Build status
An honest record of what runs today. Every tool is marked implemented, runtime-unverified until a verification run covers it — a compile success or an installed library never counts as a runtime test. The pure engines have been executed server-side (see the execution log); run the verification above to cover this browser as well.
50
Implemented
2
Partial
8
Requires setup
Run verification (in your browser)
Creates fixtures, runs the real engines, and validates outputs with independent readers (PDF.js, fflate, jsQR, manual WAV parsing). Covers the browser-only paths the server-side engine run cannot: image engines, HEIC decode, PDF rendering, canvas QR, and full workflow chains. Nothing is uploaded or stored.
Test evidence
Two layers. (1) Engine-level suite, executed in Node 20 against the same engine code — see the execution log below. (2) In-browser harness (Status page, "Run verification"): runs the same engine tests plus DOM-dependent tests (Canvas, HEIC decode, PDF.js rendering, QR canvas pipeline) and outputs independent-reader checks (PDF.js, fflate, jsQR, manual WAV/PCM parse). Nothing is simulated with timers.
2026-09-26 · Node 20 — same engine code, executed server-side — 24 of 24 passed
Base64 Unicode round trip · CSV quoting/newlines/Unicode/safe-prefix · CSV→JSON leading zeros · invoice discount/tax rounding (minor units) · SHA-256 known-answer vector · WAV trim boundaries, channel mapping, exact sample values and mono mixdown decoded back from output bytes · ZIP round trip independently CRC-verified by fflate · deflate entries · traversal/absolute/backslash/drive-letter entries skipped · encrypted + symlink entries skipped · CRC mismatch rejected · declared-size lies and a mini zip bomb aborted mid-inflation · per-file/total/count caps enforced · duplicate names uniquified · truncated archive rejected · cancellation honoured · PDF range parsing · merge order and page sizes verified by PDF.js · extract selection and order · split by ranges · organize delete/reorder · rotation metadata · watermark placement (text on selected pages only) · page numbers per page · pdf-lib→PDF.js cross-reader text · QR payloads (URL, Wi-Fi escaping, SMS, Unicode) decoded byte-exactly by the independent jsQR decoder.
- No third-party advertising or analytics scripts load anywhere in the app today, so file-processing pages are isolated from ad scripts by construction.
- The Node run proves the pure engines; browser-only paths (image engines, HEIC decode, PDF rendering, canvas QR) still need an in-browser run — the Run verification button covers them.
- Tests run on demand in the user's browser — a passing run is evidence for that browser and device only.
- No automated CI and no real-device matrix (iOS Safari, Android Chrome) has been executed yet.
- Image work runs on the main thread; very large batches may stutter (documented, not yet workerized). Decoded pixels are capped (60 MP images, 40 MP PDF renders).
- WAV-only audio conversion is partial support, not MP3 support.
Platform capability matrix
| Capability | State | Notes |
|---|---|---|
| Public anonymous use | verified | App is public; every working tool runs without an account. |
| Browser processing (Canvas, Web Crypto, Web Audio) | verified | Used by all working tools. Output types are checked against real file signatures. |
| Web Workers | verified | PDF rendering runs in a PDF.js worker; regex runs in a disposable worker with a 2 s limit. Image work runs on the main thread in short batches (browsers vary; no OffscreenCanvas path yet). |
| WASM engines | verified | HEIC photos decode via libheif compiled to WebAssembly, in-browser. PDF and QR engines are pure JS. |
| CSP & cross-origin isolation headers | unverified | Not controllable from app code as built. Needed for multithreaded FFmpeg WASM. |
| Private storage & signed downloads | implemented | Wired for the Transfer tools: files upload to private storage and download through short-lived signed URLs. Runtime-unverified until a browser verification run covers it. |
| Job scheduling / cleanup | implemented | A nightly scheduled workflow purges expired transfer sessions. |
| Realtime transfer updates | implemented | Open transfer pages poll the transfer service every few seconds, so an open page updates live with per-file arrival times. Transfers relay through platform storage — no TURN or signaling service is needed. |
| Admin console & activity logging | implemented | Console at /admin (admin accounts only): every transfer and inbox with live previews, block/flag/delete controls, and an activity feed with server-seen IP logging. Local-only tool runs are not logged — they never leave the visitor’s device. |
| Atomic counters & unique constraints | unverified | Record updates are read-then-write. Quotas, download grants and shared document numbers need a transactional service. |
| Stripe checkout & webhooks | unverified | Possible through server functions with signature checks; not configured. No payments are taken. |
| Route rendering / SEO | unverified | Single-page app. Titles and descriptions are set in the browser; no prerendering, sitemap, or real 404 status. |
| Malware scanning | needs external service | Needs an external scanner. Cloud sharing stays disabled without it. |
Configuration checklist
| Needed | Unlocks | Without it |
|---|---|---|
| Media worker or FFmpeg WASM + isolation headers | Tools 37–39, 43, MP3 output | Blocked |
| OCR / DOCX conversion provider keys | Tools 17–19 | Blocked |
| Stripe keys + approved price IDs | Pro / Business plans | No billing — everything shown is free |
Tool catalog (60 entries)
| # | Tool | Category | Where it runs | Status | Formats / blocker |
|---|---|---|---|---|---|
| 1 | Device-to-device transfer | Transfer | Cloud | Implemented · not yet verified | Any files in · download out — Files are uploaded to ToolDock’s private storage — only someone with the code can download them, and the transfer expires after 10 minutes. |
| 2 | Send text & links between devices | Transfer | Cloud | Implemented · not yet verified | Text in · text out — Held on the ToolDock platform — only someone with the code can read it. Expires after 10 minutes. |
| 3 | Temporary share links | Transfer | Cloud | Implemented · not yet verified | Any files in · download out — Anyone with the link or code can download until the transfer expires (10 minutes). |
| 4 | File collection inbox | Transfer | Cloud | Implemented · not yet verified | Any files in · download out — Files land in ToolDock’s private storage. Inboxes stay open for 30 days. |
| 5 | Merge PDFs | On device | Implemented · not yet verified | PDF in · PDF out | |
| 6 | Split PDF | On device | Implemented · not yet verified | PDF in · PDF out | |
| 7 | Extract PDF pages | On device | Implemented · not yet verified | PDF in · PDF out | |
| 8 | Delete & reorder PDF pages | On device | Implemented · not yet verified | PDF in · PDF out | |
| 9 | Rotate PDF pages | On device | Implemented · not yet verified | PDF in · PDF out | |
| 10 | Images to PDF | On device | Implemented · not yet verified | JPG, PNG, WebP in · PDF out | |
| 11 | PDF to images | On device | Implemented · not yet verified | PDF in · PNG or JPG out | |
| 12 | Compress PDF | On device | Implemented · not yet verified | PDF in · PDF out — Rasterized output only — text stops being searchable, forms and vectors are lost. Disclosed before processing. | |
| 13 | PDF under a target size | On device | Implemented · not yet verified | PDF in · PDF out — Rasterized output only. Shows "Target not reached" with alternatives when it can't hit the limit. | |
| 14 | Watermark PDF | On device | Implemented · not yet verified | PDF in · PDF out | |
| 15 | Add page numbers | On device | Implemented · not yet verified | PDF in · PDF out | |
| 16 | Extract PDF text | On device | Implemented · not yet verified | PDF in · TXT out — Embedded text only — scanned pages have none. OCR is a separate, unavailable capability. | |
| 17 | OCR — scans to text | Cloud | Blocked | Needs an OCR engine (Tesseract WASM with language data, or a configured OCR provider). Not configured. | |
| 18 | PDF to Word (DOCX) | Cloud | Blocked | Needs a real layout-aware conversion service. Not configured. | |
| 19 | Word (DOCX) to PDF | Cloud | Blocked | Needs a server document renderer (LibreOffice in an isolated worker, or a conversion provider). Not configured. | |
| 20 | Add a visual signature | On device | Implemented · not yet verified | PDF in · PDF out | |
| 21 | JPG to PNG | Images | On device | Implemented · not yet verified | JPG in · PNG out |
| 22 | PNG to JPG | Images | On device | Implemented · not yet verified | PNG in · JPG out |
| 23 | WebP to JPG or PNG | Images | On device | Implemented · not yet verified | WebP in · JPG or PNG out |
| 24 | JPG/PNG to WebP | Images | On device | Implemented · not yet verified | JPG, PNG in · WebP out (browser must support WebP encoding) |
| 25 | HEIC to JPG/PNG | Images | On device | Implemented · not yet verified | HEIC/HEIF in · JPG or PNG out |
| 26 | Resize image | Images | On device | Implemented · not yet verified | JPG, PNG, WebP, GIF, BMP in · same format out (GIF/BMP → PNG) |
| 27 | Compress image | Images | On device | Implemented · not yet verified | JPG, PNG, WebP, GIF, BMP in · JPG, PNG or WebP out |
| 28 | Image under a target size | Images | On device | Implemented · not yet verified | JPG, PNG, WebP, GIF, BMP in · JPG or WebP out |
| 29 | Crop image | Images | On device | Implemented · not yet verified | Same format out (GIF/BMP → PNG) |
| 30 | Rotate & flip image | Images | On device | Implemented · not yet verified | Same format out (GIF/BMP → PNG) |
| 31 | Watermark image | Images | On device | Implemented · not yet verified | Same format out (GIF/BMP → PNG) |
| 32 | Remove image metadata | Images | On device | Implemented · not yet verified | JPG, PNG, WebP in · same format out |
| 33 | Inspect image | Images | On device | Implemented · not yet verified | Any image file |
| 34 | Social media image resizer | Images | On device | Implemented · not yet verified | JPG/PNG/WebP out |
| 35 | Remove background | Images | On device | Blocked | Needs a licensed segmentation model running locally, or a configured background-removal provider. |
| 36 | Color picker & palette | Images | On device | Implemented · not yet verified | JPG, PNG, WebP, GIF, BMP |
| 37 | Compress video | Video & Audio | Cloud | Blocked | Needs a verified media engine — FFmpeg WASM (requires cross-origin isolation headers) or a managed transcoding worker. Not configured. |
| 38 | Convert video to MP4 | Video & Audio | Cloud | Blocked | Needs a verified media engine — FFmpeg WASM (requires cross-origin isolation headers) or a managed transcoding worker. Not configured. |
| 39 | Trim video | Video & Audio | Cloud | Blocked | Needs a verified media engine — FFmpeg WASM (requires cross-origin isolation headers) or a managed transcoding worker. Not configured. |
| 40 | Extract audio from video | Video & Audio | On device | Partial · not yet verified | MP4, WebM, MOV in (depends on your browser) · WAV out — WAV output only — MP3 needs an encoder that is not installed. |
| 41 | Convert audio to WAV | Video & Audio | On device | Partial · not yet verified | MP3, WAV, OGG, M4A, FLAC in (depends on your browser) · WAV out — WAV output only — MP3 needs an encoder that is not installed. |
| 42 | Trim audio | Video & Audio | On device | Implemented · not yet verified | MP3, WAV, OGG, M4A, FLAC in (depends on your browser) · WAV out |
| 43 | Video to GIF | Video & Audio | Cloud | Blocked | Needs a verified media engine — FFmpeg WASM (requires cross-origin isolation headers) or a managed transcoding worker. Not configured. |
| 44 | Word & character counter | Text & Data | On device | Implemented · not yet verified | Text |
| 45 | Text case converter | Text & Data | On device | Implemented · not yet verified | Text |
| 46 | Remove duplicate lines | Text & Data | On device | Implemented · not yet verified | Text |
| 47 | Sort lines | Text & Data | On device | Implemented · not yet verified | Text |
| 48 | Find and replace | Text & Data | On device | Implemented · not yet verified | Text |
| 49 | JSON formatter & validator | Text & Data | On device | Implemented · not yet verified | Text |
| 50 | JSON ⇄ CSV converter | Text & Data | On device | Implemented · not yet verified | JSON or CSV text / files |
| 51 | URL encode / decode | Text & Data | On device | Implemented · not yet verified | Text |
| 52 | Base64 encode / decode | Text & Data | On device | Implemented · not yet verified | Text |
| 53 | Password generator | Text & Data | On device | Implemented · not yet verified | Generated text |
| 54 | UUID generator | Text & Data | On device | Implemented · not yet verified | Generated text |
| 55 | SHA-256 file checksum | Text & Data | On device | Implemented · not yet verified | Any file |
| 56 | QR code generator | Text & Data | On device | Implemented · not yet verified | Text in · PNG + SVG out |
| 57 | Create & open ZIP | Text & Data | On device | Implemented · not yet verified | Any files in · ZIP out / ZIP in · files out — Created ZIPs store files without compression. Extraction blocks path-traversal entries and enforces size/count caps before inflating. |
| 58 | Invoice generator | Business | On device | Implemented · not yet verified | Form in · PDF out |
| 59 | Estimate / quote generator | Business | On device | Implemented · not yet verified | Form in · PDF out |
| 60 | Receipt generator | Business | On device | Implemented · not yet verified | Form in · PDF out |
Next steps
- Run the in-browser verification suite on each supported browser, and add automated fixture tests per tool.
- Move image processing to OffscreenCanvas workers where the browser supports it.
- Malware scanning for shared files, accounts and entitlements as cloud features grow.
- Media worker for video tools; transfer history and contacts.
- Billing, entitlements and the admin console once cloud features exist.
- Public SEO pages, sitemap and canonical URLs.