# WPeGPT puts an LLM inside IDA, and tells you to downgrade urllib3 when the proxy misbehaves

> A binary analysis plugin that ships pseudocode to a model and writes comments back into IDA. Its feature list includes PoC generation attempts, its proxy troubleshooting advice pins urllib3 to a 2021 release, and its changelog skips two versions.

**WPeace-HcH/WPeGPT** — An IDA plugin for binary file analysis, powered by AI models such as OpenAI and DeepSeek.

- Repository: https://github.com/WPeace-HcH/WPeGPT
- Stars: 1,423 · Forks: 195
- Language: Python
- License: not declared
- Published: 2026-09-14 · Updated: 2026-09-14 · Language: en
- Canonical page: https://hysenlabs.com/projects/wpeace-hch-wpegpt

## Exploit generation is on the feature list, so authorisation is the first question

Five interactive capabilities are documented: function analysis, variable rename, Python restore for small functions such as XOR decryption, vulnerability finding, and exploit generation, described as an attempt to generate a PoC exploit for vulnerable functions. The automated side adds network IoC extraction, which pulls out IPs, domains, URLs, and ports, and is described as auto-detecting and attempting to decrypt encrypted C2 addresses.

Read that list as a scope statement rather than a workflow. This is an IDA plugin: it reads decompiled pseudocode out of the database you already have open and writes analysis results back as IDA comments, and v3.0 adds a report folder. It does not ship a target list, a delivery mechanism, or anything that runs against a machine. That is what makes it legitimate to read and illegitimate to point at someone else's system, and the boundary is ownership of the binary, not the tool.

The project's own framing is lighter than the feature list. It states that AI analysis results are for reference only. The automated pipeline has three phases, global scan then critical path then full scan, and three modes with published durations: light at roughly two to five minutes for a global scan plus critical path analysis, full at roughly ten to thirty minutes, and vuln at roughly five to twenty minutes.

## Two of the three latest release titles still carry the old name

The project was renamed. A note at the top of the page says WPeChatGPT has been renamed to WPeGPT starting from v3.0 with a complete architectural redesign, and adds that existing installations are unaffected.

The release list has not caught up. Of the three most recent releases, v3.0 is titled WPeGPT v3.0 and is dated 2026-05-27, while v2.7 dated 2025-12-09 is titled WPeChatGPT v2.7 and v2.6 dated 2025-02-17 is titled WPeChatGPT v2.6. Two of three recent tags are named after a product that no longer exists.

That matters more than a stale string. The automated architecture introduced at v3.0 splits the plugin into WPeGPT.py, config.py, and wpe_ai_controller.py, and installs by copying WPeGPT.py plus the WPeGPT_Config/ folder into IDA's plugins directory. Someone picking a version by reading release titles would conclude that WPeChatGPT v2.7 is a different product from WPeGPT v3.0 rather than the previous version of the same one, and that the two trees have the same shape. The newest commit is dated 2026-05-27, the same day as v3.0.

## The changelog table skips 2.2 and stops before 2.7

There is an update history table going back to version 1.0 on 2023-02-28, and it has two gaps you can see without leaving the page.

The first is a missing version. The table runs 1.0, 1.1, 1.2, 2.0, 2.1, then jumps to 2.3 on 2023-04-23. There is no 2.2 row, so either that version was never published or the row was never written. The second gap is at the other end: the table ends at 2.6 on 2025-02-17 and then goes to 3.0, while the release list contains a v2.7 tag dated 2025-12-09. A tag exists for a version the table does not describe.

The rows themselves are unusually honest, which makes the gaps more noticeable. Version 1.2 carries the note that the upload was not tested due to OpenAI server lag. Version 2.0 records switching to gpt-3.5-turbo. Version 2.3 notes that anytree is now needed from that version on. Version 2.6 documents DeepSeek support by setting PLUGIN_NAME to WPeChat-DeepSeek and filling model_api_key, with DeepSeek-V3 as the default and deepseek-reasoner as the alternative. So the detail is there for six releases and missing for two.

## Configuration is a Python file you copy into IDA's plugins folder

There is one dependency step and one copy step. The dependency install is:

```bash
pip install -r ./requirements.txt
```

The plugin itself is installed by copying two things into your IDA plugins directory: WPeGPT.py and the WPeGPT_Config/ folder, then restarting IDA. The page insists that IDA be configured to use Python 3.

Configuration happens by editing WPeGPT_Config/config.py directly. Four keys are named: API_KEY, API_BASE_URL, MODEL, and ZH_CN, which is set to True for Chinese and is the default, or False for English. Three more are offered as optional: ANALYSIS_MODE, MAX_WORKERS, and other options that are not itemised. So the settings surface is source code that you copy into another program's directory and then edit in place, and a meaningful part of it is described only as other options.

The interactive side is reachable three ways. Four keyboard shortcuts are documented, Ctrl+Alt+G for function analysis, Ctrl+Alt+R for renaming function variables, Ctrl+Alt+E for vulnerability finding, and Ctrl+Alt+W for light auto analysis. You can also right-click in the pseudocode window or use Edit then WPeGPT in the menu bar. Python restore and exploit generation have no listed shortcut, so they are reachable only through the menu or the context menu.

## The documented proxy fix is a urllib3 downgrade to 1.25.11

There is a section on OpenAI API errors, and it opens by telling you to check your urllib3 version: v1.26 is said to have known proxy issues. The fix it gives is:

```bash
pip uninstall urllib3
pip install urllib3==1.25.11
```

That is a downgrade across a version line, not a patch bump, and it is pinned to an exact release rather than a compatible range. Anyone who follows it is removing a version that came out years later to work around a proxy bug, in a project whose whole point is sending decompiled code to a hosted API.

The rest of the section is more careful. It offers two alternatives: configure FORWARD_PROXY in config.py, with http://127.0.0.1:7890 given as the example value, or use a reverse proxy by setting API_BASE_URL. Both keep the installed library untouched. The page presents the downgrade first and the two configurable options after, and the downgrade is the one expressed as a command to run.

## requirements.txt pairs an old openai floor with an unpinned httpx

The entire dependency file is two lines:

```
openai >= 0.27.0
httpx
```

One floor with a version, one package with nothing at all. That pairing is the kind of thing worth pausing on, because the openai client library changed its HTTP stack partway through its own version line, and 0.27.0 sits before that change while httpx belongs to the stack that came after it. The changelog records the moment the project noticed: version 2.5, dated 2024-08-07, added support for the new version of the python openai package and told users they needed to update their openai package.

So the file allows an openai release that predates httpx while installing httpx at whatever version happens to be current, and it places no upper bound on either. There is no pinned requirements file in the six root entries, which are IMG/, README.ZH_CN.md, README.md, WPeGPT.py, WPeGPT_Config/, and requirements.txt itself. The result is that two installations a month apart can end up on different client libraries from the same command.

## WPeServer opens a TCP port inside IDA, with no port, bind address, or authentication given

Version 3.0 introduced an embedded TCP server, WPeServer, that lives inside IDA and accepts commands from an external controller, and it is described as supporting multiple concurrent IDA instances. That is the whole of the automation story on this page.

What the page does not give is any of the parameters that matter for a listening socket. No port number appears, no bind address appears, and nothing describes how a connecting controller is authenticated. With multiple instances supported, each IDA process can be a listener. This is the piece to examine before enabling the automated modes on a shared or untrusted machine, and none of the answers are on the page.

There are also two ways to drive it. One is the wpegpt-analyzer Skill, which lives in a separate repository, and the other is Auto-WPeGPT under Edit then WPeGPT in the menu bar. Either way, output lands in a folder named after the binary plus _WPeAI_Results, holding both JSON and Markdown reports. The string classification step is documented as sorting strings into ten categories, including antianalysis, dropper, and code execution, and the suspiciousness scoring ranks functions by keyword matching, caller and callee relationships, size, and stdlib filtering.

## Conclusion

WPeGPT fits a reverse engineer or malware analyst working on binaries they are authorized to analyse, who wants model assistance inside IDA rather than a separate tool, and who will pin their own dependency versions instead of taking the page's word. It does not fit anyone who needs an exploit-generation feature pointed at a system they do not own, and it does not fit a machine where you cannot afford an old urllib3. Before running it, confirm you are authorised for the binary in front of you, read the plugin configuration file before you copy it into IDA, and ignore the urllib3 downgrade advice in favour of fixing the proxy path or pinning versions you have audited.

## FAQ

### What is WPeGPT and what does it do inside IDA?

It is an IDA plugin that sends decompiled pseudocode to an AI model and writes the analysis results back as IDA comments. It supports OpenAI, DeepSeek, and any OpenAI-compatible API, and offers function analysis, variable rename, Python restore, vulnerability finding, and exploit generation attempts.

### How do I install the WPeGPT IDA plugin?

Run pip install -r ./requirements.txt, edit WPeGPT_Config/config.py to set API_KEY, API_BASE_URL, MODEL, and ZH_CN, then copy WPeGPT.py and the WPeGPT_Config/ folder into the IDA plugins directory and restart IDA. IDA must be configured to use Python 3.

### Which analysis modes does WPeGPT v3.0 offer and how long do they take?

Three. Light does a global scan plus critical path function analysis in about two to five minutes, full adds full function analysis at about ten to thirty minutes, and vuln does critical path function vulnerability analysis at about five to twenty minutes.

### Where does WPeGPT save its analysis results?

Structured JSON and Markdown reports go to a folder named after the binary plus _WPeAI_Results. The automated path is driven through WPeServer, a TCP command server inside IDA, or through Auto-WPeGPT from the Edit menu.

## Sources

- [Issues](https://github.com/WPeace-HcH/WPeGPT/issues)
- [README](https://github.com/WPeace-HcH/WPeGPT/blob/main/README.md)
- [Releases](https://github.com/WPeace-HcH/WPeGPT/releases)
- [WPeace-HcH/WPeGPT on GitHub](https://github.com/WPeace-HcH/WPeGPT)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/wpeace-hch-wpegpt
