Archive Workbench
Inspect and edit a small ZIP without uploading it. This workbench checks the raw directory before unpacking, verifies each file's CRC-32 while reading, and keeps edits in memory until you download a new ZIP. It preserves safe nested paths and original file bytes.
Key features
- List safe ZIP paths, sizes and CRC-32 values after verifying the actual file bytes
- Reject traversal paths, duplicate aliases, encrypted entries and unsupported ZIP variants before extraction
- Limit entries, file sizes, total uncompressed bytes and declared compression ratios
- Add local files, remove entries and download individual files
- Save a new ZIP and reopen it with a standard ZIP reader
- Work entirely in the browser with no account or file upload
How to use
- Open a local .zip file or load the example archive.
- Review its entry paths, original compressed sizes, uncompressed sizes and validated CRC-32 values.
- Add local files or remove unwanted entries. Added files use their basename at archive root.
- Download an individual file if needed, then choose Download rebuilt ZIP and check the saved result.
Use cases
- Remove an unwanted document from a small ZIP before sharing
- Add a readme or license file to a ZIP containing nested folders
- Inspect suspicious archive paths and CRC failures without extracting to disk
- Check a ZIP's file inventory and download one safe member
Frequently asked questions
Which archive formats work?
Only classic single-disk .zip archives with stored or Deflate members. RAR, 7z, TAR, ZIP64, encrypted archives, multi-volume archives and non-ASCII legacy filename encodings are unsupported. The new ZIP uses stored entries, so it may be larger than the input.
How do you stop ZIP slip and decompression bombs?
The raw ZIP directory is checked before decompression. Absolute or parent paths, unsafe separators and path aliases are rejected. Inputs are capped at 40 MiB, each file at 8 MiB, total expanded bytes at 32 MiB, 100 entries and a declared compression ratio of 100:1. The reader also stops if streamed bytes exceed the declared size.
Are CRC-32 values verified?
Yes. Each file is decompressed under a byte cap and its actual bytes are checked against the ZIP CRC-32. CRC-32 detects accidental damage, but is not a cryptographic authenticity or malware check.
Will my original ZIP metadata survive?
File bytes and safe names survive. Repacking creates a new stored ZIP; compression method, timestamps, comments, permissions and extra fields are not preserved. Symlinks and special files are rejected.
Are my files uploaded?
No. The ZIP and additions are read locally and downloads are generated in this tab. Large files are rejected before being read.
Privacy
ZIPs and added files stay in this browser tab. They are read with the File API and processed in memory; no archive content is sent to the server or analytics.
Comments & questions