we reviewed OpenClaw

    This is a research-based review. We read the official OpenClaw documentation for version 2.0 (v2026.8.1) while writing the step-by-step guides on this site. We then compared published hands-on reviews from Cybernews, ComputerTech, ClawTank and The Rundown, and security reporting from IBM X-Force, DigitalOcean and others. Usage results quoted here belong to those reviewers, and each is credited. We didn't run formal benchmarks. Clawdsbot.com is independent and not affiliated with or endorsed by the OpenClaw Foundation.

    FAQ

    OpenClaw review questions

    Is OpenClaw worth it?

    For technical users who want an assistant in their chat apps that runs real tasks, yes. Reviewers report time savings once it's set up, and the software is free. If you want zero setup and managed security, a hosted assistant is a better fit.

    Is OpenClaw safe to use?

    It can be, if you configure it carefully. It had serious 2026 incidents, including exposed instances and malicious ClawHub skills. Run it on a dedicated machine or VPS, keep the gateway private, keep it updated and never install unvetted skills.

    How long does OpenClaw take to set up?

    Published reviews range from minutes with a one-click VPS template, to about 30 minutes, to 1 to 3 hours plus debugging. OpenClaw 2.0's simpler onboarding has shortened this, but some terminal skill is still needed.

    How much does OpenClaw cost per month in practice?

    Reviewers report about $18 to $30 a month in model API fees for light personal use, plus $5 to $24 for hosting. Heavy automation can reach $50 to $150 or more. The software itself is free.

    What are OpenClaw's biggest limitations?

    The learning curve, occasional hallucinations, unpredictable API costs at first, schedule-based rather than real-time monitoring, breaking changes from fast releases, and security that depends on your setup.

    What's new in OpenClaw 2.0?

    Version 2026.8.1, released August 30, 2026, added simpler onboarding that checks your existing model access, a rebuilt Control UI, and multi-user sessions with handoff between trusted teammates.

    Related guides