# What Programming Languages Does VulnClaw Use? A Dual-Language Architecture Analysis

> Discover the programming languages VulnClaw uses. Its dual-language architecture combines Python 3 for the security engine and TypeScript for the React frontend.

- Repository: [Unclecheng/VulnClaw](https://github.com/Unclecheng-li/VulnClaw)
- Tags: architecture
- Published: 2026-07-03

---

**VulnClaw is built using Python 3 for its core penetration-testing engine and TypeScript for its modern React-based web frontend, creating a dual-language architecture that separates backend security logic from the user interface.**

VulnClaw is an open-source penetration testing framework that leverages a strategic dual-language approach to deliver both powerful automation and modern user experiences. Understanding what programming languages VulnClaw uses is essential for contributors and security researchers who want to extend its capabilities or integrate it into existing workflows. The project combines Python's robust ecosystem for security tooling with TypeScript's type-safe frontend development to create a comprehensive vulnerability assessment platform.

## Python 3: The Core Security Engine

The backbone of VulnClaw is written entirely in **Python 3**, serving as the primary runtime for all security automation, command-line interfaces, and AI agent logic. According to the Unclecheng-li/VulnClaw source code, the Python package is defined in [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml), which declares the entry point for the `vulnclaw` CLI command and manages the project's Python dependencies.

### Entry Points and CLI Interface

The command-line interface is implemented using Typer in [`vulnclaw/cli/main.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/cli/main.py), providing the primary entry point for users running scans from the terminal. The `[project.scripts]` section in [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml) maps the `vulnclaw` command to this Python module, enabling direct invocation after installation.

### Agent Logic and Penetration Testing

At the heart of the security engine lies [`vulnclaw/agent/solver.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/solver.py), which implements the goal-driven solving loop for AI-powered penetration testing. This Python module handles the core automation logic, plugin orchestration, and MCP (Model Context Protocol) coordination that enables VulnClaw to perform vulnerability assessments programmatically.

```python

# Example: programmatically invoke the CLI from Python

import subprocess

target = "http://example.com"
result = subprocess.run(
    ["vulnclaw", "run", target],
    capture_output=True,
    text=True,
)
print(result.stdout)

```

## TypeScript: The Modern Web Frontend

Complementing the Python backend, VulnClaw employs **TypeScript** to power its React-based web interface built with Vite. The frontend runs in the browser and communicates with the Python backend via HTTP APIs, providing a graphical alternative to the CLI for managing scans and visualizing results.

### Frontend Build Configuration

The frontend toolchain is configured in [`frontend/vite.config.ts`](https://github.com/Unclecheng-li/VulnClaw/blob/main/frontend/vite.config.ts), which handles the build process and development server setup for the React application. This TypeScript configuration ensures modern bundling standards while maintaining type safety throughout the development workflow.

### API Integration and Type Safety

Type definitions for the REST API are centralized in [`frontend/src/types/api.ts`](https://github.com/Unclecheng-li/VulnClaw/blob/main/frontend/src/types/api.ts), ensuring consistent interfaces between the Python FastAPI backend and the TypeScript frontend. The actual API communication layer resides in [`frontend/src/api/web.ts`](https://github.com/Unclecheng-li/VulnClaw/blob/main/frontend/src/api/web.ts), which provides a thin type-safe wrapper around HTTP requests.

```typescript
// Example: fetch a list of available plugins from the FastAPI server
import { apiClient } from "./api";

export async function loadPlugins() {
  const response = await apiClient.get<{ id: string; name: string }[]>(
    "/plugins/list"
  );
  return response.data;
}

```

## Project Structure: Where Each Language Lives

The repository organizes code by language responsibility:

- **[`vulnclaw/__init__.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/__init__.py)** (Python): Package initializer for the core engine
- **[`vulnclaw/cli/main.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/cli/main.py)** (Python): Typer-based command-line entry point
- **[`vulnclaw/agent/solver.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/solver.py)** (Python): Implements the AI agent's goal-driven solving loop
- **[`frontend/vite.config.ts`](https://github.com/Unclecheng-li/VulnClaw/blob/main/frontend/vite.config.ts)** (TypeScript): Vite configuration for the web UI build process
- **[`frontend/src/types/api.ts`](https://github.com/Unclecheng-li/VulnClaw/blob/main/frontend/src/types/api.ts)** (TypeScript): REST API type definitions ensuring backend-frontend contract alignment
- **[`frontend/src/api/web.ts`](https://github.com/Unclecheng-li/VulnClaw/blob/main/frontend/src/api/web.ts)** (TypeScript): HTTP client wrapper for all backend communication
- **[`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml)** (Python): Project metadata and dependency declaration

## Summary

- **VulnClaw uses Python 3** for all backend security logic, CLI tools, and AI agent orchestration
- **TypeScript powers the frontend**, providing type-safe React components that communicate with the Python backend via HTTP APIs
- **Key Python files** include [`vulnclaw/cli/main.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/cli/main.py) for CLI entry points and [`vulnclaw/agent/solver.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/solver.py) for the penetration testing engine
- **Key TypeScript files** include [`frontend/src/types/api.ts`](https://github.com/Unclecheng-li/VulnClaw/blob/main/frontend/src/types/api.ts) for API contracts and [`frontend/src/api/web.ts`](https://github.com/Unclecheng-li/VulnClaw/blob/main/frontend/src/api/web.ts) for HTTP client implementation
- The dual-language approach separates concerns between security automation (Python) and user interface presentation (TypeScript)

## Frequently Asked Questions

### Is VulnClaw written entirely in Python?

No, VulnClaw is not written entirely in Python. While the core penetration-testing engine, CLI interface, and agent logic are implemented in Python 3, the project includes a modern web interface built with TypeScript, React, and Vite located in the `frontend/` directory.

### Why does VulnClaw use TypeScript for the frontend instead of Python?

TypeScript was chosen for the frontend to leverage modern browser capabilities, React's component model, and compile-time type safety for API communications. This separation allows the Python backend to focus exclusively on security automation while the TypeScript frontend handles the user interface and visualization layers.

### How do the Python backend and TypeScript frontend communicate?

The Python backend exposes REST APIs via FastAPI, which the TypeScript frontend consumes through HTTP requests. The [`frontend/src/api/web.ts`](https://github.com/Unclecheng-li/VulnClaw/blob/main/frontend/src/api/web.ts) file implements the client-side HTTP wrapper, while [`frontend/src/types/api.ts`](https://github.com/Unclecheng-li/VulnClaw/blob/main/frontend/src/types/api.ts) ensures type-safe contracts between both languages.

### Can I run VulnClaw without the TypeScript frontend?

Yes, you can run VulnClaw using only the Python components. The [`vulnclaw/cli/main.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/cli/main.py) module provides a full-featured command-line interface that operates independently of the web frontend. The TypeScript frontend is optional for users who prefer a graphical interface over terminal-based interaction.