freefq/free: a scraped node list frozen in February 2024
GitHub describes it as 翻墙、免费翻墙、免费科学上网、免费节点、免费梯子、免费ss/v2ray/trojan节点、蓝灯、谷歌商店、翻墙梯子. This article stays within the project description and details documented in the GitHub repository README.
At a glance
- What is it?
- freefq/free has no code, no build and no releases. It is a README and a v2 file holding third-party v2ray endpoints that the operator crawled off the open web. What makes it worth reading is what that arrangement tells you about trusting it.
- Who is it for?
- Treat freefq/free as a sample of what circulated in early 2024 rather than as infrastructure you can rely on. It fits someone comparing free node formats and import mechanics, or looking for a concrete example of a public list whose entries were never authenticated.
- Can I use it commercially?
- Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
- Is it still maintained?
- Probably not. The repository last received commits 25 months ago, on August 20, 2024.
- What is it written in?
- GitHub does not report a main language for this repository.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
Two entries in the repository, and one of them is a data file
The entire project fits in two paths: README.md and v2. There is no source directory, no package manifest, no build script, no test suite and no issue tracker content, and the repository has no GitHub releases, so there is no version history to inspect and nothing to pin. The default branch is master, and the last push to it was on 2024-08-20. That is the whole shape of the thing: a human-readable page of links and a flat file of endpoint URIs. There is also no license file, so the terms under which the list is published are unstated, and no homepage outside GitHub. This matters more than it would for a code project, because a node list is a list of addresses. If the operator decides to stop, there is no changelog, no release note and no archived version to fall back to.
The list is crawled, and the README admits it in one line
The second line of the README is the whole risk profile: all free nodes are crawled from the internet, and the text asks readers not to use them for illegal purposes. Nothing is claimed about provenance, ownership or consent, because none of that is knowable to a crawler. The endpoints belong to machines operated by people who did not publish them for this purpose, which has two direct consequences. First, an address in the list can be reassigned between crawls, so a working entry today may be an unrelated host tomorrow and you would have no way to tell from the URI alone. Second, because the list is public on GitHub, every reader is using the same handful of addresses, so any observer who knows the list can watch who connects to them. A public free node list is a shared secret that is not secret.
Two years of silence, and the README carries its own timestamp
The README states its own update time at the top, in Chinese, as 2024-02-07 04:00. That is the date the node list was last refreshed, and it is distinct from the 2024-08-20 date of the last commit, which may be a copy edit rather than new nodes. Nothing in the repository schedules a refresh, so there is no mechanism that would tell you the list has rotted; you have to read the date yourself. The related search terms around this project are the giveaway about how such lists are consumed: free Clash, free V2ray server, free Clash VPN profile, V2ray-core, Vless. People are looking for a working configuration, and this repository hands them a snapshot with an expiry date written at the top of the page.
The import instructions depend on the page containing nothing but URIs
Batch import into the Windows client is a four-step gesture, and step one is the tell. Select all on the web page with CTRL+A, copy with CTRL+C, right-click the v2rayN client icon in the taskbar, then left-click the option to import a batch of URLs from the clipboard. Select-all-then-copy works only if the page body is essentially nothing but endpoint URIs, because the client will try to parse every line it receives. Add a heading, a note or a blank promotional line to the page and the batch import breaks, which is why forks and reposts of this kind of list so often break the very workflow they document. The tutorial link points at github.com/freefq/tutorials for the v2rayN walkthrough, a separate repository from this one.
Client links are pinned to one architecture and one build
The README hands out direct download URLs rather than naming a package, and it gives the refresh endpoint as a third URL. These are the three addresses it contains:
https://github.com/2dust/v2rayNG/releases/download/1.6.28/v2rayNG_1.6.28_arm64-v8a.apk
https://github.com/2dust/v2rayN/releases/download/3.27/v2rayN-Core.zip
https://bulinkbulink.com/freefq/free/master/v2The Android link points at a v2rayNG apk at version 1.6.28 built for arm64-v8a, and the Windows link points at a zip called v2rayN-Core.zip at version 3.27. The architecture in the Android filename is the constraint: one CPU target, so an x86 emulator or an unusual handset is not covered by that link, and you are fetching a binary from a release URL rather than installing from an app store. The Windows link is a core archive rather than an installer, so unpacking it is your job. Both clients are third-party projects maintained elsewhere, and this repository tracks neither of their versions over time.
Refresh comes from a mirror domain, not from GitHub
Instead of telling clients to pull from raw.githubusercontent.com, the README gives a subscription URL on a separate host: https://bulinkbulink.com/freefq/free/master/v2. A subscription URL is a pull the client performs on a schedule, which is convenient and also means the endpoint list you are about to trust is delivered by a domain that is not GitHub and is not the person who wrote the README. If that domain lapses, changes hands, or starts serving something other than the node list, your client keeps fetching it and you have no checksum, no signature and no second source to compare against. The same operator runs bulink.xyz, where accounts can be registered for a monthly 5G of self-built node traffic with no daily check-in, and a mirror at burstlinker.com that is described as reachable without a proxy. The account route is circular in an instructive way: registering on the main site requires a working proxy first.
What the v2 file reveals once the base64 is decoded
The v2 section of the README shows the entry format: one ss:// URI and vmess:// URIs whose payload is base64-encoded JSON. Decoding the first vmess payload gives a configuration whose fields include add, id, net, port, host, path, tls, type, security, skip-cert-verify and sni. The connection is a websocket on port 443, and skip-cert-verify is set to true, which tells the client to accept any certificate for that connection and leaves the traffic open to interception by whoever answers. The ps field is a remark, not a setting, and in the sample it carries the operator's own label naming this repository. So the file is a machine-readable config format, not an opaque token, which is good for understanding and bad for privacy: every field is readable by anyone holding the list.
Editorial conclusion
Treat freefq/free as a sample of what circulated in early 2024 rather than as infrastructure you can rely on. It fits someone comparing free node formats and import mechanics, or looking for a concrete example of a public list whose entries were never authenticated. It does not fit anyone who needs a working tunnel, a privacy guarantee or a provider they can hold accountable, because the endpoints belong to strangers, the data has not been touched since a push on 2024-08-20, and there is no license, no code and no release history behind it. Before you route anything through a list like this, find out who runs the machine at the other end, and decide what you are willing to have that operator observe.
Frequently asked questions
What does the freefq/free repository actually contain?
Two top-level paths, README.md and v2. There is no source code, no build system and no GitHub releases, and no license file. The content is a page of instructions plus a flat file of v2ray endpoint URIs scraped from the open web.
How do I import the nodes from freefq into v2rayN on Windows?
Select all on the page with CTRL+A, copy with CTRL+C, right-click the v2rayN icon in the taskbar, and choose the option to import a batch of URLs from the clipboard. For the guided walkthrough the README links to the separate freefq/tutorials repository.
How current are the free nodes in freefq/free?
The README states an update time of 2024-02-07 04:00 for the node list, and the master branch received its last push on 2024-08-20. Nothing in the repository refreshes the list automatically, so the date at the top of the page is the only freshness signal a reader gets.
Does freefq/free require an account to use the free nodes?
The page itself is public and needs nothing. Registering on bulink.xyz is described as optional, and it requires a working proxy to reach, while the burstlinker.com mirror is described as not requiring one. That account adds a monthly 5G of self-built node traffic with no daily check-in.