Prowl
58/100
prowl
Benchmarked Sep 30, 2026

AltoroJ REST API

API provider (testfire.net:altoroj)

api platform_profile
Benchmark Your API

Score Breakdown

Token Efficiency8/10
Error Clarity7/10
Auth Simplicity7/10
Documentation5/10
First-Try Success5/10
Parseability5/10
Latency2/10
Consistency2/10

Benchmark Analysis Log

Full LLM thinking from the 4-phase benchmark pipeline.

Analyze
{
  "service_type": "platform",
  "base_url": "https://testfire.net:altoroj",
  "auth_method": "none",
  "auth_config": {},
  "endpoints": [],
  "pricing_model": {"type": "free", "details": {"notes": "AltoroJ is a deliberately vulnerable application maintained by IBM for security education and testing."}},
  "rate_limits": {},
  "capabilities": [
    "Deliberately vulnerable online banking demo application",
    "REST API for banking operations (accounts, transfers, login)",
    "Security testing and training target",
    "Supports common web vulnerabilities (SQL injection, XSS, CSRF)",
    "Used for IBM AppScan and other security tool demonstrations"
  ],
  "raw_analysis": "AltoroJ is a Java-based web application created and maintained by IBM as a deliberately vulnerable online banking application. Its primary purpose is educational: to serve as a target for security testing, training, and demonstrations of IBM Security AppScan (now HCL AppScan) and similar security tools. The provided URL (https://testfire.net:altoroj) appears malformed; the actual demo is commonly hosted at https://demo.testfire.net. The service is not a production platform for building integrations; it is a sandbox with known vulnerabilities. The \"REST API\" categorization likely refers to HTTP endpoints used by the web UI (e.g., /login, /doLogin, /transfer, /api/...), but no formal, documented public REST API with authentication exists. Authentication is session-based (cookies) with intentionally weak credentials like admin/admin. Rate limits are not enforced, as the goal is to allow unrestricted testing. Pricing is free; it is an open-source project (Apache 2.0) available on GitHub (github.com/IBM/AltoroJ). Maturity: stable but old (circa 2006-2017), with community forks. Integrations: primarily security scanners, CI/CD pipelines for security validation, and educational exercises. Not recommended for production or as a reliable API provider."
}
Execute

0/3 tests passed

TestEndpointStatusLatency
website_uptimeGET /None27ms
robots_txtGET /robots.txtNone2ms
llms_txtGET /llms.txtNone1ms
Interpret
{
  "overall": 22,
  "dimensions": {
    "token_efficiency": 8.0,
    "first_try_success": 5.0,
    "response_parseability": 5.0,
    "error_clarity": 7.0,
    "doc_quality": 5.0,
    "auth_simplicity": 7.0,
    "latency": 2.0,
    "consistency": 2.0
  },
  "pricing_normalized": {
    "model": "free",
    "tier": "free",
    "notes": "Open-source, IBM-maintained deliberately vulnerable banking app for security education."
  },
  "issues": [
    "All three platform check requests failed with 'Invalid port: altoroj' — the platform name appears malformed in the URL scheme, suggesting no live/addressable endpoint was resolved.",
    "No working status_code, robots.txt, llms.txt, or security headers were returned, meaning no measurable uptime or latency could be verified.",
    "Latency measurements (27ms, 2ms, 1ms) are meaningless because requests never reached the target — they timed out at URL parsing.",
    "Deliberately vulnerable by design: recommending to end users carries inherent risk if mistaken for a production banking API."
  ],
  "recommendations": [
    "Clarify to users that AltoroJ is a security-testing/demo target, not a real banking platform — never for production or real data.",
    "Fix the integration/URL scheme so checks can resolve a real hostname and port; current name 'altoroj' is being parsed as a port.",
    "Provide a public status page or stable endpoint (e.g., GitHub repo or hosted demo URL) to enable uptime and latency verification.",
    "Document supported vulnerability categories and intended tooling (AppScan demos) up front to set correct agent expectations.",
    "Publish an llms.txt or structured endpoint so agents can introspect capabilities programmatically."
  ]
}

Agent Readiness

x402 Payments
Not supported
Streaming
No
Sandbox
None
Agent Auth
Unknown
SDKs
None listed
MCP Support
No

Embed your Prowl badge

Show your live agent-readiness score on your own site. Free, no auth — it updates as your score changes.

Prowl agent-readiness badge
<a href="https://prowl.world/service/altoroj-rest-api">
  <img src="https://prowl.world/badge/altoroj-rest-api.svg" height="56" alt="Agent-readiness on Prowl">
</a>

Options: ?style=light|dark · ?size=sm|md · ?variant=certified (claimed + DNS-verified only) · badge generator with preview

Want the full interactive view?

See operational metrics, LLM evaluations, agent readiness, and more.

Open in Dashboard