MoneyPrinterTurbo automates the whole faceless short-video pipeline. Give it a subject such as "how AI is changing everyday life" and it has a language model write the script and pick search terms, pulls matching clips from Pexels, Pixabay or your own folder (or generates clips with paid text-to-video APIs), reads the script aloud, burns in styled subtitles, adds background music and renders a 9:16, 16:9 or 1:1 MP4. It runs as a Streamlit web interface, a REST API, a command-line tool, or a skill an AI coding agent can drive, and it can batch-generate and even post the results straight to TikTok, Instagram and YouTube Shorts.
It has about 128,000 stars, is made by developer harry0703 and is released under MIT. Its videos and setup guides circulate widely on TikTok and X, mostly pitched at people building faceless channels. Free paths exist for most steps (Edge TTS needs no key, Pexels and Pixabay keys are free, and Ollama can write the script), but the README is dominated by sponsor blocks with referral links for Chinese model API resellers, so read past them to the install section.
- Repository: github.com/harry0703/MoneyPrinterTurbo
- Licence: MIT (MIT License)
- Language: Python. Stars: 128.1K. Forks: 20K. Last push: Oct 3, 2026.
- Scan: safe, Oct 3, 2026, commit fafec0f
Who it is for
Creators experimenting with faceless short-form channels, marketers who need quick explainer clips, and developers who want a scriptable video pipeline behind an API.
Getting started
1. Clone the repository (Windows users can instead download the one-click .7z package from Releases)
git clone https://github.com/harry0703/MoneyPrinterTurbo.git && cd MoneyPrinterTurbo2. Install Python 3.11 and the locked dependencies with uv
uv python install 3.11 && uv sync --frozen3. Start the web interface (Windows: .\webui.bat), then add your API keys in Basic Settings
sh webui.sh4. Or run it in Docker and open http://127.0.0.1:8501
cp config.example.toml config.toml && docker compose -f docker-compose.release.yml upYou need at least an LLM (a cloud key or a local Ollama model) and a free Pexels or Pixabay key for footage. AI video clips, premium voices and some script providers are paid APIs. The bundled background music is taken from YouTube videos, and the README itself warns it may carry copyright claims; swap in your own before publishing. The API server listens on all interfaces with no key by default; set listen_host to 127.0.0.1 or an API key in config.toml if your network is shared.
Safety scan
We cloned harry0703/MoneyPrinterTurbo at commit fafec0f on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no pattern hits, no committed binaries and no install hooks across 305 files and about 88,000 lines of Python. The many hosts in the code are the LLM, TTS, stock-footage and video APIs it supports, plus placeholder example domains in tests.
- config.example.toml sets listen_host to 0.0.0.0, and app/controllers/base.py lets every request through when no API key is configured. Anyone on your network can then start jobs that spend your API credits. Set listen_host to 127.0.0.1 or set an x-api-key before running the API on a shared network.
- Auto-posting to TikTok, Instagram and YouTube goes through upload-post.com, a third-party service you sign up for and give your social accounts to. The 29 bundled background tracks in resource/songs come from YouTube videos, and the README warns they may carry copyright claims.
- uv.lock pins 124 packages with 70 known advisories (2 critical, 39 high). Most come with Streamlit: GitPython 3.1.50 alone carries a dozen command-injection and config-injection advisories, though MoneyPrinterTurbo never points it at an untrusted repository. The rest are anyio, aiohttp, cryptography and python-multipart in the web stack, which matters more if you expose the API.
- Two workflows, none using pull_request_target; none of the 7 third-party actions is pinned to a commit. Security policy and licence present; no Dependabot, CodeQL or contributing guide.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | None: nothing runs at install beyond the package manager itself. |
| Committed binaries | None. |
| CI workflows | 2 workflows. None use pull_request_target. 7 of 7 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 40 distinct hosts referenced from source; most often cdn.example.com, example.test, v.example, github.com. No URLs to bare IP addresses. |
| Known vulnerabilities | 70 advisories across 125 pinned packages: 2 critical, 39 high, 22 moderate, 7 low. requirements.txt: 21 packages, 5 advisories; uv.lock: 124 packages, 70 advisories. |
| Project hygiene | Has security policy, licence file. Missing automated dependency updates, CodeQL, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Worst known vulnerabilities (24 of 70)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-82r6-8w77-94w6 | critical | anyio@4.13.0 | AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing |
| GHSA-284h-m62q-gf8w | critical | gitpython@3.1.50 | GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any… |
| GHSA-5rvq-cxj2-64vf | high | python-multipart@0.0.27 | python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service |
| GHSA-cq5v-8q36-5273 | high | aiohttp@3.14.0 | AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response) |
| GHSA-47fr-3ffg-hgmw | high | click@8.1.8 | |
| GHSA-g6cj-pr64-35w5 | high | cryptography@49.0.0 | cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing |
| GHSA-239g-whfq-7xj9 | high | gitpython@3.1.50 | GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution |
| GHSA-2f96-g7mh-g2hx | high | gitpython@3.1.50 | GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist |
| GHSA-3f7w-8rr8-f37f | high | gitpython@3.1.50 | GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file over… |
| GHSA-3rp5-jjmw-4wv2 | high | gitpython@3.1.50 | GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE) |
| GHSA-4gmw-gg2m-w46p | high | gitpython@3.1.50 | GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file over… |
| GHSA-6p8h-3wgx-97gf | high | gitpython@3.1.50 | GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone … |
| GHSA-7833-fr7j-v32q | high | gitpython@3.1.50 | GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigPars… |
| GHSA-8mcc-hrx5-hvxc | high | gitpython@3.1.50 | GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory … |
| GHSA-94p4-4cq8-9g67 | high | gitpython@3.1.50 | GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pg… |
| GHSA-956x-8gvw-wg5v | high | gitpython@3.1.50 | GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwr… |
| GHSA-9rj7-rf2p-w77r | high | gitpython@3.1.50 | GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks |
| GHSA-fjr4-x663-mwxc | high | gitpython@3.1.50 | GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled… |
| GHSA-g5vv-9gxw-82hx | high | gitpython@3.1.50 | GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex - commit author/committer f… |
| GHSA-hmq2-w58f-27jc | high | gitpython@3.1.50 | GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitP… |
| GHSA-jm78-9fvv-mhgr | high | gitpython@3.1.50 | GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/… |
| GHSA-r9mr-m37c-5fr3 | high | gitpython@3.1.50 | GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command exe… |
| GHSA-rwj8-pgh3-r573 | high | gitpython@3.1.50 | GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL |
| GHSA-v396-v7q4-x2qj | high | gitpython@3.1.50 | GitPython unsafe clone option gate bypass through joined short options |
By the numbers
| Stars | 128.1K |
|---|---|
| Forks | 20K |
| Contributors | 134 |
| Commits | 1,070 |
| Open issues | 14 |
| Open pull requests | 38 |
| Releases | 21 |
| Latest release | v1.3.8 |
| Licence | MIT |
| Main language | Python |
| Project age | 2 years |
| Last push | Oct 3, 2026 |
| Tracked files | 305 |
| Lines of code | 88.2K |
| Checkout size | 213 MB |
Lines by language: Python 76.1K, JSON 7,846, Markdown 2,105, TOML 810, CSS 487, YAML 444.
Questions
Is MoneyPrinterTurbo free?
The software is MIT-licensed and free. A video can be made at no cost with Edge TTS for the voice, free Pexels or Pixabay keys for footage and a local Ollama model for the script. Cloud LLMs, AI-generated clips (MiniMax, Seedance and others), ElevenLabs voices and similar services bill you per use through their own accounts.
Does MoneyPrinterTurbo actually make money?
No. The name is a joke on faceless-channel culture; it makes videos, not income. Platforms increasingly limit reach and monetisation for mass-produced, low-originality content, so whether the output earns anything depends on the script, editing and niche you bring to it.
Can I use my own footage and script?
Yes. Every stage can be overridden: paste a script instead of generating one, upload local images and videos instead of stock clips, upload your own voiceover or turn narration off, and use local music. Subtitle font, colour, position and outline are all adjustable.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
