5 min read

Paperless-ngx: Scan, OCR and Search Your Paperwork (GitHub, Scanned)

A self-hosted document archive that OCRs, tags and indexes every scan so you can find any paper again.

Paperless-ngx logo
✅
Scan: safe. Nothing malicious, and the hygiene is unusually good. One thing to know, which the project states itself: documents are stored unencrypted, so it belongs on hardware you control. Scanned Oct 3, 2026; the full report is below.

Paperless-ngx turns a pile of paper into a searchable archive. Scan a letter, receipt or contract (or drop in a PDF or email it in), and it runs OCR so the text becomes searchable, stores an archival PDF, and assigns a correspondent, document type and tags, learning from how you have filed similar documents before. A web interface lets you search full text, filter by date or tag, and set up saved views and workflows so new documents file themselves.

It is on this list because it is the standard answer to going paperless at home, and its auto-matching does the boring part for you. It is a mature project: the official successor to Paperless and Paperless-ng, run by a team of maintainers rather than one person, translated into many languages through Crowdin, with a large ecosystem of companion apps and scripts listed on its wiki.

Paperless-ngx has about 46,000 stars and is licensed GPL-3.0. The latest release, 3.2.1, came out in September 2026, and a public demo runs at demo.paperless-ngx.com.

Who it is for

Households and small offices with filing cabinets they would like to empty, homelab owners who want their tax records and invoices on their own hardware, and anyone tired of hunting for a warranty receipt.

Getting started

1. Run the install script, which asks a few questions and writes a Docker Compose setup

bash -c "$(curl -L https://raw.githubusercontent.com/paperless-ngx/paperless-ngx/main/install-paperless-ngx.sh)"

2. Or take a ready-made Compose file from docker/compose in the repository, then start it

docker compose up -d

3. Open the web interface and log in with the admin account you created

open http://localhost:8000

The install script is fetched from GitHub and run directly; read it first if you prefer. The project warns that documents are stored unencrypted and that Paperless-ngx should never run on an untrusted host: the safest setup is a server in your own home, with backups.

Safety scan

We cloned paperless-ngx/paperless-ngx at commit 6ce43be on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets and no pattern hits across 1,557 files and about 259,000 lines (141,000 Python, 72,000 TypeScript). The one bare-IP URL is a test in src/paperless/tests/test_network.py asserting a rewritten URL, using 93.184.216.34, the address long associated with example.com.
  • install-paperless-ngx.sh (408 lines) asks a few questions, downloads a Compose file and .env from the project's main branch on raw.githubusercontent.com and writes the configuration. The scanner's sudo flag comes from a printed hint suggesting you add yourself to the docker group; the script never calls sudo itself. It fetches from main rather than a release tag, so read it first if that matters to you.
  • 13 known advisories, none critical (8 high). Ten are in JavaScript build tooling: the Angular frontend's pnpm-lock.yaml (4) and the Tailwind build for email templates (6), neither of which ships as running code. The runtime Python ones are nltk 3.10.3 (one high, file access outside allowed roots in model-artifact APIs) and oauthlib 3.3.1 (two moderate, in OAuth provider endpoints).
  • 15 workflows. Two use pull_request_target (pr-bot and project-actions); they label and comment, and neither checks out pull request code. 43 of 47 third-party actions are pinned to commits.
  • Security policy, Dependabot, CodeQL, licence, contributing guide and code of conduct are all present, the full set. The maintainers state that documents are stored in clear text and that it should never run on an untrusted host.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time code1 npm lifecycle script. 3 installer scripts (one can call sudo)
Committed binariesNone.
CI workflows15 workflows. 2 use pull_request_target, none check out the pull request head. 4 of 47 third-party actions pinned to a tag rather than a commit.
Network hosts40 distinct hosts referenced from source; most often github.com, paperless-ngx.com, docs.paperless-ngx.com, docs.celeryq.dev. 1 URL to a bare IP address, listed under the raw findings.
Known vulnerabilities13 advisories across 1,157 pinned packages: 0 critical, 8 high, 5 moderate, 0 low. src-ui/pnpm-lock.yaml: 829 packages, 4 advisories; src/paperless_mail/templates/package-lock.json: 73 packages, 6 advisories; uv.lock: 274 packages, 3 advisories.
Project hygieneHas security policy, automated dependency updates, CodeQL, licence file, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

URLs to bare IP addresses (1)
WhereRuleMatch
src/paperless/tests/test_network.py:32ip-literal-urlassert str(rewritten_request.url) == "https://93.184.216.34:8443/test"
npm lifecycle scripts (1)
  • src-ui/package.json preinstall: npx only-allow pnpm
Installer scripts (3)
Worst known vulnerabilities (13 of 13)
AdvisorySeverityPackageSummary
GHSA-6j4f-fj2g-mc7phighbrace-expansion@2.1.4brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-qhr7-859c-m2p7highbrace-expansion@2.1.4brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-2883-xcg3-v3hhhighjs-yaml@3.15.1js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
GHSA-vfj7-8cjw-p6xmhighbraces@3.0.3braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
GHSA-2v37-7h3g-55p8highnanoid@3.3.16nanoid: custom generators can loop indefinitely when size is zero
GHSA-c2c7-rcm5-vvqjhighpicomatch@2.3.1Picomatch has a ReDoS vulnerability via extglob quantifiers
GHSA-c2c7-rcm5-vvqjhighpicomatch@4.0.3Picomatch has a ReDoS vulnerability via extglob quantifiers
GHSA-8mgp-746c-j5xphighnltk@3.10.3NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
GHSA-q2hr-2g5m-vwhrmoderatebrace-expansion@2.1.4brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
GHSA-3v7f-55p6-f55pmoderatepicomatch@2.3.1Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
GHSA-3v7f-55p6-f55pmoderatepicomatch@4.0.3Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
GHSA-hj66-6f7g-4r5vmoderateoauthlib@3.3.1Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
GHSA-xpv3-w29h-x7cvmoderateoauthlib@3.3.1Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)
Workflows worth a look

By the numbers

Stars46.2K
Forks3,205
Contributors461
Commits12.2K
Open issues0
Open pull requests9
Releases162
Latest releasev3.2.1
LicenceGPL-3.0
Main languagePython
Project age4 years
Last pushOct 3, 2026
Tracked files1,557
Lines of code258.9K
Checkout size93 MB

Lines by language: Python 141.4K, TypeScript 72K, Markdown 18.6K, HTML 10.2K, JSON 7,162, SCSS 3,961.

Questions

Is Paperless-ngx free?

Yes. Paperless-ngx is GPL-3.0, community-run and free, with no paid tier or hosted plan from the project. Your only costs are the machine it runs on and, if you want one, a document scanner.

Is it safe to keep sensitive documents in Paperless-ngx?

Only on hardware you control. The maintainers state plainly that documents are stored in clear text without encryption and that it should never be run on an untrusted host. Run it on a home server, keep it off the open internet or behind a VPN, and back it up.

Can I try Paperless-ngx without installing it?

Yes. A demo runs at demo.paperless-ngx.com with the login demo and the password demo. Its content resets often, and you should not upload anything confidential to it.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.