6 min read

Wan2GP: AI Video Generation on a 6 GB GPU (GitHub, Scanned)

A web app that runs open video, image and audio models on consumer GPUs, some in 6 GB of VRAM.

Wan2GP logo
✅
Scan: safe. Nothing malicious. Two things to know: the one-click installers fetch prebuilt acceleration kernels from community GitHub repositories, and an optional DLSS 5 script installs unsigned third-party binaries after an explicit warning. Scanned Oct 1, 2026; the full report is below.

Wan2GP, which calls itself WanGP, is a browser-based studio for running the major open generative models on your own graphics card. For video it covers Wan 2.1 and 2.2 and their derivatives, LTX-2, Hunyuan Video, LongCat, Kandinsky and others; for images Qwen Image, Z-Image, Flux and HiDream among more; and for audio a set of speech, voice and music models including Qwen3 TTS, Chatterbox and ACE-Step. Around them sit a generation queue, galleries, reusable settings, a mask editor, pose and depth extractors, upscaling and frame interpolation, plus a headless mode and an API.

The point is memory. Its author, who goes by DeepBeepMeep, focuses on offloading and quantization so that models built for data-center GPUs fit on gaming cards: some run in 6 GB of VRAM, NVIDIA cards from the GTX 10 series on are supported, AMD RDNA 2 to 4 works, and it downloads the checkpoint variant that suits your hardware. Updates are frequent; version 13.141 shipped on September 29, 2026.

It has about 9,900 stars and a following on YouTube, where low-VRAM video tutorials often use it. GitHub shows its licence as unrecognised because it uses its own WanGP Community License 2.0: free to use, including at a company, and you may sell what you make with it, but selling WanGP itself, embedding it in a paid product or offering it as a paid hosted service needs a commercial licence. Each model keeps its own licence.

Who it is for

Hobbyists and creators with a gaming PC who want to try current open video models without renting cloud GPUs, and ComfyUI users who want a simpler interface for the same models.

Getting started

1. Clone the repository and create an environment (RTX 20 to 50 series)

git clone https://github.com/deepbeepmeep/Wan2GP.git && cd Wan2GP && conda create -n wan2gp python=3.11.14 && conda activate wan2gp

2. Install PyTorch for CUDA 13 and the requirements

pip install torch==2.10.0 torchvision==0.25.0 torchaudio==2.10.0 --index-url https://download.pytorch.org/whl/cu130 && pip install -r requirements.txt

3. Start the web UI and pick a model from the Guides tab

python wgp.py

Windows users can run install.bat and run.bat from the scripts folder instead, which also set up acceleration kernels such as Triton and SageAttention; Linux has matching .sh scripts, and Pinokio offers a one-click install. GTX 10 series cards need Python 3.10.9 and PyTorch 2.7.1. Models download on first use and are large. Several audio models clone a voice from a short sample; only clone voices you have permission to use. Use only the official repository and wangp.ai: the author warns that other sites using the name are not affiliated.

Safety scan

We cloned deepbeepmeep/Wan2GP at commit b8b18f8 on Oct 1, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets and no bare-IP URLs across 2,764 files and about 649,000 lines of Python. Of the three pattern hits, the very long line in models/qwen21/qwen21_handler.py is a model description string, install.sh pipes astral.sh's uv installer to sh when you pick that option, and install.bat uses certutil only as a fallback downloader when curl is missing.
  • setup.py is not a pip package script but the environment manager behind the install, run and update scripts: it creates a uv, venv or conda environment and installs PyTorch and the kernels listed in setup_config.json, prebuilt wheels from deepbeepmeep/kernels, woct0rdho's SageAttention and SpargeAttn forks, and nunchaku. install.sh uses sudo only to install Python through apt, dnf or pacman.
  • scripts/install_dlss5.ps1 is opt-in and Windows-only. It warns that the RenoDX and DLSSNR files are community-hosted, NVIDIA-derived, proprietary and unsigned, requires you to type I ACCEPT, and checks each download against a SHA-256. The one committed binary, postprocessing/seedvc/campplus_cn_common.bin (28 MB), is the CAM++ speaker-embedding checkpoint that the Seed-VC voice converter uses.
  • 90 known advisories (1 critical, 54 high). requirements.txt holds 57 among its 40 packages, chiefly transformers and diffusers advisories about loading untrusted models or remote code, which apply if you load checkpoints from unknown sources such as random CivitAI uploads; the critical is GitPython. The other 33 are build tooling for the bundled image-editor component.
  • No GitHub workflows, security policy or contributing guide; a licence file is present. GitHub shows no release because WanGP versions live in the README changelog rather than tags.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious code3 pattern hits found and read; every one is listed under the raw findings.
Install-time code1 setup.py with custom install logic. 5 installer scripts (one fetches and runs a remote script; one can call sudo)
Committed binaries1 executable or compiled object committed; listed under the raw findings.
CI workflowsNo GitHub Actions workflows.
Network hosts40 distinct hosts referenced from source; most often github.com, www.apache.org, arxiv.org, huggingface.co. No URLs to bare IP addresses.
Known vulnerabilities90 advisories across 371 pinned packages: 1 critical, 54 high, 30 moderate, 5 low. requirements.txt: 40 packages, 57 advisories; shared/gradio/wangp_image_editor/frontend/package-lock.json: 332 packages, 33 advisories.
Project hygieneHas licence file. Missing security policy, automated dependency updates, CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Pattern hits (3)
WhereRuleMatch
models/qwen21/qwen21_handler.py:133very-long-line3118 chars
scripts/install.bat:233living-off-the-landcertutil -urlcache -split -f "%DL_URL%" "%TMP_FILE%"
scripts/install.sh:129download-piped-to-shellcurl -LsSf https://astral.sh/uv/install.sh | sh
Installer scripts (5)
Committed binaries (1)
  • postprocessing/seedvc/campplus_cn_common.bin: .bin, 28 MB
Worst known vulnerabilities (24 of 90)
AdvisorySeverityPackageSummary
GHSA-284h-m62q-gf8wcriticalgitpython@3.1.45GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any…
GHSA-7wx4-6vff-v64phighdiffusers@0.36.0Diffusers: TOCTOU Trust Remote Code Bypass
GHSA-98h9-4798-4q5vhighdiffusers@0.36.0Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components
GHSA-j7w6-vpvq-j3gmhighdiffusers@0.36.0
GHSA-29pf-2h5f-8g72hightransformers@4.54.0HuggingFace transformers vulnerable to remote code execution
GHSA-fgcw-684q-jj6rhightransformers@4.54.0huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
GHSA-x9r9-c232-4q39hightransformers@4.54.0Hugging Face Transformers downloads custom generation code before trust consent
GHSA-xrqw-3rrv-vx5whightransformers@4.54.0Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
CVE-2025-14920hightransformers@4.54.0
CVE-2025-14921hightransformers@4.54.0
CVE-2025-14924hightransformers@4.54.0
CVE-2025-14926hightransformers@4.54.0
CVE-2025-14927hightransformers@4.54.0
CVE-2025-14928hightransformers@4.54.0
CVE-2025-14929hightransformers@4.54.0
CVE-2025-14930hightransformers@4.54.0
GHSA-39mp-8hj3-5c49highgradio@5.29.0Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+
GHSA-7hp7-4p35-3cx2highgradio@5.29.0Gradio contains a cookie injection vulnerability
GHSA-j36p-7w88-g82jhighgradio@5.29.0Gradio FileExplorer preprocess path traversal allows files outside root_dir to reach callbacks
GHSA-jmh7-g254-2cq9highgradio@5.29.0Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing
GHSA-239g-whfq-7xj9highgitpython@3.1.45GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution
GHSA-2f96-g7mh-g2hxhighgitpython@3.1.45GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
GHSA-3f7w-8rr8-f37fhighgitpython@3.1.45GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file over…
GHSA-3rp5-jjmw-4wv2highgitpython@3.1.45GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

By the numbers

Stars9,858
Forks1,563
Contributors36
Commits1,826
Open issues1,186
Open pull requests66
Releases0
Latest releasenone tagged
Licencecustom
Main languagePython
Project age1 year
Last pushOct 1, 2026
Tracked files2,764
Lines of code648.6K
Checkout size93 MB

Lines by language: Python 570.7K, JSON 30.5K, Markdown 12K, JavaScript 11.3K, TypeScript 8,099, Svelte 5,430.

Questions

Is Wan2GP free?

Yes, to run locally. The WanGP Community License 2.0 lets anyone use it for free, including inside a company, and you may sell the images, videos and audio you make, crediting WanGP when you sell an output directly. Selling WanGP itself, white-labelling it or offering it as a paid hosted service needs a commercial licence. Model weights keep their own licences.

How much VRAM does Wan2GP need?

Some models run in as little as 6 GB of VRAM thanks to offloading and quantized checkpoints, but larger video models and higher resolutions want more, and system RAM matters too because weights are offloaded to it. NVIDIA GTX 10 series and newer and AMD RDNA 2 to 4 cards are supported.

What is the difference between Wan2GP and ComfyUI?

ComfyUI is a node graph where you wire up every step yourself; Wan2GP is a fixed web interface with a form per model, tuned presets and memory management done for you. ComfyUI is more flexible; Wan2GP is quicker to a first result on a small GPU.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.