github.com / christitustech
christitustech/ winutil
PowerShell·323 files·commit 086aecf·scanned 3d ago·cached ✓
15/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
score capped at 15 — 60,957+ stars — findings likely false positives
verdict accurate?
60,957 stars
5% file coverage
threat-state: lowlive
FINDINGS ░▒▓
criticalBrowser credential store accessAccessing Chrome, Firefox, Edge, or Brave profile directories to steal cookies, passwords, and session tokens.config/tweaks.json
{
"Path": "HKLM:\\SOFTWARE\\Policies\\BraveSoftware\\Brave",
"Name": "BraveRewardsDisabled",
"Value": "1",+10infoSuspicious file in repoExecutable file (Add-SelectedAppsMenuItem.ps1) in repositoryfunctions/private/Add-SelectedAppsMenuItem.ps1+2
infoSuspicious file in repoExecutable file (Close-WinUtilRunspacePool.ps1) in repositoryfunctions/private/Close-WinUtilRunspacePool.ps1+2
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
15 files scanned @ 086aecf | 8/21/2026 | heuristic scan — always review manually
risk by category
code execution0
network & exfiltration0
file system access10
obfuscation0
supply chain15
owasp / injection0
telemetry
files 15/323rules hit 4engine v5commit 086aecf
github
christitustech/winutil
Chris Titus Tech's Windows Utility - Install Programs, Tweaks, Fixes, and Updates
60957
3553
1580d
323 files
15 scanned(5%)
086aecf
architecture░▒▓
entry (1) flagged (0) pkg (6)
9 nodes · 7 edgesscroll to zoom · click node to jump to finding