$npx skillfedfor your agent

pcodedmp

A VBA p-code disassembler

With conditionsPyPI UtilitiesReleased Jul 20197.6M downloads / moGPLPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pcodedmp-1.2.6-py2.py3-none-any.whl
v1.2.6 · released 2019-07-30 · 2 runtime deps: oletools, win-unicode-console

Yes, with conditions. Install if you need to analyze VBA p-code in legacy Office documents (Office 97–2009) or conduct DFIR work on macro-based malware. The low install friction and lack of known vulnerabilities make it safe to add. However, do not rely on it for modern Office versions (2010+) without testing—the package is abandoned and has known disassembly gaps in 64-bit Office 2016. For current macro analysis, consider pairing it with actively maintained tools.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires an OLE2-format Office document (Word, Excel, etc.
  • with embedded VBA); modern Office formats (.docx, .xlsx) use different structures and are not supported.
  • Low friction installation with only two runtime dependencies (oletools and win-unicode-console).

License · maintenance · safety

GPL (copyleft) — Licensed under GPLv3 (copyleft). Any derivative work or distribution must also be open-source under GPL v3 terms. This is a strong copyleft restriction suitable for security research and analysis tools but may constrain commercial or proprietary use.

last release 2019-07-30 (2572 days) · last repo commit 2021-06-12 · 490 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 7,645,131 downloads/mo, #1,710 on PyPI

Verify before relying

pip install pcodedmp
python -m pcodedmp document.doc
# or programmatically:
from pcodedmp import pcodedmp
pcodedmp.processFile('document.doc')
  • Whether the package correctly handles all VBA7 (Office 2010+) p-code variants, given known limitations in 64-bit Office 2016 disassembly.
  • Current compatibility with modern Python versions beyond 3.6, since classifiers list only up to 3.6.
  • Whether oletools dependency has received security updates since pcodedmp's last release.
Same gist for agents: .md · .json

What it is and what it does

pcodedmp is a command-line tool and Python library that extracts and disassembles VBA p-code from Microsoft Office documents. VBA macros exist in three executable forms—source code, p-code (pseudo-code for a stack machine), and execodes—but p-code is what actually runs most of the time. Many DFIR and antivirus tools only inspect the source code form, which can be removed while leaving p-code intact and executable. This tool fills that gap by parsing OLE2 document streams and converting p-code instructions into human-readable assembly-like output, making it possible to analyze what a macro will actually do even when source code is hidden or absent.

The tool supports VBA5 (Office 97–98), VBA6 (Office 2000–2009), and VBA7 (Office 2010+). It can process single files or recursively scan directories, and offers options to dump raw stream contents, display variable and function identifiers, or focus only on disassembled p-code. Output can be sent to stdout or saved to a file. However, the package is no longer maintained—its last commit was in June 2021 and latest release in July 2019—so it will not receive updates for newly discovered p-code variants or modern Office versions.

Use it for

  • Analyze suspicious Office documents during incident response to understand what embedded macros will execute, bypassing obfuscation or source-code removal.
  • Reverse-engineer malware samples that use VBA macros as a delivery mechanism, extracting execution logic from p-code when source is unavailable.
  • Validate macro behavior in legacy Office documents (Office 97–2009) where p-code format is stable and well-understood.
  • Supplement other macro analysis tools that focus on source code by examining the compiled form that Office actually runs.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, with conditions.

Install if you need to analyze VBA p-code in legacy Office documents (Office 97–2009) or conduct DFIR work on macro-based malware. The low install friction and lack of known vulnerabilities make it safe to add. However, do not rely on it for modern Office versions (2010+) without testing—the package is abandoned and has known disassembly gaps in 64-bit Office 2016. For current macro analysis, consider pairing it with actively maintained tools.

Install

pcodedmp on PyPI

Before you install

Low friction installation with only two runtime dependencies (oletools and win-unicode-console). However, the package is abandoned—last commit was 2021-06-12 and no releases since 2019-07-30. It remains marked Production/Stable and works with Python 2.7 and Python 3.x, but will not receive updates or security patches.

Requires an OLE2-format Office document (Word, Excel, etc. with embedded VBA); modern Office formats (.docx, .xlsx) use different structures and are not supported.

License in practice

Licensed under GPLv3 (copyleft). Any derivative work or distribution must also be open-source under GPL v3 terms. This is a strong copyleft restriction suitable for security research and analysis tools but may constrain commercial or proprietary use.

Quickstart

pip install pcodedmp
python -m pcodedmp document.doc
# or programmatically:
from pcodedmp import pcodedmp
pcodedmp.processFile('document.doc')

Verify before relying

  • Whether the package correctly handles all VBA7 (Office 2010+) p-code variants, given known limitations in 64-bit Office 2016 disassembly.
  • Current compatibility with modern Python versions beyond 3.6, since classifiers list only up to 3.6.
  • Whether oletools dependency has received security updates since pcodedmp's last release.

Package facts

LicenseGPL copyleft
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
oletoolswin-unicode-console
MaintenanceAbandoned 2,572 days since the last release
Last repo commit
First released
Downloads7,645,131 / month, #1,710 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: GNU General Public License v3 (GPLv3)Natural Language :: EnglishOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 2Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.3Programming Language :: Python :: 3.4Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Topic :: SecurityTopic :: Software Development :: DisassemblersTopic :: Utilities

Evidence: pcodedmp-1.2.6-py2.py3-none-any.whl

Tags

Capabilities
vba p-code disassemblermacro analysis office documentsvba decompilerextract vba bytecodeoffice macro inspectionvba reverse engineeringmalware macro analysis
Topics
malware-analysisreverse-engineeringdfir
PyPI keywords
vbap-codedisassembler

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “vba p-code disassembler”

  • pcodedmpDisassembles VBA p-code from Microsoft Office documents to reveal the…
  • pypcodepypcode provides machine code disassembly and intermediate…
  • xlwingsxlwings lets you call Python from Excel and vice versa, automating…

Give your agent the search over MCP, or paste the wish link into any chat.

More Utilities packages

idna Worth it
PyPI · Python Modules · released Jun 2026

Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.

Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.

BSD-3-Clausepure Python · 3.9+
1.8Bdownloads / mo
charset-normalizer Worth it
PyPI · Utilities · released Aug 2026

Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.

permissive licensepure Python · 3.7+
1.7Bdownloads / mo
setuptools Worth it
PyPI · Python Modules · released Aug 2026

Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.

MITpure Python · 3.10+
1.6Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
Pygments Worth it
PyPI · Utilities · released Mar 2026

Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.

Install it if you need to display or transform source code.

BSD-2-Clausepure Python · 3.9+
1.3Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo

See also oletools · pypcode · pcpp · capstone · msoffcrypto-tool · olefile · xdis · smda · evmdasm · cppclean