k1tbyte/Wand-Enhancer
47.5
Weak · 23 September 2026
6k
lines of production code
C#
primary language
5
measurements over time
What this system is
WandEnhancer is a .NET-based desktop application designed to patch and modify Electron-based software, specifically targeting Adobe products for activation and update control. It utilizes a custom library, AsarSharp, to securely read, write, and verify ASAR archives while applying structural JavaScript patches via a WPF interface. The system also features a hardened remote web panel with a WebSocket bridge, enabling remote trainer control, game status synchronization, and multi-language support.
How it got here
2024–2025 — Project initialization and core library development
7 changes.
The project was rebranded as WandEnhancer and initialized with a .NET-based patcher and a Vite-based web panel, replacing legacy Node.js scripts. Significant effort focused on developing the AsarSharp library, introducing secure ASAR extraction and creation, integrity verification, and Chromium-style Pickle serialization tools.
2026 — WandEnhancer 2.0 structural overhaul
7 changes.
The project underwent a major rebranding and architectural shift to WandEnhancer, targeting .NET Framework 4.8 with a new WPF interface and a structurally robust JavaScript patching engine. This period focused on hardening the web-panel bridge with strict security controls, implementing multi-language support, and establishing automated release validation and testing pipelines.
Features
AsarSharp introduces secure extraction and new packaging capabilities
The AsarSharp library now includes a new AsarCreator class for building .asar archives from directories, supporting options to unpack specific paths via regex. The AsarExtractor has been rewritten to improve performance by using a single file handle for all reads and, critically, to prevent path traversal (zip-slip) attacks during extraction by validating that all file and link targets remain within the destination directory. Extraction also now correctly handles symlinks on non-Windows platforms and preserves executable permissions.
AsarSharp · high confidence
Integrity verification for ASAR archives
AsarSharp now includes an integrity helper that computes and validates SHA-256 hashes for ASAR files. The new IntegrityHelper class supports both standard file verification and streaming hashing, allowing users to verify archive integrity by checking file and block-level hashes against expected values.
AsarSharp/Integrity · high confidence
Introduce PickleTools for Chromium-style Pickle serialization
Added the PickleTools library, including the Pickle and PickleIterator classes, to support reading and writing Chromium-style Pickle data structures. The implementation handles payload buffer allocation with a 4096-byte initial unit, manages header and payload sizing, and provides methods for writing and reading integers, unsigned 32-bit values, and UTF-8 strings with proper alignment.
AsarSharp/PickleTools · high confidence
Introduce multi-language support and accent color customization in the web panel
The web panel now supports six languages (English, Russian, German, French, Spanish, and Chinese) with automatic browser locale detection and a manual selector in the Settings drawer. Users can also customize the interface accent color via a picker in Settings, with the choice persisted locally. These features are implemented using Lingui for internationalization and a dedicated appearance storage module, integrated into the main app entry point and the Settings UI.
web-panel/src · high confidence
Introduce new AsarFileSystem implementation for reading and writing ASAR archives
The AsarSharp library now includes a new AsarFileSystem namespace containing the core logic for handling ASAR archives. This adds a new Disk class for low-level I/O operations (reading headers, copying files, and atomic writes), a Filesystem class for managing the archive's internal tree structure and node lookups, a FileSystemCrawler for scanning directories and handling symlinks, and a FilesystemEntry model representing archive metadata. This new implementation provides the underlying mechanics for the library's archive manipulation capabilities.
AsarSharp/AsarFileSystem · high confidence
New custom renderer script support and IPC debugging tool
Users can now place custom JavaScript files in the \web-panel/scripts/custom\ directory to inject logic into the Wand renderer, with a provided example demonstrating safe, repeatable script loading via the \WandEnhancer\ global API. Additionally, a new default \ipc-logger.js\ script has been added to intercept and log Electron IPC \invoke\ and \send\ calls in the browser console, aiding in debugging remote panel communication. A \verify-dist.mjs\ script has also been introduced to enforce build invariants, ensuring production bundles parse correctly and do not contain development-only artifacts.
web-panel/scripts · high confidence
New installed-apps-sync bridge and remote trainer control scripts
The bridge now includes a new renderer-side script module that synchronizes installed game data, catalog information, and game/trainer status to the main process via IPC. This module also introduces remote command handling, allowing the bridge to trigger trainer launches and stops remotely. Additionally, a new script manages the remote pairing UI by injecting styles and rendering QR codes for the connection flow.
web-panel/bridge/scripts · high confidence
New release automation and validation scripts
Added PowerShell scripts to support the 2.0.0.0 release process: \validate-release-metadata.ps1\ ensures the assembly version in AssemblyInfo.cs matches the latest CHANGELOG.md entry and optional release tag; \get-changelog-section.ps1\ extracts changelog content for a specific version (handling pre-release tags); and \test-desktop.ps1\ / \test-patch-locators.ps1\ provide regression tests for desktop patching, update notification logic, and JavaScript patch locators.
scripts · high confidence
Repository initialization with rebranded project structure and build tooling
The repository is initialized with the project rebranded to WandEnhancer, including updated solution files, build scripts (build.cmd/ps1/sh), and documentation (README, CONTRIBUTING, AGENTS). The legacy Node.js unlocker scripts (memoryScanner.js, unlocker.js) are removed, and the project now relies on a .NET-based patcher with a bundled Remote Web Panel. Configuration files (.gitattributes, .gitignore) are added to manage line endings and exclude build artifacts, logs, and local settings.
(repo-wide) · high confidence
Behavioural changes
Automated release metadata validation on commit
A new pre-commit hook has been added to automatically validate release metadata before changes are committed. This hook executes a PowerShell script located in the repository's scripts directory, ensuring that release-related metadata is consistent and correct prior to saving code changes.
.githooks · high confidence
Bridge runtime and protocol hardened with strict validation and security controls
The web-panel/bridge module has been rewritten to enforce strict protocol compliance and security boundaries. The new bridge-state and protocol-router components validate all incoming WebSocket messages, requiring a compatible handshake before processing commands and rejecting requests from mismatched trainers or unknown cheat targets. Security is strengthened by rejecting cross-origin WebSocket connections, limiting WebSocket frame sizes to 1MB, and ignoring untrusted HTTP Host headers. Additionally, the bridge now normalizes trainer values (converting numeric toggles to booleans), tracks game status and installed apps with signature-based deduplication, and exposes a robust health endpoint for monitoring.
web-panel/bridge · high confidence
Improved path handling, extraction security, and file copy diagnostics
The library now uses a faster, literal-prefix algorithm for computing relative paths, falling back to full normalization only when necessary for security checks or complex path structures. Extraction safety is strengthened by validating that file candidates remain inside the root directory after full path normalization, preventing zip-slip attacks. Additionally, file copy operations now clear read-only attributes to avoid permission errors and provide detailed diagnostic messages when access is denied, helping users identify causes like antivirus interference or pending file deletions.
AsarSharp/Utils · high confidence
WandEnhancer rebrands and introduces structural JavaScript patching with a new .NET 4.8 WPF UI
The application has been rebranded to WandEnhancer and now targets .NET Framework 4.8, featuring a WPF interface with localized resources and custom visibility converters. The core patching engine has been overhauled to locate JavaScript edits structurally by anchoring on stable API names and IPC identifiers rather than fragile signatures, ensuring patches remain valid across builds. This new engine supports multiple patch types, including Pro activation, update disabling, and a remote web panel preview, while also introducing a static on-disk patch strategy that manages Electron ASAR integrity fuses and handles backup/rollback logic.
WandEnhancer · high confidence
Dependencies
Initialize .NET and web-panel dependency manifests
The project now includes explicit dependency definitions for its core components. The .NET side (WandEnhancer and AsarSharp) targets .NET Framework 4.8 and relies on Newtonsoft.Json (13.0.3), ILRepack (2.0.41), and several System.\* packages. The web-panel is set up with pnpm, using Vite (7.3.6), Preact, Tailwind CSS, and Lingui for internationalization, while the legacy root package.json with the 'asar' dependency has been removed.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 51 → 47 (-3.4)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 59 → 48 (-10.4)
- Architecture 96 → 97 (+0.8)
- Maturity 54 → 62 (+7.1)
- Readiness 43 → 35 (-8.1)
- Security 54 → 70 (+15.7)
Resolved (31)
- Build did not complete in the analyzer
- Coverage not included — suite not readable by the collector
- Duplicated block (10 lines × 2) (AsarSharp/Utils/Extensions.cs)
- EmptyCatchBlock (WandEnhancer/Utils/Common.cs)
- EmptyCatchBlock (WandEnhancer/Utils/Extensions.cs)
- Enhancer.ApplyJsPatch (cognitive 16) (WandEnhancer/Core/Enhancer.cs)
- Enhancer.PatchAsar (cognitive 18) (WandEnhancer/Core/Enhancer.cs)
- High CVE: [GHSA redacted] (web-panel/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (web-panel/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (web-panel/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (web-panel/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (web-panel/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (web-panel/pnpm-lock.yaml)
- High vulnerability: [GHSA redacted] (web-panel/pnpm-lock.yaml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 11 more
New (35)
- AsarContentPatcher.Patch (cognitive 17) (WandEnhancer/Core/Patching/Content/AsarContentPatcher.cs)
- Build failed
- Coverage not measured — .NET and JavaScript/TypeScript suite
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- DotNetImage.BodyCalls (cognitive 17) (WandEnhancer/Core/Patching/Strategies/Static/DotNetImage.cs)
- Duplicated block (11 lines × 2) (AsarSharp/Utils/Extensions.cs)
- Filesystem.SearchNodeFromDirectory (cognitive 28) (AsarSharp/AsarFileSystem/FileSystem.cs)
- Filesystem.SearchNodeFromDirectory (cyclomatic 17) (AsarSharp/AsarFileSystem/FileSystem.cs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 15 more
Changes since last survey
- 23 commits — 17 feature/other, 6 fixes
By area
- WandEnhancer/Core — 6 commits
- (root) — 5 commits
- web-panel/src — 3 commits
- AsarSharp/AsarFileSystem — 2 commits
- web-panel/bridge — 2 commits
- (repo) — 1 commit
- AsarSharp/Utils — 1 commit
- WandEnhancer/Locale — 1 commit
- WandEnhancer/Patches — 1 commit
- tools/asar-fuses-bypass — 1 commit
Notable commits
- fix: fix(asar): correct archive tree lookups and fail loudly on unreadable input
- fix: fix(launcher): clear the fuse in every process Wand spawns
- fix: fix(launcher): retry the fuse write until the process is ready
- fix: fix(patch): roll back the installation when patching fails
- fix: fix(patch): stop the deployed launcher inheriting a read-only flag
- fix: fix(renderer-scripts): await the bridge bind and retry it on poll
- change: Merge pull request #279 from k1tbyte/feature/rc_v_2.0.0.0
- change: chore(build): enforce lint, type-check and dist invariants in build and CI
- change: chore(release): 2.1.0.0
- change: chore(release): prepare 2.0.0.0 and support pre-release tags
- change: docs(changelog): note the failed-patch rollback
- change: feat(launcher): clear the ASAR fuse from a debugger instead of a proxy DLL
- change: feat(launcher): log the applied patches and keep the previous log
- change: feat(launcher): show the window when Wand fails to start
- change: feat(launcher): write startup diagnostics to launcher.log
- change: feat(panel): add IconButton primitive and fix input, reconnect and a11y gaps
- change: feat(patch): report what is blocking a denied copy
- change: feat(patch-engine): locate patches structurally instead of by signature
- change: feat(patching): static on-disk patch method with strategy selector
- change: feat: prepare 2.0.0.0 with opt-in update notifications and pre-release fixes
- …and 3 more
Architecture
- Unchanged — 1 containers · 0 contexts · 0 edges
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
k1tbyte/Wand-Enhancer was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c6ae7a3ad49388ab9ad0ef6e06d235b59cc573cb — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.