Zippy
Version:
Multi-purpose archive toolkit for creation, extraction, inspection, recovery, and repair
-> Supports a wide range of archive formats with a consistent interface.
-> Authorized password recovery for encrypted ZIP archives.
-> Includes a powerful repair toolkit for damaged archives.
Supported archives
| Format | Algorithm | Deep notes & typical use |
|---|---|---|
| ZIP (.zip) | DEFLATE (store/deflate/deflate64; variants) | Per-file container with random access and per-file metadata. Widely supported across platforms. Optional password protection (ZipCrypto/AES) depends on tool. Good for cross‑platform distribution and per-file extraction. |
| TAR (.tar) | none (archive only) | Archive container preserving Unix metadata, permissions, and order. Not compressed—commonly paired with compressors (gzip/xz/bzip2) for multi-file archives and backups. |
| TAR.GZ / TGZ (.tar.gz, .tgz) | gzip (DEFLATE) | Stream compressor wrapping tar (single compressed stream). Fast decompression, ubiquitous, not random-access—ideal for streaming and distribution. |
| TAR.BZ2 / TBZ (.tar.bz2, .tbz) | bzip2 | Block compressor with higher ratios for some data at the cost of CPU; slower than gzip, not random-access. Good for distribution when size matters. |
| TAR.XZ / TLZ (.tar.xz, .tlz) | xz / LZMA2 | High compression ratio, memory- and CPU-intensive; slower but yields smaller archives. Best for distribution/releases where size is critical. |
| GZIP (.gz) | gzip (DEFLATE) | Single-file stream compressor. Combine with tar for multi-file archives. Fast and widely supported. |
| BZ2 (.bz2) | bzip2 | Single-file block compressor—better ratios in some cases, slower CPU. Use for single-file compression tasks. |
| XZ (.xz) | xz / LZMA2 | Single-file high-compression format with streaming support; resource-heavy but efficient for size-sensitive workloads. |
| LZMA (.lzma) | LZMA | Older single-file LZMA format similar to xz characteristics; less common but supported for specific compatibility needs. |
About
Zippy is a command-line toolkit for working with various archive formats. It provides a consistent interface for creating, extracting, and repairing archives, as well as tools for password cracking on encrypted ZIP files. It works across multiple platforms and is designed for both casual users and professionals needing reliable archive management. The repair tools can help salvage data from corrupted archives, making it a versatile addition to any toolkit. Zippy can also be used in offensive security contexts for penetration testing and forensic analysis. features include:
- Multi-format support - handles ZIP (including AES-encrypted), TAR (and compressed variants), and single-file compressors (gzip, bzip2, xz, lzma).
- Password cracking - built-in dictionary attack capabilities for encrypted ZIP files using a curated password list.
- Archive repair - tools to attempt recovery of corrupted archives, including salvage extraction and best-effort repairs.
- Cross-platform - works on Windows, macOS, and Linux with consistent command-line interface.
- User-friendly features - progress indicators, colorized logging, and tab completion for ease of use.
- Automation friendly - supports configuration saving/loading for repeatable tasks and CI environments.
- Extensibility - designed with a modular architecture, allowing for easy integration of new features and support for additional archive formats.
- Performance - optimized for speed and efficiency, making it suitable for both small-scale and large-scale archive operations.
- Security-conscious extraction - rejects archive traversal paths and ZIP symbolic links; configuration files never store passwords.
Installation
From PyPI (recommended)
python -m pip install zippy-py
From source
git clone https://github.com/John0n1/ZIPPY.git
cd ZIPPY
python -m pip install .
Debian package
sudo apt install ./zippy_*.deb
Quick start
Extract an archive
zippy --extract backups/site.tar.xz -o ./site
Create a password-protected ZIP from multiple paths
zippy --lock secure.zip -f docs,images -p "Tru5ted!"
List TAR.BZ2 contents
zippy --list datasets.tar.bz2
Attempt unlocking with the bundled wordlist
zippy --unlock encrypted.zip -d password_list.txt --verbose
Run salvage repair on a damaged tarball
zippy --repair broken.tar.gz --repair-mode remove_corrupted
Run zippy --help for the full command reference or zippy --version to confirm the installed release.
Configuration & automation
- Use
--save-config <file>to capture the current non-secret flag set. Passwords are deliberately omitted. - Rehydrate saved flags via
zippy --load-config <file>; command-line values override loaded defaults. - Disable animations with
--no-animationfor CI environments.
Logging & colours
Logging defaults to concise INFO output. Add --verbose for DEBUG traces. Colour output automatically downgrades in non-interactive terminals, while animations fall back to plain log messages when disabled or redirected. Windows terminals are supported through colorama.
Password dictionary
The installed package includes a small starter dictionary for authorized recovery and demonstrations. The unlock command ignores comments (# ...) and safely handles mixed encodings. Supply your own list with --dictionary <file> for larger, authorized recovery jobs.
Safety and limitations
- Treat archives as untrusted input. Zippy blocks known path-traversal and symbolic-link extraction hazards for native ZIP/TAR handling; formats delegated to external tools inherit those tools' security properties.
- Archive creation and ZIP repair use atomic replacement so an existing destination is retained if writing fails.
- Password recovery is intentionally dictionary-based and ZIP-only. Use it only on archives you own or are authorized to assess.
- Repair is best-effort salvage, not guaranteed reconstruction. Always keep the original and work from backups.
- Single-file compressors (
.gz,.bz2,.xz,.lzma) contain one byte stream, not a directory tree.
See CHANGELOG.md for release details.
Contributing
Pull requests are welcome—please open an issue describing the enhancement before submitting substantial changes.
License
Zippy is released under the MIT License. See LICENSE for the full text.
Disclaimer
Zippy is provided "as is" without warranty of any kind. Use at your own risk and keep backups of critical data.
The author is not responsible for any data loss or damage resulting from the use of this software.
Metadata
Release files for zippy-py 2.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| zippy_py-2.1.0.tar.gz | 37.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| zippy_py-2.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 64.3 kB
Release files / zippy_py-2.1.0.tar.gz
| Download URL | zippy_py-2.1.0.tar.gz |
|---|---|
| Size | 37.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
efcd8c2e1b9c8f6ec7ed88e9ce4480ca518001f4fd737feceb5a253aa5770ce6
|
|
BLAKE2b-256 checksum How to use checksums |
cb3db5ac1aa7abb23e381d8f5b752156dd280620f73ed6001e6581a9125f9f4b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 18, 2026.
Transparency logRelease files / zippy_py-2.1.0-py3-none-any.whl
| Download URL | zippy_py-2.1.0-py3-none-any.whl |
|---|---|
| Size | 26.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
3d394062acdc6de3cf24b34f978875dbf5477bb9acff96d2915eb6ba118b9c1e
|
|
BLAKE2b-256 checksum How to use checksums |
ac678b89a4a7747259803d5fbac98d50e83e470704adc28cbf40a3f48bca83ad
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 18, 2026.
Transparency log