4 min read

ConvertX: Self-Hosted File Converter for 1,000+ Formats (GitHub, Scanned)

A self-hosted web app that converts images, video, documents and e-books between 1,000+ formats.

ConvertX logo
✅
Scan: safe. Nothing malicious. One thing to know: it feeds uploaded files to two dozen complex converters, and the container runs as root unless you set PUID, so only let people you trust upload. Scanned Sep 30, 2026; the full report is below.

ConvertX is an online file converter you run yourself. Open it in a browser, drop in files, pick an output format and download the results; it handles batches, keeps a history and supports several user accounts. Behind the simple page it wraps more than twenty established tools: FFmpeg for video and audio, ImageMagick, GraphicsMagick and libvips for images, LibreOffice and Pandoc for documents, Calibre for e-books, Inkscape for vector graphics and Assimp for 3D models, plus converters for HEIF, JPEG XL, LaTeX, Outlook messages and raster-to-vector tracing.

The point is privacy without losing convenience. Free conversion websites work by uploading your file to someone else's server; ConvertX does the same job on your own hardware and, by default, deletes files older than a day. It ships as one Docker image, so the whole toolchain installs with a single command, and FFmpeg can be given hardware-acceleration flags.

ConvertX is written in TypeScript on Bun and Elysia by the developer C4illin, is AGPL-3.0 licensed, and has about 19,000 stars. Version 0.19 came out in September 2026.

  • Repository: github.com/C4illin/ConvertX
  • Licence: AGPL-3.0 (GNU Affero General Public License v3.0)
  • Language: TypeScript. Stars: 19.1K. Forks: 1,085. Last push: Oct 2, 2026.
  • Scan: safe, Sep 30, 2026, commit 49d1db8

Who it is for

Self-hosters and home-lab users who want one converter for every file type, and anyone who regularly converts documents or media that should not be uploaded to a free conversion website.

Getting started

1. Run it with Docker, then open http://localhost:3000 and create your account

docker run -p 3000:3000 -e PUID=1000 -e PGID=1000 -v ./data:/app/data ghcr.io/c4illin/convertx

2. Better: also set a fixed secret for signing logins

docker run -p 3000:3000 -e PUID=1000 -e PGID=1000 -e JWT_SECRET=a-long-random-string -v ./data:/app/data ghcr.io/c4illin/convertx

Create your account straight away: the first person to open a fresh instance can register it. Logins only work over localhost or HTTPS unless you set HTTP_ALLOWED=true, and the README warns never to expose an instance to the internet with ACCOUNT_REGISTRATION or ALLOW_UNAUTHENTICATED turned on. Match PUID and PGID to your own user (id -u and id -g) to avoid permission errors on the data folder.

Safety scan

We cloned C4illin/ConvertX at commit 49d1db8 on Sep 30, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no suspicious patterns, no bare-IP URLs, no install hooks and no committed binaries across 131 files and about 10,000 lines of TypeScript. The only hosts in the code are github.com and stackoverflow.com links.
  • We read how converters are called: src/converters uses execFile with argument arrays, not a shell, so a crafted filename cannot inject commands. The converters themselves (FFmpeg, ImageMagick, LibreOffice, Calibre, Inkscape and others) are large native programs with their own history of file-parsing bugs, which is why upload access matters.
  • The project's dependencies are pinned in bun.lock, a format the scan does not read, so no advisory count is available; the converters come from the Docker image's operating-system packages and update when you pull a new image.
  • Defaults to know from the README: PUID defaults to 0, so the app runs as root inside the container unless you set it; anyone who reaches a fresh instance can register the first account; and JWT_SECRET is random per start unless you set one, which logs everyone out on restart. Files older than 24 hours are deleted by default.
  • Seven workflows. The pull_request_target one, conventional-label.yml, labels PRs from their titles without checking out code. Only one of 15 third-party actions is pinned to a commit. Security policy, Renovate and licence present; no Dependabot or CodeQL.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time codeNone: nothing runs at install beyond the package manager itself.
Committed binariesNone.
CI workflows7 workflows. 1 uses pull_request_target, none check out the pull request head. 14 of 15 third-party actions pinned to a tag rather than a commit.
Network hosts2 distinct hosts referenced from source; most often github.com, stackoverflow.com. No URLs to bare IP addresses.
Known vulnerabilitiesNo lockfile to check: dependencies are declared as ranges, so what gets installed is whatever is current on the day.
Project hygieneHas security policy, automated dependency updates, licence file. Missing CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Workflows worth a look

By the numbers

Stars19.1K
Forks1,085
Contributors46
Commits894
Open issues91
Open pull requests27
Releases32
Latest releasev0.19.0
LicenceAGPL-3.0
Main languageTypeScript
Project age2 years
Last pushOct 2, 2026
Tracked files131
Lines of code10.3K
Checkout size564 KB

Lines by language: TypeScript 8,649, Markdown 500, YAML 415, JavaScript 310, JSON 270, CSS 81.

Questions

Is ConvertX free?

Yes. ConvertX is AGPL-3.0 licensed with no paid tier or limits; the cost is the machine you run it on. Large video conversions are CPU-heavy, so a small home server will be slow with them.

Are my files kept on the server?

Only for a while. By default ConvertX checks every 24 hours and deletes files older than that, and AUTO_DELETE_EVERY_N_HOURS changes the interval or turns it off. Files are not sent to any outside service; every converter runs inside the container.

Which formats does ConvertX support?

More than 1,000 across its converters. FFmpeg alone reads around 470 formats and ImageMagick around 245, and the others cover documents, e-books, data files such as JSON and YAML, 3D assets and vector graphics. The README lists every converter with its input and output counts.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.