ConvertX is an online file converter you run yourself. Open it in a browser, drop in files, pick an output format and download the results; it handles batches, keeps a history and supports several user accounts. Behind the simple page it wraps more than twenty established tools: FFmpeg for video and audio, ImageMagick, GraphicsMagick and libvips for images, LibreOffice and Pandoc for documents, Calibre for e-books, Inkscape for vector graphics and Assimp for 3D models, plus converters for HEIF, JPEG XL, LaTeX, Outlook messages and raster-to-vector tracing.
The point is privacy without losing convenience. Free conversion websites work by uploading your file to someone else's server; ConvertX does the same job on your own hardware and, by default, deletes files older than a day. It ships as one Docker image, so the whole toolchain installs with a single command, and FFmpeg can be given hardware-acceleration flags.
ConvertX is written in TypeScript on Bun and Elysia by the developer C4illin, is AGPL-3.0 licensed, and has about 19,000 stars. Version 0.19 came out in September 2026.
- Repository: github.com/C4illin/ConvertX
- Licence: AGPL-3.0 (GNU Affero General Public License v3.0)
- Language: TypeScript. Stars: 19.1K. Forks: 1,085. Last push: Oct 2, 2026.
- Scan: safe, Sep 30, 2026, commit 49d1db8
Who it is for
Self-hosters and home-lab users who want one converter for every file type, and anyone who regularly converts documents or media that should not be uploaded to a free conversion website.
Getting started
1. Run it with Docker, then open http://localhost:3000 and create your account
docker run -p 3000:3000 -e PUID=1000 -e PGID=1000 -v ./data:/app/data ghcr.io/c4illin/convertx2. Better: also set a fixed secret for signing logins
docker run -p 3000:3000 -e PUID=1000 -e PGID=1000 -e JWT_SECRET=a-long-random-string -v ./data:/app/data ghcr.io/c4illin/convertxCreate your account straight away: the first person to open a fresh instance can register it. Logins only work over localhost or HTTPS unless you set HTTP_ALLOWED=true, and the README warns never to expose an instance to the internet with ACCOUNT_REGISTRATION or ALLOW_UNAUTHENTICATED turned on. Match PUID and PGID to your own user (id -u and id -g) to avoid permission errors on the data folder.
Safety scan
We cloned C4illin/ConvertX at commit 49d1db8 on Sep 30, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no suspicious patterns, no bare-IP URLs, no install hooks and no committed binaries across 131 files and about 10,000 lines of TypeScript. The only hosts in the code are github.com and stackoverflow.com links.
- We read how converters are called: src/converters uses execFile with argument arrays, not a shell, so a crafted filename cannot inject commands. The converters themselves (FFmpeg, ImageMagick, LibreOffice, Calibre, Inkscape and others) are large native programs with their own history of file-parsing bugs, which is why upload access matters.
- The project's dependencies are pinned in bun.lock, a format the scan does not read, so no advisory count is available; the converters come from the Docker image's operating-system packages and update when you pull a new image.
- Defaults to know from the README: PUID defaults to 0, so the app runs as root inside the container unless you set it; anyone who reaches a fresh instance can register the first account; and JWT_SECRET is random per start unless you set one, which logs everyone out on restart. Files older than 24 hours are deleted by default.
- Seven workflows. The pull_request_target one, conventional-label.yml, labels PRs from their titles without checking out code. Only one of 15 third-party actions is pinned to a commit. Security policy, Renovate and licence present; no Dependabot or CodeQL.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | None: nothing runs at install beyond the package manager itself. |
| Committed binaries | None. |
| CI workflows | 7 workflows. 1 uses pull_request_target, none check out the pull request head. 14 of 15 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 2 distinct hosts referenced from source; most often github.com, stackoverflow.com. No URLs to bare IP addresses. |
| Known vulnerabilities | No lockfile to check: dependencies are declared as ranges, so what gets installed is whatever is current on the day. |
| Project hygiene | Has security policy, automated dependency updates, licence file. Missing CodeQL, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Workflows worth a look
- .github/workflows/conventional-label.yml: pull_request_target
By the numbers
| Stars | 19.1K |
|---|---|
| Forks | 1,085 |
| Contributors | 46 |
| Commits | 894 |
| Open issues | 91 |
| Open pull requests | 27 |
| Releases | 32 |
| Latest release | v0.19.0 |
| Licence | AGPL-3.0 |
| Main language | TypeScript |
| Project age | 2 years |
| Last push | Oct 2, 2026 |
| Tracked files | 131 |
| Lines of code | 10.3K |
| Checkout size | 564 KB |
Lines by language: TypeScript 8,649, Markdown 500, YAML 415, JavaScript 310, JSON 270, CSS 81.
Questions
Is ConvertX free?
Yes. ConvertX is AGPL-3.0 licensed with no paid tier or limits; the cost is the machine you run it on. Large video conversions are CPU-heavy, so a small home server will be slow with them.
Are my files kept on the server?
Only for a while. By default ConvertX checks every 24 hours and deletes files older than that, and AUTO_DELETE_EVERY_N_HOURS changes the interval or turns it off. Files are not sent to any outside service; every converter runs inside the container.
Which formats does ConvertX support?
More than 1,000 across its converters. FFmpeg alone reads around 470 formats and ImageMagick around 245, and the others cover documents, e-books, data files such as JSON and YAML, 3D assets and vector graphics. The README lists every converter with its input and output counts.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
