# stable diffusion webui: a Gradio front end pinned to old libraries

> AUTOMATIC1111/stable-diffusion-webui is a Python and Gradio interface for Stable Diffusion whose install lives in per-hardware wikis and whose dependencies are hard pinned to gradio 3.41.2 and transformers 4.30.2. The last commit landed on 2026-03-02 and the newest release tag is v1.10.1 from February 2025, so the deciding factor is not the feature list but whether your extensions still match the pins.

**AUTOMATIC1111/stable-diffusion-webui** — GitHub describes it as Stable Diffusion web UI. The repository metadata lists Python as its primary language. The metadata lists the AGPL-3.0 license. This article stays within the project description and details documented in the GitHub repository README.

- Repository: https://github.com/AUTOMATIC1111/stable-diffusion-webui
- Stars: 165,150 · Forks: 32,120
- Language: Python
- License: AGPL-3.0
- Published: 2026-08-13 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/automatic1111-stable-diffusion-webui

## The last commit is 2026-03-02 and the newest tag is v1.10.1

The maintenance picture matters more here than in most projects, because the extension ecosystem moves faster than the core. The last push to the repository was on 2026-03-02. The release tags are older still: v1.10.1 on 2025-02-09, v1.10.0 on 2024-07-27, and v1.10.0-RC on 2024-07-06. The default branch is master, CHANGELOG.md sits at the root, and the repository is not archived.

So the core is not being abandoned, but it is not where new work is arriving either, and the dependency pins in the tree have not moved with the ecosystem. Consequence for an operator: an extension published against a newer gradio or transformers will not simply work, and the debugging session you end up in is about version conflicts rather than about image generation. Check CHANGELOG.md and your extension's own requirements before you install anything, and expect to pin a working set rather than track the tip.

## --allow-code is the flag that decides whether the UI is a viewer

One of the advertised features is running arbitrary python code from the UI, and it is gated behind a command line flag. Read the feature list carefully: arbitrary code execution must run with `--allow-code` to enable. Nothing else about that feature is explained.

That single flag is the difference between a local tool and an open service. The default address the project configures is port 7860, taken from the pytest base_url of http://127.0.0.1:7860 in pyproject.toml, so on a normal setup the UI answers on loopback. Consequence: an extension that needs to run code will fail in a way that looks like a bug in the extension until you notice the flag was never passed, and if you do pass the flag you have a Python execution surface on a port you now have to keep off the network. Learn the flag before you need it rather than after.

## gradio==3.41.2 and transformers==4.30.2 are exact pins, not floors

requirements.txt is where this project makes its real compatibility promise, and several entries are exact. gradio is pinned to 3.41.2, transformers to 4.30.2, protobuf to 3.20.0, and pillow-avif-plugin to 1.4.3, while fastapi is a floor at 0.90.1 and scikit-image a floor at 0.19. Everything else, torch, numpy, safetensors, kornia, omegaconf, accelerate and the rest, floats.

An exact pin on the web layer is a deliberate choice with a direct cost. Any extension built against a newer gradio has to be downgraded or dropped, and protobuf 3.20.0 in particular collides with other tooling that expects a newer one. Consequence: give this tool its own environment. Sharing a virtualenv with another machine learning project means the first install that wants a newer protobuf wins the argument and the web UI stops starting.

## There is no install command on the front page, and python comes first

The Installation and Running section is a set of links, not a sequence. It asks you to meet the dependencies listed on a wiki page, then to follow instructions written for your hardware: NVidia GPUs, marked recommended, AMD GPUs, and Intel CPUs and GPUs, whose page lives on a different organization's wiki. The only install statement in the feature list is the one click install and run script, and it carries its own caveat: you still must install python and git.

The root shows what the project expects to find around that script: webui.sh and webui.bat launchers, webui-user.sh and webui-user.bat for per-user settings, a webui-macos-env.sh environment script, launch.py and webui.py, an environment-wsl2.yaml for one platform, and a requirements_npu.txt beside requirements.txt. Consequence: the launcher differs by platform and the instructions differ by vendor, so a question with no answer on this page is usually a question for the wiki for your GPU, not a bug in the repository.

## Your prompt travels inside the image, in PNG chunks or EXIF

Generation parameters are saved with the image they produced. The rule is precise: in PNG chunks for PNG, in EXIF for JPEG. You can drag an image to the PNG info tab to restore its parameters and have them copied into the interface, the same works by dragging an image onto the prompt box, a button loads parameters into the UI, and the whole behaviour can be switched off in settings.

That design is what makes a result reproducible, and it is also a metadata decision you should make deliberately. A JPEG carries the parameters in EXIF, which means the settings travel with the file into whatever reads it next, including whatever service processes the image. Consequence: if you disable parameter saving, or hand someone a converted file, the seed and prompt are gone and the result cannot be regenerated. If you leave it on, decide where those images go before you start.

## ((attention)) and uppercase AND are two different parsers, and neither is portable

The prompt field carries two independent grammars. Attention uses double parentheses, so a man in a `((tuxedo))` pays more attention to tuxedo, with `(tuxedo:1.21)` as the alternative syntax, and the Ctrl+Up and Ctrl+Down shortcuts adjust attention on a selection, with Command on macOS. Composable-Diffusion is separate: it splits prompts on an uppercase `AND` and accepts per-prompt weights, as in `a cat :1.2 AND a dog AND a penguin :2.2`.

Around them sit negative prompt, styles saved from prompt fragments, variations for the same image with tiny differences, seed resizing for the same image at a different resolution, prompt editing to change the prompt mid generation, and the X/Y/Z plot for sweeping a parameter across a grid. The tool also lifts the original limit of 75 prompt tokens. Consequence: a prompt that works here is not a portable asset. Another tool will read `((tuxedo))` as literal characters, so keep the plain version of any prompt you intend to share.

## The Extras tab bundles four upscalers, two face fixers and a preview model

The Extras tab collects models that do one job each, and the front page labels them. GFPGAN is described as a neural network that fixes faces, and CodeFormer as a face restoration tool offered as an alternative to it. Upscaling has more choices: RealESRGAN, ESRGAN with a lot of third party models, SwinIR and Swin2SR, and LDSR, which is named as latent diffusion super resolution. The live preview runs on a separate neural network with almost none VRAM or compute requirement.

The hardware claims elsewhere in the feature list sit in the same anecdotal register: 4GB video card support with reports of 2GB working, and embeddings training on 8GB with reports of 6GB working. Consequence: you are choosing between several models of different sizes and origins, each a separate download and a separate way to fail, and the front page does not say which one to reach for. The xformers option is the exception with a clear trigger, since it asks for `--xformers` on the command line for a major speed increase on select cards.

## The JavaScript side is a lint harness, and ruff skips the extension folders

The npm side of the project is minimal. package.json is named stable-diffusion-webui with version 0.0.0, a single dev dependency on eslint 8.40, and two scripts, `lint` and `fix`. There is no JavaScript build pipeline here, only a linter next to script.js, style.css and the html/ and javascript/ directories.

The Python side is more layered. pyproject.toml configures ruff with target-version py39, selects the bugbear, complexity, import and warning rules, and excludes both the extensions and extensions-disabled directories from linting entirely. webui.py carries its own per-file exemption for module level imports, and the bugbear configuration lists fastapi.Depends and fastapi.security.HTTPBasic as immutable calls so the linter leaves FastAPI's dependency injection alone. A .pylintrc sits in the root as well. Consequence: three lint configurations, and contributed extension code is deliberately outside the strictest one, so a clean lint run on the core says nothing about a third party extension.

## Conclusion

Use this web UI if you want the widest extension ecosystem for Stable Diffusion and can keep an environment built around gradio 3.41.2 and transformers 4.30.2. Do not start a new integration on it without accepting that the last commit was on 2026-03-02 and that the newest tag is v1.10.1. Verify three things before you commit: the per-hardware install page you actually need, whether your intended extension works with those pins, and what LICENSE.txt under AGPL-3.0 obliges you to do if you expose the tool to other people.

## FAQ

### How do I install the Stable Diffusion web UI?

The front page gives no command. It asks you to meet the dependencies on a wiki page and then follow instructions for your hardware, with separate pages for NVidia, marked as recommended, for AMD GPUs and for Intel CPUs and GPUs. The one click install and run script still requires you to install python and git first.

### How do I run the Stable Diffusion web UI?

The repository root carries the launchers: webui.sh and webui.bat, webui-user.sh and webui-user.bat, a webui-macos-env.sh environment script, and the Python entry points launch.py and webui.py. The local address the project configures is port 7860, taken from the pytest base_url in pyproject.toml.

### How do I update the Stable Diffusion web UI?

Check what has actually shipped: the last commit to the repository was on 2026-03-02, and the newest release tag is v1.10.1 from 2025-02-09, before v1.10.0 in July 2024. CHANGELOG.md at the root is the place to read before assuming a newer version is waiting for you.

### How do I use a LoRA in the Stable Diffusion web UI?

Loras are listed alongside hypernetworks and embeddings, described as the same idea but easier to use, and training covers hypernetwork and embedding options. A separate interface lets you choose, with a preview, which embeddings, hypernetworks or Loras to add to your prompt.

### How do I open the Stable Diffusion web UI in a browser?

It is a web interface for Stable Diffusion built with the Gradio library, so it serves a page locally once the process is running. The port the project configures for that local page is 7860.

## Sources

- [Official README](https://github.com/AUTOMATIC1111/stable-diffusion-webui#readme)
- [Project repository](https://github.com/AUTOMATIC1111/stable-diffusion-webui)
- [Release notes](https://github.com/AUTOMATIC1111/stable-diffusion-webui/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/automatic1111-stable-diffusion-webui
