Ross ROSS = Recommend OSS · open-source software intelligence for agents

wiire-a/pixiewps

An offline Wi-Fi Protected Setup brute-force utility observed · 2026-08-28

github.com/wiire-a/pixiewps · C · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

57/100

  • Activity 77
  • Release rhythm 8
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4171
  • days_rel: n/a
  • days_push: 138
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1740 stars · 324 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Pixiewps is a C command-line utility that brute-forces Wi-Fi Protected Setup (WPS) PINs offline, exploiting low- or non-entropy software implementations via the 'pixie-dust attack'. On vulnerable routers it can recover the PIN in seconds or minutes rather than the hours required by online tools, and since version 1.4 it can also recover the WPA-PSK from a complete passive capture for some devices.

Use cases

  • recover a WPS PIN offline from a vulnerable router
  • run a pixie dust attack against a WPS-enabled access point
  • audit whether my router's WPS implementation has low entropy
  • perform WPS security testing during an authorized Wi-Fi penetration test
  • extract the WPA-PSK passphrase from a complete passive WPS capture (M1 through M7)
  • crack WPS PINs in seconds instead of hours-long online brute-force

When to choose

  • auditing WPS-enabled routers for the pixie-dust vulnerability in authorized penetration tests
  • you need offline PIN recovery in seconds or minutes instead of the hours required by online brute-force tools
  • recovering WPA-PSK from a full passive capture on supported devices using --mode 3

When to avoid

  • you need to capture the WPS exchange itself - Pixiewps only computes the PIN offline and relies on tools like Reaver or Bully (with modified options) to gather the PKE, PKR, hashes, and nonces
  • targets not vulnerable to pixie-dust require traditional online attacks, which this tool does not perform
  • you need a graphical tool or native Windows binary - it is a C program built with make targeting Linux with POSIX threads
  • any use against networks you do not own or lack explicit permission to test

Facets

cli-tool · maturity active

security penetration-testing cryptography security penetration-testing networking cli wps pixie-dust-attack wifi-security bruteforce offline-attack wpa-psk wireless-pentesting kali-linux wifi-hacking hacking-tool command-line linux

1 source

Member repositories

RepositoryRoleHealth v2
wiire-a/pixiewpsmain57

For agents

markdown · JSON · MCP: product_card(name="wiire-a/pixiewps")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem