Open-source, self-hosted WeChat mini-program `.wxapkg` decompiler: auto-decrypt, unpack, decompile and tidy in the browser, then download a clean `src/` project — run online or via Docker Compose, no external database, cache or message queue required.
DSH integration
Ecosystem-related
Safety audit
Unaudited
Last verified
2026-08-27
License
MIT
01What can it help you accomplish?
Decompile WeChat mini-program .wxapkg files from a browser
A clean src/ project — auto-decrypted (when an AppID is provided), unpacked, decompiled and tidied — downloaded as a ZIP that never mixes in the raw unpacking data
Developers and analysts who need to inspect, learn from or troubleshoot WeChat mini-program packages they are authorized to process
Self-host a private decompilation service with Docker Compose
A single-machine Web service (UI on :3004, API on :9090) whose task state, queue and artifacts live only in local volumes — no external database, cache or message queue
Users handling sensitive, private or not-yet-authorized packages who should avoid the public demo site and process them in a controlled self-hosted environment
02How to install into DeepSeek Harness
Prerequisites
- Docker Engine and Docker Compose — the README says these are all you need for self-hosting
- A .wxapkg file to process (encrypted packages also need the matching AppID)
Installation steps
- 01
Clone the repository: `git clone https://github.com/Leslie-SSS/seeWxapkg.git`
$ git clone https://github.com/Leslie-SSS/seeWxapkg.git
- 02
Enter the directory: `cd seeWxapkg`
- 03
Start the stack: `docker compose up -d --build`
Verify the integration
- Open the web UI at http://localhost:3004, or check the health endpoint at http://localhost:9090/api/health
Rollback
- Stop the service: `docker compose down`
- To immediately delete all uploads, task records and artifacts: `docker compose down -v`
03DSH integration and capability boundaries
Static decompilation without executing package code
.wxapkg file (standard / encrypted / common WeChat 4.x structures)→Unpacked and tidied JSON, JavaScript, WXML, WXSS — unconfirmable content is honestly marked
Never executes package JavaScript via eval, Function or a VMEncrypted-package support via a matching AppID
Encrypted .wxapkg + the AppID that matches the target package→Decrypted decompilation result
AppID is destroyed after one decryption attemptLive progress, status, quality score & technical reports
A decompilation task→Real-time progress, result status, static quality score, check hints and technical reports
reports/ technical reports are not included in the download ZIP; query them via the result page or the task APIHTTP API for tasks and artifacts
POST /api/compile upload of a .wxapkg file→Task state, SSE live progress, technical reports, diagnostics and artifact download (/api/download/:taskId)
API has no built-in user authentication or per-user task permissionsSingle-machine Docker Compose self-hosting
Docker Engine + Docker Compose→Self-hosted web UI (:3004) and API (:9090); task data kept only in configured local volumes
No external database, cache or message queue
04Who is it for? When not to use it?
Good for
- Developers and analysts who need to inspect, learn from or troubleshoot WeChat mini-program packages they are authorized to process
- Users handling sensitive, private or not-yet-authorized packages who should avoid the public demo site and process them in a controlled self-hosted environment
Not for
- Encrypted packages must be paired with the AppID that matches the target package, and the AppID is destroyed after one decryption attempt. The public demo site temporarily stores uploads during processing — do not upload sensitive, private or unauthorized packages; self-host in a controlled environment instead.
- The API has no built-in authentication or per-user task permissions — public deployments must add TLS, authentication and rate limiting at an upstream gateway and isolate the worker network.
05Compatibility, maintenance and safety notes
- Decompilation is a best-effort static recovery of the compiled artifact, not extraction of the original source — the result may lack original variable names, comments, directory structure or runtime-generated content, and the output project is not guaranteed to compile or run.
- Encrypted packages must be paired with the AppID that matches the target package, and the AppID is destroyed after one decryption attempt. The public demo site temporarily stores uploads during processing — do not upload sensitive, private or unauthorized packages; self-host in a controlled environment instead.
- The API has no built-in authentication or per-user task permissions — public deployments must add TLS, authentication and rate limiting at an upstream gateway and isolate the worker network.
- WeChat 4.x aggregate structures are supported for common layouts only — not every client version or build variant — and game packages are currently only classified, not fully decompiled.
MIT · actively maintained (README: own code MIT, fallback component GPL-3.0-or-later; last push 2026-08-26, no releases)
06Frequently asked questions
Does See Wxapkg integrate with the DeepSeek Harness (dsh) CLI?
The README makes no mention of dsh, MCP or any DeepSeek Harness integration — it is a standalone web application. Deployment only needs Docker Engine and Docker Compose (`git clone https://github.com/Leslie-SSS/seeWxapkg.git`, then `docker compose up -d --build`), or you can use the public site at seewxapkg.keepbuild.cn.
Which package types can it decompile?
Standard packages, encrypted packages and common WeChat 4.x structures. Encrypted packages require a matching AppID (18 digits: `wx` + 16 lowercase hex chars), and the AppID is destroyed after one decryption attempt.
Does decompilation execute any code from the package?
No. The README states decompilation is static only: it never executes package JavaScript through eval, Function or a VM, and it honestly marks content it cannot confirm.
Can I self-host it, and how is data handled?
Yes — Docker Compose self-hosting is the recommended option. Task state, queue and artifacts live only in local volumes with no external database, cache or message queue; normal terminal states delete the original upload immediately, and the AppID credential file uses 0600 permissions and is removed after one decryption attempt.
Can the decompiled result be compiled and run directly?
No. Decompilation is a best-effort static recovery of the compiled artifact, not extraction of the original source — the result may lack original variable names, comments, directory structure or runtime-generated content, and is not guaranteed to match the original project or run.
07Related DSH workflows
awesome-gpt-image-2
by freestylefly
Prompt-as-Code engine and template library for GPT-Image2, with 470+ reverse-engineered cases, 20+ production templates and distilled agent skills.
voyager
by voyager-crew
A browser-extension suite for Gemini, AI Studio, Claude, ChatGPT, and DeepSeek, with a prompt manager that works on any website, including DeepSeek Harness.
dsh-im
by xmanrui
把 IM 机器人接入 DSH:统一管理飞书/微信/钉钉/企业微信/QQ/Telegram/Discord/WhatsApp 八个渠道,扫码或凭据接入、流式回复与设置页管理
wegent
by wecode-ai
Plan, build, and deliver with an open-source, self-hostable AI workspace for coding, collaboration, and automation.
08Data and sources
This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-08-27. Found an error? Submit a correction.
Best DeepSeek Harness Plugins
Twelve plugins worth installing first — picked from the whole catalog, across every category.
