64-bit
msixgithub.com · publisher domain- SHA-256
- 606bba9cd7f3a8805bb89c6669e0abfd67a705ddc98939148afedefeed520b9c
by Kenji Mouri · MIT
The 7-Zip derivative intended for the modern Windows experience.
These URLs are the ones Kenji Mouri declares in its own manifest. We do not proxy or shorten them, and we do not host a copy.
Run this against the file on disk. If the output does not match the hash below, the file is not what Kenji Mouri published. Delete it.
Windows · PowerShell
Get-FileHash "NanaZip_6.5.1767.0.msixbundle" -Algorithm SHA256macOS · Linux
shasum -a 256 "NanaZip_6.5.1767.0.msixbundle"Expected output
606bba9cd7f3a8805bb89c6669e0abfd67a705ddc98939148afedefeed520b9c
| Signal | Finding | Points |
|---|---|---|
| SHA-256 hash published | 2 of 2 installers ship a SHA-256 hashWithout a published hash there is no way to prove the file you downloaded is the file the publisher built. | 30 / 30 |
| Binary provenance | 2 on the publisher's own domainThe strongest signal against a repackaged installer: the file should come from the publisher, not from a mirror nobody vouches for. | 35 / 35 |
| Served over HTTPS | 2 of 2 over HTTPSAn installer fetched over plain HTTP can be modified in transit. | 15 / 15 |
| Release recency | last release about 1 months agoSoftware that has not shipped in years accumulates unpatched vulnerabilities. | 15 / 15 |
| Licence declared | MITA declared licence tells you what you are actually allowed to do with the software. | 5 / 5 |
Extensions NanaZip registers itself to handle.
Every version with a published manifest, newest first. Useful when you need an older build for compatibility.