Minimal WinUI 3 GUI wrapper for Windows built-in ZIP support.
No 7-Zip. No WinRAR. No third-party compression code.
π Project website Β· π Get it from Microsoft Store Β· β Support the project on Ko-fi Β· πΊπ¦ Π£ΠΊΡΠ°ΡΠ½ΡΡΠΊΠΎΡ
Pakko uses a different trust model β not a claim of absolute security superiority, but a different set of supply chain dependencies with different auditability properties. Both tools have supply chain characteristics (developer jurisdiction, no reproducible builds, CVE history) that some security-conscious environments find unacceptable.
For the full CVE tables and rationale, see SECURITY.md (the canonical source).
| Component | Source | Auditability |
|---|---|---|
| ZIP compression | System.IO.Compression β .NET BCL |
Open source, part of .NET runtime |
| UI framework | WinUI 3 / Windows App SDK | Open source on GitHub |
The entire compression stack is part of the .NET Base Class Library β maintained by Microsoft with a public CVE process, reproducible builds, and community audit via dotnet/runtime.
Trust dependency: The .NET runtime and Windows App SDK are themselves trust dependencies. Pakko's security properties depend on the integrity of Microsoft's supply chain and build infrastructure. Organizations that trust the Microsoft/.NET ecosystem will find this architecture auditable; those that do not should evaluate accordingly.
- No third-party compression dependencies β attack surface limited to .NET runtime
- Open source β full codebase auditable
- Minimal permissions β no network access, no background services
- No telemetry β no data leaves the machine
- Mark of the Web (MOTW) propagation β extracted files inherit
Zone.Identifierfrom the archive by default; prevents macro execution in extracted Office docs (7-Zip does not do this by default) - No libarchive in-process β tar/RAR/7z extraction via isolated
tar.exesubprocess, sandboxed in an AppContainer with no network capability, not an in-process parser - Group Policy / ADMX support β administrators can lock down risky features (e.g. tar-family extraction) fleet-wide; see
docs/POLICIES.md
| Layer | Technology |
|---|---|
| UI | WinUI 3 + Windows App SDK |
| Language | C# 12 / .NET 10 LTS |
| Compression | System.IO.Compression (ZIP) |
| Distribution | MSIX (self-contained) |
| Min OS | Windows 10 1809 (build 17763) / Windows Server 2019 |
| License | Apache 2.0 |
| Format | Status | Method |
|---|---|---|
| ZIP | β read/write, v1.0 | System.IO.Compression |
| TAR/GZ/BZ2/XZ/ZST/LZMA | β read (v1.3) + create (v1.4) | tar.exe (Windows built-in), AppContainer-sandboxed for extraction |
| RAR | β read only, v1.3 | tar.exe (Windows built-in) β libarchive has no RAR writer |
| 7z | β read only, v1.3 | tar.exe (Windows built-in) β libarchive has no 7z writer |
| Password-protected ZIP | β read (ZipCrypto, WinZip AES) and create (AES-256 only) | System.IO.Compression + .NET cryptography |
| Encrypted 7z/RAR | β detected and refused with a clear error | β |
Pakko closes gaps in Windows Explorer:
- Native context menu β Open, Extract here, Extract to folder, Add to
X.zip, Add toX.tar, Compressβ¦, Test archive, Scan for threats, Hash: CRC-32 / SHA-256 (both the modernIExplorerCommandmenu and the classic "Show more options" menu); each command runs in a Pakko window with progress, a password prompt and a conflict dialog - File type associations β double-click any supported archive format opens directly into
Pakko's Archive Browser, not just
.zip - Archive Browser β navigate an archive's folder structure without extracting everything first, extract a selection or the whole archive, then climb past the archive root into the real filesystem (drives, "This PC") the same way NanaZip's classic file manager does
- Scan for threats β hands an archive's contents to the antivirus installed on the machine (through Windows' AMSI interface), password-protected ZIP entries included
- Recovery data (PAR2) β standard PAR 2.0 files written next to a new archive (5, 10 or 20 %), then "Verify with PAR2" and "Repair with PAR2" in the menu and the app; the repaired copy is a new file and the original is only read. par2cmdline and MultiPar read Pakko's sets, and Pakko reads theirs
- Group Policy / ADMX β administrators can disable tar-family extraction and other
risk-relevant features fleet-wide via a real ADMX template; see
docs/POLICIES.md
Windows 11 23H2+ includes tar.exe (Microsoft-signed bsdtar), which Pakko uses β no third-party
compression tools β to read RAR/7z/tar/gz/bz2/xz/zst/lzma, and to create tar-family archives
(plain tar plus the five compression-filter variants).
pakko.exe (project name Archiver.CLI) is a standalone, self-contained command-line build with
7z-familiar commands (x/t/i/a/l, and r to repair from PAR2 files) β it runs independently of the GUI/MSIX. See
docs/CLI.md for the full command/switch specification. Download it as its own
per-architecture zip (with a SHA256SUMS file for verification) from the
project's GitHub Releases page β every version
tag is built and published there automatically. The zip is not added to PATH; from v1.7.0 the
Microsoft Store/MSIX install also gives the pakko command in any terminal, and the zip can be
installed with winget once the winget catalog accepts the package β see docs/CLI.md's "Distribution" section.
ZIP archive/extract (with passwords), the native shell extension (context menu, file
associations, MOTW propagation), sandboxed RAR/7z/tar-family read + tar-family create via
tar.exe, the Archive Browser, antivirus scan, PAR2 recovery data, the pakko command line and
Group Policy/ADMX support are all implemented and on-device verified. Per-release history:
CHANGELOG.md.
- β Archive (single / separate) with compression level selector, ZIP or any tar-family format
- β Extract with smart folder logic, ZIP slip protection, and a per-conflict Ask/Overwrite/ Rename/Skip resolution
- β
Password-protected ZIP β extract, test, browse, and threat-scan (ZipCrypto + WinZip AES),
with a password prompt in the app, the Explorer menu, and the CLI (
-p); create AES-256 encrypted ZIPs from the app orpakko a -p(file names inside the archive stay visible) - β System tray icon
- β
File log (
%LocalAppData%\Pakko\logs\pakko.log) - β i18n β 37 locales, OS-language auto-match with English fallback
- β
MSIX packaging, signed with a dev cert via
Deploy.ps1 - β Mid-file cancellation (async streaming)
- β Safe temp file/dir pattern β no partial files on cancel
- β Compression-ratio bomb detection (1000:1 threshold), confirm-and-extract if the destination has room, for ZIP and every tar-family format
- β UTF-8 filenames β Cyrillic and emoji round-trip verified
- β
Native right-click context menu β Open, Extract here, Extract to folder, Add to
X.zip/X.tar, Compressβ¦, Test archive, Scan for threats, Hash (CRC-32, SHA-256) - β Scan for threats β archive contents checked by the installed antivirus through AMSI
- β Extracted files and folders keep the dates stored in the archive
- β
Recovery data (PAR2) β created next to an archive from the app or
pakko a -rr, verified bypakko t, Explorer and the app, repaired into a new file bypakko r, Explorer and the app - β
pakkocommand line β in any terminal after a Store install, or as a standalone zip - β
File type association (every readable format). No URI protocol is registered (the former
pakko://scheme was removed), so a web page cannot launch Pakko through a link of its own - β MOTW propagation on extracted files by default, always for Archive Browser previews; the user may leave it off for one trusted archive, unless Group Policy decides
- β Alternate Data Stream / reserved-filename / reparse-point protections during extraction
- β Archive Browser β navigate, extract selected/all, preview an image or text file without a manual extract, climb past the archive root into the real filesystem
- β RAR/7z/tar-family extraction runs inside an AppContainer sandbox β quarantine staging, ACL'd output directory, Job Object process limits, no network capability
- β
Group Policy / ADMX support β see
docs/POLICIES.md - β Full automated test suite, run on every push in CI (see the Build Status badge above)
Now available on the Microsoft Store: https://apps.microsoft.com/detail/9p5mw010d8pr
(also installable via winget install 9P5MW010D8PR --source msstore). GitHub Releases remain
available as an alternative for every version tag.
See docs/SPEC.md's "Future Roadmap" section for the version-to-focus table, and docs/TASKS.md
for the detailed task list.
- Context menu flickers on the first right-click in a newly opened Explorer window β this is a known Windows Explorer verb/icon-cache artifact (Explorer caches top-level shell-extension verbs across COM DLL registrations until it requeries them), not a Pakko bug.
Prerequisites: Visual Studio 2026 (.NET desktop + Desktop C++ workloads, MSVC v143 x64/ARM64 build tools), .NET 10 SDK.
See scripts/README.md for the full build/sign/deploy steps and
CONTRIBUTING.md for the contributor workflow. Production code signing with a
trusted certificate is planned (T-F10) β see docs/SIGNING.md for Pakko's Code
Signing Policy (team roles, build process, and artifacts covered).
dotnet test --filter "Category!=Slow&Category!=VeryLarge"Always run without a path argument β all projects must stay green after every change. See
docs/TESTING.md for the full test plan, fixture generation, and the
Category=Slow/Category=VeryLarge tiers.
- Developer / API Docs β generated site: architecture,
conventions, CLI reference, and an API reference built from
Archiver.Core's own XML doc comments - Changelog β per-release history
- Security Policy β threat model, CVE tables, mitigations
- Privacy Policy
- Code Signing Policy
- Group Policy / ADMX Reference
- CLI Command Reference
- Contributing Guide
- Code of Conduct
- License (Apache 2.0)



