Skip to main content

pyVBAanalysis

CI Security PyPI Python License: MIT

Static analysis for Office VBA. It reads your macros and reports likely bugs and the errors the VBA compiler would catch, without opening Office or running any code.

Point it at an Excel workbook, a Word document, a PowerPoint deck, an Access database, or a set of exported module files, and it returns the problems it finds, each with the exact line and a plain explanation. Each file is measured against its own host's object model, so Word code is never judged by Excel's surface.

What it checks

It looks for more than a hundred kinds of problem, including:

  • Type errors, such as assigning a string to a Long or passing the wrong type to a procedure.
  • Undeclared variables and calls to procedures or members that do not exist.
  • Code the VBA compiler rejects: duplicate declarations, malformed statements, or a Declare that lacks PtrSafe on 64-bit Office.
  • A type from another Office application's library the project does not reference, such as Dim doc As Word.Document in a workbook with no reference to Word.
  • Likely run-time failures, such as dividing by a constant zero or a type mismatch from a bad conversion.
  • Dead code: variables nothing uses or nothing reads, private procedures nothing calls, and statements no path reaches.

It only reports a problem when it can prove one, and stays quiet otherwise, so the output does not bury you in false alarms.

Install

pip install pyvbaanalysis

Python 3.10 or later. Nothing else to set up.

Use it from Python

Analyze a workbook:

from pyvbaanalysis import analyze_office_file

for module, problems in analyze_office_file("Budget.xlsm").items():
    for p in problems:
        print(module, p.severity.value, p.code, p.message)

Analyze a single module's source:

from pyvbaanalysis import analyze_module

source = "Sub Test()\n    Dim n As Long\n    n = \"oops\"\nEnd Sub\n"
for p in analyze_module(source):
    print(p.code, p.message)

Each result has a code, a message, a severity (error, warning, or information), and a span giving the character offsets in the source.

Analyze several exported files together, so references between them resolve:

from pyvbaanalysis import analyze_loose_files

analyze_loose_files(["Module1.bas", "Sheet1.cls", "UserForm1.frm"])

Use it from the command line

pyvbaanalysis Budget.xlsm
pyvbaanalysis ./exported_modules --format json
pyvbaanalysis Budget.xlsm --only Sheet1

A path can be a workbook, a folder of exported .bas / .cls / .frm files, or a single file. The command exits 1 when it finds problems and 0 when the code is clean, so it drops into a CI check.

Scope

This analyzes the VBA inside Office files. It does not run macros and does not need Office installed.

Each file is measured against its own host's object model, so a Word document is never judged by Excel's surface. Readable containers: Excel (.xlsm, .xlsb, .xlam, .xls), Word (.docm, .dotm, .doc), PowerPoint (.pptm, .potm) and Access (.accdb, .mdb, read-only). Legacy .ppt is not readable yet, because its VBA project sits in a compressed record the reader does not open.

Documentation

Built with this

xlide-mcp is an MCP server built on this. The diagnostics here are its build gate: an agent that changes a macro runs them afterwards and treats an error as a failure rather than a suggestion, which is most of what stops a model shipping VBA that does not compile.

Security

Report a vulnerability privately through GitHub's advisory form, not a public issue. CodeQL, Semgrep and pip-audit run on every push and gate every release, and each release carries its security report. See SECURITY.md.

License

MIT. See LICENSE.

Metadata

Release files for pyvbaanalysis 2.3.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pyvbaanalysis 2.3.1
File Size Uploaded
pyvbaanalysis-2.3.1.tar.gz 2.3 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for pyvbaanalysis 2.3.1
File Interpreter ABI Platform
pyvbaanalysis-2.3.1-py3-none-any.whl Python 3 none any Details

Total release size: 4.5 MB

Release files / pyvbaanalysis-2.3.1.tar.gz

Download URL pyvbaanalysis-2.3.1.tar.gz
Size 2.3 MB
Tags Source
SHA-256 checksum
How to use checksums
cbb91d8a22a997ec207cf047dbe6048a29a169a7af7e4bebb3cf19802187664e
BLAKE2b-256 checksum
How to use checksums
fbd7d5fd4f01642e79480eed234ffcf2bb1e2963d8d75ba3a84a47de5c808433
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release files / pyvbaanalysis-2.3.1-py3-none-any.whl

Download URL pyvbaanalysis-2.3.1-py3-none-any.whl
Size 2.2 MB
Tags Python 3
SHA-256 checksum
How to use checksums
05a93bff42762a6bf6d16975195924590f6ad812cf5f69869df7cf3e0f076365
BLAKE2b-256 checksum
How to use checksums
fe942e665598120fde1f41111a1428bf02bedf76f238300328b5861a97154703
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release history Release notifications | RSS feed

3.0.0

2 release files

This release

2.3.1 This release

2 release files

2.3.0

2 release files

2.2.1

2 release files

2.2.0

2 release files

2.1.1

2 release files

2.1.0

2 release files

2.0.0

2 release files

1.4.2

2 release files

1.4.1

2 release files

1.4.0

2 release files

1.3.2

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.0

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page