Archive Inspector
Look inside a ZIP, TAR or TAR.GZ without extracting it. Every file, its real size, and anything worth a second look — links, paths that escape their folder, and members that expand suspiciously.
ZIP Inspector
Add your files. Recommended settings are ready, so you can process in one click.
PDF, Word, images, audio, video, archives and more
Up to 100 files · 250 MB · No account- 1Add files
- 2Choose an action
- 3Download or keep going
What happens to your file.
For a ZIP, the central directory is read directly so the names appear exactly as the archive stores them — most readers quietly resolve a "../" away, which hides the very thing you would want to know. The external attributes are read from the same place, which is where the Unix mode that marks a symbolic link lives. For a TAR, the 512-byte headers are walked, including the GNU and PAX extensions that carry long names. Member contents are only decoded to the extent needed to report a real size, and nothing is written anywhere. Process file lists a ZIP on our server as a JSON report: every entry with its sizes, date, compression method, checksum and whether it is encrypted, with the same warnings, and names from a ZIP made on a Mac read correctly.
Where it stops: In the visual editor, a password-protected ZIP cannot be read, and you are told so; Process file lists its names, sizes and dates, which a ZIP stores unencrypted. In the visual editor, very large archives are limited by what your browser can hold in memory. Flagging a member is not a virus scan — it reports what the archive structure says, not what a file does.
What each warning means
| Warning | Why it matters |
|---|---|
| Points outside the folder (../) | Extracting this member could write over a file elsewhere on the system |
| Stored as an absolute path | The member asks for a fixed location rather than your chosen folder |
| Stored with a Windows drive letter | The same idea, written the Windows way |
| Name contains hidden control characters | Used to disguise what a file really is |
| A symbolic link / hard link | A pointer rather than a file, often aimed outside the archive |
| Expands more than 200× | The signature of a compression bomb |
| Another member writes to the same name | One will silently overwrite the other |
| Two extensions, e.g. invoice.pdf.exe | Built to look like a document while being a program |
| Runs when opened | An executable, script or installer |
Does inspecting an archive put me at risk?
No. The archive is read in your browser as data: nothing is written to your computer, nothing is extracted, and no file inside it is ever run. That is the reason to look here first rather than double-clicking an archive you were sent and hoping.
What people use it for.
Everything you need, without a paywall.
Common questions.
Is the archive extracted to inspect it?
No. Members are read as data to report their real sizes, and nothing is written to your computer or run, in the visual editor or with Process file. That is what makes this safe on an archive you do not yet trust.
What does a very high compression ratio mean?
Usually just highly repetitive text. An extreme ratio on a small member can also mean a compression bomb built to expand enormously, which is exactly what you want to know before extracting.
Can I see inside a password-protected ZIP?
Yes, with Process file: a ZIP keeps the names, sizes and dates of its files unencrypted, so they are listed without the password. The contents stay locked. The visual editor tells you the archive is protected.
Why does a name look different from what was stored?
Both are shown. The safe path is what any extraction should use; the "stored as" line underneath is the archive’s own name. When they differ, the archive was asking for something it should not have.
Can I keep the listing?
Yes. Download it as a CSV with every member, its sizes, its date and any warnings, which opens in Excel or Google Sheets.
Is this a virus scan?
No. It reports what the archive structure says about each member. It cannot tell you what a file does when you run it, so treat it as a first look rather than a clean bill of health.
Is my archive uploaded?
Not with the visual editor, which reads it in your browser. Process file sends it to our server, where it is written to a temporary folder for that request and deleted as soon as the job finishes.
You might also need.
Convert TAR or TAR.GZ archives into ZIP while safely validating archive member paths.
Convert a ZIP archive into TAR while safely validating member paths and extraction size.
Safely extract one ZIP archive per job with path-traversal, member-count and total output-size limits.
Detect a file type from its signature, extension and parsable format information instead of trusting the filename alone.