Back to directory

seewxapkg

Maintenance: Active

leslie-sss/seewxapkg

Minimal, practical web tool for decompiling WeChat mini-program (wxapkg) packages.

View on GitHubHomepage
$ git clone https://github.com/Leslie-SSS/seeWxapkg.git

105

stars

31

forks

Go

Language

MIT

License

2026-01-31

Created

2026-09-25

Last push

Open-source, self-hosted WeChat mini-program `.wxapkg` decompiler: auto-decrypt, unpack, decompile and tidy in the browser, then download a clean `src/` project — run online or via Docker Compose, no external database, cache or message queue required.

DSH integration

Ecosystem-related

Safety audit

Unaudited

Last verified

2026-08-27

License

MIT

01What can it help you accomplish?

  • Decompile WeChat mini-program .wxapkg files from a browser

    A clean src/ project — auto-decrypted (when an AppID is provided), unpacked, decompiled and tidied — downloaded as a ZIP that never mixes in the raw unpacking data

    Developers and analysts who need to inspect, learn from or troubleshoot WeChat mini-program packages they are authorized to process

  • Self-host a private decompilation service with Docker Compose

    A single-machine Web service (UI on :3004, API on :9090) whose task state, queue and artifacts live only in local volumes — no external database, cache or message queue

    Users handling sensitive, private or not-yet-authorized packages who should avoid the public demo site and process them in a controlled self-hosted environment

02How to install into DeepSeek Harness

Prerequisites

  • Docker Engine and Docker Compose — the README says these are all you need for self-hosting
  • A .wxapkg file to process (encrypted packages also need the matching AppID)

Installation steps

  1. 01

    Clone the repository: `git clone https://github.com/Leslie-SSS/seeWxapkg.git`

    $ git clone https://github.com/Leslie-SSS/seeWxapkg.git

  2. 02

    Enter the directory: `cd seeWxapkg`

  3. 03

    Start the stack: `docker compose up -d --build`

Verify the integration

  • Open the web UI at http://localhost:3004, or check the health endpoint at http://localhost:9090/api/health

Rollback

  • Stop the service: `docker compose down`
  • To immediately delete all uploads, task records and artifacts: `docker compose down -v`

03DSH integration and capability boundaries

DSH integrationEcosystem-related
  • Static decompilation without executing package code

    .wxapkg file (standard / encrypted / common WeChat 4.x structures)→Unpacked and tidied JSON, JavaScript, WXML, WXSS — unconfirmable content is honestly marked

    Never executes package JavaScript via eval, Function or a VM
  • Encrypted-package support via a matching AppID

    Encrypted .wxapkg + the AppID that matches the target package→Decrypted decompilation result

    AppID is destroyed after one decryption attempt
  • Live progress, status, quality score & technical reports

    A decompilation task→Real-time progress, result status, static quality score, check hints and technical reports

    reports/ technical reports are not included in the download ZIP; query them via the result page or the task API
  • HTTP API for tasks and artifacts

    POST /api/compile upload of a .wxapkg file→Task state, SSE live progress, technical reports, diagnostics and artifact download (/api/download/:taskId)

    API has no built-in user authentication or per-user task permissions
  • Single-machine Docker Compose self-hosting

    Docker Engine + Docker Compose→Self-hosted web UI (:3004) and API (:9090); task data kept only in configured local volumes

    No external database, cache or message queue

04Who is it for? When not to use it?

Good for

  • Developers and analysts who need to inspect, learn from or troubleshoot WeChat mini-program packages they are authorized to process
  • Users handling sensitive, private or not-yet-authorized packages who should avoid the public demo site and process them in a controlled self-hosted environment

Not for

  • Encrypted packages must be paired with the AppID that matches the target package, and the AppID is destroyed after one decryption attempt. The public demo site temporarily stores uploads during processing — do not upload sensitive, private or unauthorized packages; self-host in a controlled environment instead.
  • The API has no built-in authentication or per-user task permissions — public deployments must add TLS, authentication and rate limiting at an upstream gateway and isolate the worker network.

05Compatibility, maintenance and safety notes

  • Decompilation is a best-effort static recovery of the compiled artifact, not extraction of the original source — the result may lack original variable names, comments, directory structure or runtime-generated content, and the output project is not guaranteed to compile or run.
  • Encrypted packages must be paired with the AppID that matches the target package, and the AppID is destroyed after one decryption attempt. The public demo site temporarily stores uploads during processing — do not upload sensitive, private or unauthorized packages; self-host in a controlled environment instead.
  • The API has no built-in authentication or per-user task permissions — public deployments must add TLS, authentication and rate limiting at an upstream gateway and isolate the worker network.
  • WeChat 4.x aggregate structures are supported for common layouts only — not every client version or build variant — and game packages are currently only classified, not fully decompiled.
2026-01-312026-08-26Not specified by the author

MIT · actively maintained (README: own code MIT, fallback component GPL-3.0-or-later; last push 2026-08-26, no releases)

06Frequently asked questions

Does See Wxapkg integrate with the DeepSeek Harness (dsh) CLI?

The README makes no mention of dsh, MCP or any DeepSeek Harness integration — it is a standalone web application. Deployment only needs Docker Engine and Docker Compose (`git clone https://github.com/Leslie-SSS/seeWxapkg.git`, then `docker compose up -d --build`), or you can use the public site at seewxapkg.keepbuild.cn.

Which package types can it decompile?

Standard packages, encrypted packages and common WeChat 4.x structures. Encrypted packages require a matching AppID (18 digits: `wx` + 16 lowercase hex chars), and the AppID is destroyed after one decryption attempt.

Does decompilation execute any code from the package?

No. The README states decompilation is static only: it never executes package JavaScript through eval, Function or a VM, and it honestly marks content it cannot confirm.

Can I self-host it, and how is data handled?

Yes — Docker Compose self-hosting is the recommended option. Task state, queue and artifacts live only in local volumes with no external database, cache or message queue; normal terminal states delete the original upload immediately, and the AppID credential file uses 0600 permissions and is removed after one decryption attempt.

Can the decompiled result be compiled and run directly?

No. Decompilation is a best-effort static recovery of the compiled artifact, not extraction of the original source — the result may lack original variable names, comments, directory structure or runtime-generated content, and is not guaranteed to match the original project or run.

08Data and sources

This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-08-27. Found an error? Submit a correction.

🏆

Best DeepSeek Harness Plugins

Twelve plugins worth installing first — picked from the whole catalog, across every category.

DSH Plugins is an independent community directory of DeepSeek Harness plugins. Not affiliated with or endorsed by DeepSeek. Third-party plugins are not security-audited — review the source before installing.

New DeepSeek Harness plugins, weekly. No spam.