Product status
Published MacCrab Rave offerings, compatibility, and known limitations
Last checked: 7 September 2026.
Available now
Mac Security Posture Pro 0.3.1 is the only published Rave plugin. It collects security-control and system-inventory metadata. Its release archive, catalog records, and revocation list are signed. There are no published kits.
The archive is Apple Silicon only. MacCrab itself also supports Intel, but this plugin archive does not. The catalog declares MacCrab 1.19.0 or newer and macOS 13 or newer; those version declarations do not establish that every combination has been tested. MacCrab’s last published release is v1.21.5. The next v1.22.0 release is in development.
Access and result limitations
First-party plugins run in a Developer-ID-validated, unsandboxed process with MacCrab’s privileges, including Full Disk Access if granted to the app. Posture Pro declares read-only metadata collection and no outbound network use. Its current execution path does not enforce filesystem or network restrictions. See verification for what signatures establish.
Posture Pro 0.3.1 can produce a grade when collection is incomplete, and some unavailable sources may appear empty. Treat its grade as a limited assessment; it does not establish that every control or inventory source was examined. Coverage reporting and collection reliability are being corrected for a future release.
Posture Pro 0.1.0 through 0.3.0 are revoked because those builds lack the Developer ID signature required by newer MacCrab releases. Use the current release. Historical version records remain available for inspection.
In development
Universal plugin packaging, clearer collection coverage, version-specific permission approval, complete posture analysis, scan comparison, and verifiable investigation exports are planned improvements. Unpublished plugin source and analyzer packages are not installable offerings. Kit installation and enterprise mirrors are also planned.
The submission page checks current intake availability before login. Availability is a deployed setting; it is separate from qualification of the complete community publishing journey. There are no published community plugins in the current catalog.