Skip to content
Utiloom

ZIP Inspector & Verified Extractor

Inspect ZIP paths and structure, block unsafe entries, then extract selected files with CRC, byte-count, and SHA-256 evidence.

LocalNo archive retention

Reviewed July 14, 2026

Guide, examples, and validation Show

About this tool

Review an untrusted ZIP archive before opening members, then extract only the files you select after structural and integrity checks pass in your browser.

ZIP Inspector & Verified Extractor reconciles ZIP end records and critical local entry fields, verifies payload and descriptor boundaries, classifies unsafe paths and entry types, and verifies selected output bytes before enabling individual downloads.

  • Preflights a central directory up to 16 MB and 10,000 entries, reconciles classic and ZIP64 end records plus critical local and central header fields, then verifies every payload and data descriptor ends before the directory without overlapping another entry.
  • Separates clear, manual-review, and blocked entries, with explicit declared sizes, compression ratios, findings, search, filters, and a versioned JSON inspection report.
  • Extracts up to 200 selected files within a 200 MB runtime budget and enables individual downloads only after CRC, actual byte length, and SHA-256 processing all succeed.

How to use ZIP Inspector

Choose one ZIP, inspect its bounded structure, search and filter every clear, review, or blocked entry, select only intended files, then extract and download them after the complete selection passes CRC, actual-size, and SHA-256 processing.

When this tool is useful

  • Before opening an archive received through email, upload, or file transfer.
  • When only a few members of a large archive are needed.
  • When archive paths, entry types, declared sizes, CRC values, and selected output hashes must be recorded.

Practical tips

  • Treat Review entries as a manual decision; nested archives and executable-looking names are never selected automatically.
  • Keep the source ZIP until each downloaded file is checked in its destination workflow.
  • Use a maintained malware scanner and target-format parser separately before opening untrusted extracted content.
  • Compare the extraction evidence SHA-256 with a trusted digest when provenance matters.

Examples you can test

Load an example, compare the result with the expected output, then replace it with your own input.

Review a vendor handoff

Example input

One ZIP containing documents, a nested package, and a traversal-style entry

Expected output

Explicit clear, review, and blocked rows plus verified downloads for selected documents.

The structural verdict does not establish that document content is harmless.

Validation checklist

  • Review every blocked path, collision, type, encryption, compression, and size finding.
  • Review executable-looking and nested-archive entries individually.
  • Confirm the completed batch reports CRC, actual size, and SHA-256 for every selected file.
  • Scan and parse untrusted downloads with appropriate maintained tools before opening them.

Frequently asked questions

Does this prove a ZIP file is safe?

No. It checks bounded archive structure, critical local and central metadata, paths, entry types, declared resources, payload and descriptor boundaries, overlapping ranges, CRC, and output size. It does not scan for malware or prove extracted content is safe to open.

Can it extract password-protected ZIP files?

No. Encrypted entries remain visible in the inspection report but are blocked from extraction, and the tool does not accept passwords.

Which ZIP compression methods are supported?

Stored, Deflate, and Deflate64 entries can be eligible. Other methods are reported and blocked from extraction.

What happens to folders and file permissions?

Directories are not downloaded. Verified files are downloaded individually with path segments flattened into the filename; timestamps, permissions, ownership, and symbolic links are not recreated.

Are archive files uploaded?

No. Inspection, selected extraction, CRC checking, and SHA-256 calculation run locally in the current browser session.

Related tools

Keep the workflow moving

Continue with tools that handle a related input, output, or validation step.

File

File Checksum Verifier

Strictly calculate and verify SHA-256 file checksums.

Local
File

ZIP File Maker

Create and verify standard ZIP archives locally.

Local
File

Audio Trim & WAV Export

Trim local audio into a verified PCM WAV.

Local
File

Folder Checksum & Integrity Verifier

Create and compare strict SHA-256 folder manifests.

Local