Wan2GP, which calls itself WanGP, is a browser-based studio for running the major open generative models on your own graphics card. For video it covers Wan 2.1 and 2.2 and their derivatives, LTX-2, Hunyuan Video, LongCat, Kandinsky and others; for images Qwen Image, Z-Image, Flux and HiDream among more; and for audio a set of speech, voice and music models including Qwen3 TTS, Chatterbox and ACE-Step. Around them sit a generation queue, galleries, reusable settings, a mask editor, pose and depth extractors, upscaling and frame interpolation, plus a headless mode and an API.
The point is memory. Its author, who goes by DeepBeepMeep, focuses on offloading and quantization so that models built for data-center GPUs fit on gaming cards: some run in 6 GB of VRAM, NVIDIA cards from the GTX 10 series on are supported, AMD RDNA 2 to 4 works, and it downloads the checkpoint variant that suits your hardware. Updates are frequent; version 13.141 shipped on September 29, 2026.
It has about 9,900 stars and a following on YouTube, where low-VRAM video tutorials often use it. GitHub shows its licence as unrecognised because it uses its own WanGP Community License 2.0: free to use, including at a company, and you may sell what you make with it, but selling WanGP itself, embedding it in a paid product or offering it as a paid hosted service needs a commercial licence. Each model keeps its own licence.
- Repository: github.com/deepbeepmeep/Wan2GP
- Licence: custom (Other)
- Language: Python. Stars: 9,858. Forks: 1,563. Last push: Oct 1, 2026.
- Scan: safe, Oct 1, 2026, commit b8b18f8
Who it is for
Hobbyists and creators with a gaming PC who want to try current open video models without renting cloud GPUs, and ComfyUI users who want a simpler interface for the same models.
Getting started
1. Clone the repository and create an environment (RTX 20 to 50 series)
git clone https://github.com/deepbeepmeep/Wan2GP.git && cd Wan2GP && conda create -n wan2gp python=3.11.14 && conda activate wan2gp2. Install PyTorch for CUDA 13 and the requirements
pip install torch==2.10.0 torchvision==0.25.0 torchaudio==2.10.0 --index-url https://download.pytorch.org/whl/cu130 && pip install -r requirements.txt3. Start the web UI and pick a model from the Guides tab
python wgp.pyWindows users can run install.bat and run.bat from the scripts folder instead, which also set up acceleration kernels such as Triton and SageAttention; Linux has matching .sh scripts, and Pinokio offers a one-click install. GTX 10 series cards need Python 3.10.9 and PyTorch 2.7.1. Models download on first use and are large. Several audio models clone a voice from a short sample; only clone voices you have permission to use. Use only the official repository and wangp.ai: the author warns that other sites using the name are not affiliated.
Safety scan
We cloned deepbeepmeep/Wan2GP at commit b8b18f8 on Oct 1, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets and no bare-IP URLs across 2,764 files and about 649,000 lines of Python. Of the three pattern hits, the very long line in models/qwen21/qwen21_handler.py is a model description string, install.sh pipes astral.sh's uv installer to sh when you pick that option, and install.bat uses certutil only as a fallback downloader when curl is missing.
- setup.py is not a pip package script but the environment manager behind the install, run and update scripts: it creates a uv, venv or conda environment and installs PyTorch and the kernels listed in setup_config.json, prebuilt wheels from deepbeepmeep/kernels, woct0rdho's SageAttention and SpargeAttn forks, and nunchaku. install.sh uses sudo only to install Python through apt, dnf or pacman.
- scripts/install_dlss5.ps1 is opt-in and Windows-only. It warns that the RenoDX and DLSSNR files are community-hosted, NVIDIA-derived, proprietary and unsigned, requires you to type I ACCEPT, and checks each download against a SHA-256. The one committed binary, postprocessing/seedvc/campplus_cn_common.bin (28 MB), is the CAM++ speaker-embedding checkpoint that the Seed-VC voice converter uses.
- 90 known advisories (1 critical, 54 high). requirements.txt holds 57 among its 40 packages, chiefly transformers and diffusers advisories about loading untrusted models or remote code, which apply if you load checkpoints from unknown sources such as random CivitAI uploads; the critical is GitPython. The other 33 are build tooling for the bundled image-editor component.
- No GitHub workflows, security policy or contributing guide; a licence file is present. GitHub shows no release because WanGP versions live in the README changelog rather than tags.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | 3 pattern hits found and read; every one is listed under the raw findings. |
| Install-time code | 1 setup.py with custom install logic. 5 installer scripts (one fetches and runs a remote script; one can call sudo) |
| Committed binaries | 1 executable or compiled object committed; listed under the raw findings. |
| CI workflows | No GitHub Actions workflows. |
| Network hosts | 40 distinct hosts referenced from source; most often github.com, www.apache.org, arxiv.org, huggingface.co. No URLs to bare IP addresses. |
| Known vulnerabilities | 90 advisories across 371 pinned packages: 1 critical, 54 high, 30 moderate, 5 low. requirements.txt: 40 packages, 57 advisories; shared/gradio/wangp_image_editor/frontend/package-lock.json: 332 packages, 33 advisories. |
| Project hygiene | Has licence file. Missing security policy, automated dependency updates, CodeQL, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Pattern hits (3)
| Where | Rule | Match |
|---|---|---|
| models/qwen21/qwen21_handler.py:133 | very-long-line | 3118 chars |
| scripts/install.bat:233 | living-off-the-land | certutil -urlcache -split -f "%DL_URL%" "%TMP_FILE%" |
| scripts/install.sh:129 | download-piped-to-shell | curl -LsSf https://astral.sh/uv/install.sh | sh |
Installer scripts (5)
- run-docker-cuda-deb.sh, 211 lines, uses sudo; talks to nvidia.github.io
- scripts/install.sh, 181 lines, uses sudo, fetches and runs a remote script; talks to astral.sh, repo.anaconda.com
- scripts/install_dlss5.ps1, 237 lines; talks to github.com, reshade.me
- scripts/run.sh, 85 lines
- scripts/start-chrome-no-gpu.sh, 37 lines
Committed binaries (1)
postprocessing/seedvc/campplus_cn_common.bin: .bin, 28 MB
Worst known vulnerabilities (24 of 90)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-284h-m62q-gf8w | critical | gitpython@3.1.45 | GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any… |
| GHSA-7wx4-6vff-v64p | high | diffusers@0.36.0 | Diffusers: TOCTOU Trust Remote Code Bypass |
| GHSA-98h9-4798-4q5v | high | diffusers@0.36.0 | Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components |
| GHSA-j7w6-vpvq-j3gm | high | diffusers@0.36.0 | |
| GHSA-29pf-2h5f-8g72 | high | transformers@4.54.0 | HuggingFace transformers vulnerable to remote code execution |
| GHSA-fgcw-684q-jj6r | high | transformers@4.54.0 | huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path |
| GHSA-x9r9-c232-4q39 | high | transformers@4.54.0 | Hugging Face Transformers downloads custom generation code before trust consent |
| GHSA-xrqw-3rrv-vx5w | high | transformers@4.54.0 | Transformers save_pretrained path traversal allows arbitrary file writes through chat template names |
| CVE-2025-14920 | high | transformers@4.54.0 | |
| CVE-2025-14921 | high | transformers@4.54.0 | |
| CVE-2025-14924 | high | transformers@4.54.0 | |
| CVE-2025-14926 | high | transformers@4.54.0 | |
| CVE-2025-14927 | high | transformers@4.54.0 | |
| CVE-2025-14928 | high | transformers@4.54.0 | |
| CVE-2025-14929 | high | transformers@4.54.0 | |
| CVE-2025-14930 | high | transformers@4.54.0 | |
| GHSA-39mp-8hj3-5c49 | high | gradio@5.29.0 | Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+ |
| GHSA-7hp7-4p35-3cx2 | high | gradio@5.29.0 | Gradio contains a cookie injection vulnerability |
| GHSA-j36p-7w88-g82j | high | gradio@5.29.0 | Gradio FileExplorer preprocess path traversal allows files outside root_dir to reach callbacks |
| GHSA-jmh7-g254-2cq9 | high | gradio@5.29.0 | Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing |
| GHSA-239g-whfq-7xj9 | high | gitpython@3.1.45 | GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution |
| GHSA-2f96-g7mh-g2hx | high | gitpython@3.1.45 | GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist |
| GHSA-3f7w-8rr8-f37f | high | gitpython@3.1.45 | GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file over… |
| GHSA-3rp5-jjmw-4wv2 | high | gitpython@3.1.45 | GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE) |
By the numbers
| Stars | 9,858 |
|---|---|
| Forks | 1,563 |
| Contributors | 36 |
| Commits | 1,826 |
| Open issues | 1,186 |
| Open pull requests | 66 |
| Releases | 0 |
| Latest release | none tagged |
| Licence | custom |
| Main language | Python |
| Project age | 1 year |
| Last push | Oct 1, 2026 |
| Tracked files | 2,764 |
| Lines of code | 648.6K |
| Checkout size | 93 MB |
Lines by language: Python 570.7K, JSON 30.5K, Markdown 12K, JavaScript 11.3K, TypeScript 8,099, Svelte 5,430.
Questions
Is Wan2GP free?
Yes, to run locally. The WanGP Community License 2.0 lets anyone use it for free, including inside a company, and you may sell the images, videos and audio you make, crediting WanGP when you sell an output directly. Selling WanGP itself, white-labelling it or offering it as a paid hosted service needs a commercial licence. Model weights keep their own licences.
How much VRAM does Wan2GP need?
Some models run in as little as 6 GB of VRAM thanks to offloading and quantized checkpoints, but larger video models and higher resolutions want more, and system RAM matters too because weights are offloaded to it. NVIDIA GTX 10 series and newer and AMD RDNA 2 to 4 cards are supported.
What is the difference between Wan2GP and ComfyUI?
ComfyUI is a node graph where you wire up every step yourself; Wan2GP is a fixed web interface with a form per model, tuned presets and memory management done for you. ComfyUI is more flexible; Wan2GP is quicker to a first result on a small GPU.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
