4 min read

ebook2audiobook: Turn E-Books Into Audiobooks With Local AI (GitHub, Scanned)

Converts EPUB, PDF, MOBI and other e-books into chaptered audiobooks with local text-to-speech.

ebook2audiobook logo
✅
Scan: safe. Nothing malicious. Two things to know: the web interface binds to 0.0.0.0, so anyone on your network can reach it while it runs, and most Python dependencies are unpinned, so they could not be checked. Scanned Oct 2, 2026; the full report is below.

ebook2audiobook reads an e-book and writes an audiobook. It takes EPUB, MOBI, AZW3, PDF, DOCX, TXT and a long list of other formats, runs OCR on scanned pages, splits the text into chapters, and narrates it with a local text-to-speech engine: XTTSv2 by default, or Bark, VITS, Fairseq, Tacotron2, Tortoise, GlowTTS or YourTTS. The result is an M4B (or MP3, FLAC, M4A and others) with chapter markers and metadata. Fairseq's models extend coverage to more than 1,100 languages, inline tags add pauses and voice switches, and you can clone a narrator from your own voice sample.

Drew Thomasson started it in January 2024 and it has about 20,000 stars, with a Gradio web interface, a headless command line and Docker images for CPU and several CUDA versions. It runs on as little as 2 GB of RAM and 1 GB of VRAM, though the better engines want a real GPU. The code is Apache-2.0, and the README states plainly that it is for DRM-free, legally acquired books only.

Who it is for

Readers who want audio versions of books that have none, language learners, people with visual impairments or dyslexia, and anyone with a backlog of public-domain or self-published books.

Getting started

1. Clone the repository

git clone https://github.com/DrewThomasson/ebook2audiobook.git && cd ebook2audiobook

2. Install and launch the web interface on Linux or macOS (Windows: ebook2audiobook.cmd), then open http://localhost:7860

./ebook2audiobook.command

3. Or convert headless

./ebook2audiobook.command --headless --ebook mybook.epub --language eng

4. Or run the CPU Docker image

docker run -v "./ebooks:/app/ebooks" -v "./audiobooks:/app/audiobooks" --rm -it -p 7860:7860 athomasson2/ebook2audiobook:cpu

The launcher installs missing tools for you: Homebrew on macOS and Scoop on Windows. Models download on first run. On a CPU, XTTSv2 and Bark are very slow; use a GPU or a lighter engine such as YourTTS or Tacotron2. The web interface listens on all network interfaces, so other devices on your network can reach it while it runs, and the --share flag goes further with a public Gradio link.

Safety scan

We cloned DrewThomasson/ebook2audiobook at commit d3ff5bc on Oct 2, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no committed binaries and no bare-IP URLs across 339 files and about 49,000 lines. The three pattern hits are a Dockerfile installing Rust with rustup's curl | sh during an image build, a Windows launcher message telling you how to install Docker, and a long line of language-code mappings in lib/conf_models.py.
  • lib/conf.py sets interface_host to 0.0.0.0, and app.py passes it to Gradio, so the converter is reachable from other devices on your network without a password. The --share flag goes further and publishes a temporary public gradio.live link.
  • components/rocmfix.py is a vendored copy of ROCmFix, an AMD GPU helper. ebook2audiobook only calls its detection code, which downloads a GPU compatibility list from rocmfix-data.onrender.com when it meets an AMD card it does not know; ROCmFix's own opt-in telemetry is never called. The launch scripts install Homebrew on macOS or Scoop on Windows if they are missing.
  • requirements.txt has 52 lines but pins only three packages (Gradio 6.28.0, coqui-tts and piper-tts), none with a known advisory; the other dependencies resolve to whatever is current at install time and could not be checked.
  • Eight workflows, none using pull_request_target; neither of the 2 third-party actions is pinned. Licence and code of conduct present; no security policy, Dependabot, CodeQL or contributing guide.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious code3 pattern hits found and read; every one is listed under the raw findings.
Install-time codeNone: nothing runs at install beyond the package manager itself.
Committed binariesNone.
CI workflows8 workflows. None use pull_request_target. 2 of 2 third-party actions pinned to a tag rather than a commit.
Network hosts18 distinct hosts referenced from source; most often github.com, colab.research.google.com, raw.githubusercontent.com, download.pytorch.org. No URLs to bare IP addresses.
Known vulnerabilities0 advisories across 3 pinned packages: 0 critical, 0 high, 0 moderate, 0 low. requirements.txt: 3 packages, 0 advisories.
Project hygieneHas licence file. Missing security policy, automated dependency updates, CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Pattern hits (3)
WhereRuleMatch
Dockerfile:148download-piped-to-shellcurl https://sh.rustup.rs -sSf | sh -s -- -y --default-toolchain stable; \
ebook2audiobook.cmd:578download-piped-to-shellecho Then manually run: curl -fsSL https://get.docker.com ^| sh
lib/conf_models.py:258very-long-line18109 chars

By the numbers

Stars20.3K
Forks1,730
Contributors43
Commits15.2K
Open issues2
Open pull requests0
Releases42
Latest releasev26.9.27
LicenceApache-2.0
Main languagePython
Project age2 years
Last pushOct 2, 2026
Tracked files339
Lines of code49.2K
Checkout size36 MB

Lines by language: Python 20.9K, Markdown 17.5K, JSON 5,983, YAML 1,571, Batch 1,248, CSS 685.

Questions

Is ebook2audiobook free?

The software is Apache-2.0 and free, with no API costs since everything runs locally. The voice models have their own terms: the default XTTSv2 model is under the Coqui Public Model License, which allows non-commercial use only, so selling audiobooks made with it needs a different engine or licence.

Can ebook2audiobook convert Kindle books?

It reads AZW3, MOBI and other Kindle formats, but only without DRM. Books bought from Kindle and most other stores are DRM-protected, and the project supports only DRM-free, legally acquired files. Public-domain sites such as Project Gutenberg are a good source.

How long does a book take to convert?

It depends on the engine, the book and your hardware. With XTTSv2 a full novel can take hours even on a good NVIDIA GPU and far longer on a CPU, which is why the README suggests lighter engines such as YourTTS or Tacotron2 for CPU use; they are faster but sound more robotic.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.