harry0703/MoneyPrinterTurbo
51.7
Adequate · 26 September 2026
27.8k
lines of production code
Python
primary language
4
measurements over time
What this system is
This system is a containerized video generation service that automates the creation of videos from text prompts using LLMs for scripting and metadata. It provides a REST API and a WebUI for managing tasks, uploading media assets, and configuring generation parameters such as transitions and subtitles. The platform handles background processing with concurrency controls and supports multiple LLM providers through a structured registry.
Features
Add static landing page for MoneyPrinterTurbo
A new static HTML landing page has been added to the public resources, displaying the application title and a brief description of its functionality in both Chinese and English, along with a link to the project's GitHub repository.
resource · high confidence
Added video transition effects (Fade, Slide, Zoom)
A new utility module for video effects has been introduced, providing FadeIn, FadeOut, SlideIn, SlideOut, ZoomIn, and ZoomOut transitions. The slide and zoom implementations use custom logic to ensure visual stability and visibility, addressing issues where built-in MoviePy effects were unreliable or imperceptible.
app/services/utils · high confidence
Initial API controller structure with secure key validation
The application introduces a base controller module that enforces API key authentication via the 'x-api-key' header when configured, ensuring secure constant-time comparison and sanitizing client request IDs to prevent log injection. A new health check endpoint is also added at '/ping' to verify service availability.
app/controllers · high confidence
Introduce Docker containerization and standardized repository configuration
The project now supports running as a Docker container, providing a \Dockerfile\ for standard CPU-based execution, a \Dockerfile.gpu\ for NVIDIA CUDA acceleration, and a \Dockerfile.claude\ variant that includes the Claude Code CLI. The containerized WebUI is exposed on port 8501 with CORS enabled and usage statistics disabled. To support this and improve repository hygiene, the diff adds \.dockerignore\ to exclude local development artifacts, \.gitattributes\ to normalize line endings and mark media files as binary, and a \.python-version\ file to pin the runtime to Python 3.11.
(repo-wide) · high confidence
Introduce v1 API endpoints for video generation, LLM scripts, and social metadata
The application now exposes a new v1 REST API under /api/v1. This includes endpoints for generating video scripts, video terms, and social publishing metadata via the LLM service, as well as endpoints for creating video and subtitle tasks, uploading and retrieving video materials, and managing background music. The v1 router enforces API key authentication (when configured) and supports Redis-backed task management for concurrency and queuing.
app/controllers/v1 · high confidence
Security
Hardened file path validation and stabilized logging for cross-platform reliability
The application now enforces strict path traversal protection by resolving all user-supplied file paths against a base directory using real-path canonicalization, preventing directory escape attacks via symlinks or relative path tricks. Additionally, logging has been refactored to handle cross-platform path discrepancies (such as Windows mapped drives) and WebUI hot-reload scenarios, ensuring log records are preserved and consistently formatted without dropping entries during terminal handler re-initialization.
app/utils · high confidence
Behavioural changes
API key enforcement, CORS hardening, and ping health check
The application now enforces API key authentication for the /api/v1 and /tasks endpoints, issuing a warning if the key is missing to encourage secure deployment. Browser cross-origin access is restricted by default; CORS is only enabled when specific origins are configured via CORS\_ALLOWED\_ORIGINS, with improved origin normalization to prevent silent failures and a warning when wildcard origins are used without API key protection. Additionally, a ping health check router is registered to support service monitoring.
app · high confidence
Introduce dedicated background music and local material upload services
The application now includes dedicated services for handling background music and local material uploads, introducing explicit server-side validation and security controls. The new BGM service enforces a 30 MB upload limit, restricts accepted formats to standard audio extensions (MP3, M4A, AAC, WAV, FLAC, OGG, OPUS, WMA), and validates files using FFmpeg to ensure they contain decodable audio streams. It also sanitizes filenames to reject Windows reserved names and unsafe Unicode control characters. Similarly, the local material upload service validates video and image uploads against specific extensions and content types, rejecting images disguised as videos and enforcing size limits (200 MB for video, 20 MB for images). These changes ensure that user-uploaded media is safe, correctly formatted, and does not bypass pipeline expectations.
app/services · high confidence
Introduce structured LLM provider registry and comprehensive video generation schema
The application now uses a centralized registry of LLM provider specifications (in app/models/llm\_provider.py) to manage API keys, base URLs, and regional endpoints, replacing ad-hoc configuration with a structured, extensible model. Concurrently, the video generation parameters (app/models/schema.py) have been expanded to support new user-facing features including configurable video transitions (SlideIn, SlideOut, ZoomIn, ZoomOut), clip fit modes (cover/contain), word-by-word subtitle animations, custom audio file uploads, and background music prompts. Supporting constants for punctuation and task states are also now explicitly defined in app/models/const.py.
app/models · high confidence
Modernized WebUI layout and streamlined Streamlit integration
The WebUI has been redesigned to improve visual clarity and reduce clutter. A new CSS stylesheet hides Streamlit's default platform toolbars (Deploy, skills nudges) and compresses top padding, while the main container now features a compact brand header with the project name and version number. The layout has been refined to keep configuration controls, such as the video subject and voice mode selection, visually aligned and compact, ensuring a cleaner, more focused user experience for generating videos.
webui · high confidence
Non-blocking runtime configuration updates for WebUI
The application now supports updating WebUI configuration settings (such as provider keys or model selections) without blocking ongoing video generation tasks. Previously, changing a setting while a task was running could freeze the interface or interrupt the process. The new implementation uses a deferred update queue: if the configuration lock is held by a long-running task, UI changes are queued and applied immediately after the task completes, ensuring the interface remains responsive and the current task's configuration remains stable.
app/config · high confidence
Fixes
Introduce robust task queue management with concurrency limits and stale task handling
Added a new task management layer in \app/controllers/manager\ that enforces configurable concurrency and queue size limits to prevent resource exhaustion. The \TaskManager\ base class ensures thread-safe concurrency counting and rejects tasks when the queue is full. The \RedisTaskManager\ implementation now safely handles stale or invalid queued tasks by discarding them and marking their status as failed, preventing API/WebUI from hanging in a 'processing' state. An in-memory alternative is also provided for non-persistent scenarios.
app/controllers/manager · high confidence
Test coverage
Comprehensive unit test suite for core services and security controls
Added a structured test directory with a README and a suite of unit tests covering critical application areas. Tests verify API authentication logic (including key validation, duplicate header rejection, and OpenAPI documentation), ASGI CORS origin parsing and enforcement, and secure static file serving (including symlink traversal prevention). Additional tests cover background music upload sanitization and validation, video cache management (stats and cleanup), CLI argument parsing and Unicode handling, video clip speed normalization, configuration persistence (including UTF-8 BOM handling and example config validation), and controller base utilities like task ID normalization. These tests ensure that security hardening, configuration robustness, and media processing logic function correctly without relying on external services.
test · high confidence
Dependencies
Migrate dependency management to uv and pyproject.toml
The project has adopted the uv-based environment and dependency management system, consolidating all runtime dependencies into a new pyproject.toml file and locking versions via uv.lock to ensure consistent builds across different machines. This change introduces support for Python 3.13 through the conditional audioop-lts dependency and includes specific library updates such as upgrading moviepy to 2.2.1, openai to 2.24.0, and adding litellm 1.86.2 and google-genai 2.11.0. A legacy requirements.txt is retained solely for backward-compatible pip installation support, while development tooling is now managed via uv with ruff and pytest pinned in the project configuration.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 41 → 52 (+11.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 90 → 74 (-15.9)
- Architecture 96 → 97 (+1.6)
- Maturity 52 → 52 (+0.1)
- Readiness 20 → 36 (+16.7)
- Security 48 → 75 (+27.4)
Resolved (53)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Disclosure policy has no reporting contact
- Duplicated block (12 lines × 2) (test/services/test_llm.py)
- Duplicated block (16 lines × 2) (test/services/test_task.py)
- Duplicated block (19 lines × 2) (test/services/test_material.py)
- Duplicated block (8 lines × 2) (test/services/test_video.py)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 33 more
New (298)
- Banned license: edge-tts
- Critical CVE: [GHSA redacted] (uv.lock)
- Critical CVE: [GHSA redacted] (uv.lock)
- Documentation: no installation or build instructions (README.md)
- Duplicated block (10 lines × 2) (app/services/bgm.py)
- Duplicated block (10 lines × 2) (app/services/elevenlabs_music.py)
- Duplicated block (10 lines × 3) (app/services/material.py)
- Duplicated block (10–11 lines × 2) (webui/Main.py)
- Duplicated block (10–14 lines × 3) (app/services/muapi.py)
- Duplicated block (11 lines × 2) (app/services/bgm.py)
- Duplicated block (11 lines × 2) (app/services/material.py)
- Duplicated block (11 lines × 2) (app/services/material.py)
- Duplicated block (11 lines × 3) (app/services/metaso_minimax.py)
- Duplicated block (11 lines × 4) (app/services/metaso_minimax.py)
- Duplicated block (11 lines × 4) (app/services/metaso_minimax.py)
- Duplicated block (11 lines × 5) (webui/Main.py)
- Duplicated block (11–13 lines × 2) (webui/Main.py)
- Duplicated block (11–13 lines × 4) (webui/Main.py)
- Duplicated block (12 lines × 2) (app/services/material.py)
- Duplicated block (12 lines × 2) (webui/Main.py)
- …and 278 more
Changes since last survey
- 239 commits — 116 feature/other, 123 fixes
By area
- (repo) — 62 commits
- (root) — 54 commits
- webui/i18n — 36 commits
- test/services — 32 commits
- app/services — 31 commits
- app/controllers — 6 commits
- docs/skill — 4 commits
- .github/workflows — 3 commits
- app/models — 3 commits
- app/asgi.py — 2 commits
- webui/Main.py — 2 commits
- app/config — 1 commit
- app/router.py — 1 commit
- docs/MoneyPrinterTurbo.ipynb — 1 commit
- docs/voice-list.txt — 1 commit
Notable commits
- fix: Fix Colab notebook: add missing imports and correct REPO_DIR path
- fix: Fix UnicodeEncodeError that kills the CLI after a successful run
- fix: Fix webui.sh port check breaking on paths with spaces
- fix: Merge pull request #1191 from HaningZS/fix/persist-generation-settings
- fix: Merge pull request #1192 from HaningZS/fix/rollback-unscheduled-task
- fix: Merge pull request #1238 from lihuiyang1024/fix/custom-audio-path-traversal
- fix: Merge pull request #1239 from lihuiyang1024/fix/task-static-symlink
- fix: Merge pull request #1241 from lihuiyang1024/fix/material-upload-hardening
- fix: Merge pull request #1242 from lihuiyang1024/fix/request-id-sanitization
- fix: Merge pull request #1252 from abhiunix/fix/webui-headless-play-open-folder
- fix: Merge pull request #1263 from YUSAKRU/fix/audio-duration-from-file
- fix: Merge pull request #1264 from Mihir7027/fix/batch-manifest-byte-limit-message
- fix: Merge pull request #1265 from Mihir7027/fix/content-disposition-filename-quoting
- fix: Merge pull request #1266 from Mihir7027/fix/redis-url-null-password
- fix: Merge pull request #1267 from Mihir7027/fix/llm-retry-spurious-warning
- fix: Merge pull request #1268 from Mihir7027/fix/siliconflow-subtitle-end-truncation
- fix: Merge pull request #1269 from Mihir7027/fix/audio-clip-leak-in-tts-providers
- fix: Merge pull request #1270 from Mihir7027/fix/greedy-regex-eats-script-content
- fix: Merge pull request #1282 from housine35/fix/windows-console-encoding
- fix: Merge pull request #1288 from Sushanth012/fix/windows-reserved-download-names
- …and 219 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
harry0703/MoneyPrinterTurbo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit ad5496f1b729d1d7e361dd972015d26c08b0e052 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.