ALL DEVELOPER TOOLS56
Unzip Files
Unzip Files Online — Free, No Upload
List everything inside a .zip with its real size, then pull out just the files you want — all in this tab.
Nothing is enforced, and what binds is the UNPACKED total rather than the archive's own size — a small archive can hold an enormous amount, and extracting it was measured at about three times that unpacked total in memory.
About Unzip Files
Opening an archive means trusting whatever is inside it, which is exactly why doing it on somebody else's server is a strange habit. This page reads the ZIP's own index in your browser and lists every entry — its path, its packed size, its unpacked size, the compression it uses — before anything is written out, so you can pull one file out of a large archive without unpacking the rest. Entries whose stored path tries to leave the folder you would extract into are refused and named on screen, not quietly rewritten to something that looks harmless: that rewrite is the standard behaviour of the underlying library, and it is the zip-slip vulnerability with its edge filed off rather than removed. Password-protected entries are named too. They cannot be opened here at all, because there is no decryption in this page and the reader refuses an archive whole when it meets one — the same is true of entries compressed with bzip2, LZMA or zstd. Nothing is uploaded, and nothing about the archive is sent anywhere.
Questions
It says my archive is password-protected and will not open anything at all.
That is accurate, and the second half is the part worth explaining. This page has no decryption in it, and the reader it uses refuses an archive outright the moment it meets an encrypted entry while walking the index — before a single byte is extracted. So one protected file blocks every unprotected file beside it, and there is no partial extraction to offer. The listing still works, because the archive's index is read separately and is never encrypted, which is why the page can name exactly which entries are protected. To open it, use 7-Zip, Keka or the unzip command, where you can supply the password.
Why is one of the files marked REFUSED?
Because its stored path tries to leave the folder you would extract into — it begins with ../, or with a slash, or with a drive letter. That is the shape of a zip-slip attack: an archive that writes a file over something elsewhere on your disk when a careless extractor follows the path it was given. What makes it worth flagging is that the usual behaviour is not a refusal but a quiet repair — the library underneath this page rewrites ../../etc/passwd to etc/passwd and extracts it under that name without a word. Here the entry is refused, named on screen, and left out. Everything else in the archive is unaffected.
Why did my two files come down as another ZIP?
Because a browser cancels most of a burst of downloads fired at once, so handing you six separate files would reliably give you one or two. Selecting a single entry saves that file directly under its own name. Selecting more repacks them into one archive that keeps their folder paths, which you then unpack with whatever you normally use. It is worth being clear that this is a repack rather than a folder appearing on your disk: a web page cannot write a directory tree, and any tool that claims to unzip straight into your file system is either an extension or an application, not a page.
The file names have strange characters in them.
Old archives store names in CP437, the original IBM PC character set, and only set a flag saying "this name is UTF-8" if the writer bothered. This reader decodes names as UTF-8 either way, matching the library it extracts with, so a name written on a Windows machine in the 1990s can come out wrong. The page counts those entries and warns you rather than letting you assume the file is damaged. Only the names are affected — the contents are read byte for byte and are exactly what the archive holds. Rename the file after saving it, or unpack the archive with a tool that lets you name the codepage.
It says the archive uses a compression it cannot read.
A ZIP can hold entries compressed in several ways, and the reader here inflates the two that account for practically every archive in the wild: Store, which is no compression, and DEFLATE. Entries written with bzip2, LZMA, zstd or the old implode method cannot be inflated, and — as with encryption — the reader refuses the whole archive rather than skipping them, so one such entry blocks the rest. The listing still names them and shows which method each uses, because that comes out of the index. 7-Zip and the unzip command read all of these, and re-saving the archive from either one produces a file this page can open.
Is my file uploaded to a server?
No. Transmute processes everything locally in your browser using JavaScript and WebAssembly. Your files never leave your device — there is no server, no upload, no cloud processing.