30 August 2026
What travels
inside a ZIP
Archives are assembled by dragging a folder. Whatever was in that folder goes too, including the files your operating system put there without telling you.
30 August 2026
Archives are assembled by dragging a folder. Whatever was in that folder goes too, including the files your operating system put there without telling you.
A ZIP is made by selecting a folder and compressing it. The mental model is “the files I put in there”. The reality is everything the folder contains, including the parts that are hidden from view in every file browser by default.
On macOS, .DS_Store records every file that was in the folder when you last looked at it, including ones you removed before sending. Windows leaves Thumbs.db, which holds small copies of images that were there. Editors leave .swp and files ending in a tilde, which are usually the previous version of the document sitting beside it. None of these appear when you look at the folder.
If the folder came from development work, the risk changes character. A .env file holds API keys and database passwords in plain text. A .git directory contains the entire history of the project, including anything committed and later deleted — removing a password in a later commit does not remove it from the history. Files ending in .pem or named id_rsa are private keys, and a private key in someone else's hands is the access it was issued for.
Then there is the ordinary content. A folder of photographs carries the coordinates of wherever each one was taken. A proposal in the folder carries its author, its editing time, and possibly tracked changes. Zipping does not remove any of that; it just puts it out of sight behind one filename.
The checker on this site reads archives: it lists what is inside, flags the file types that should not be in there, and looks inside the images and documents it finds to report what those carry. It runs in your browser, so a ZIP full of client work is not uploaded anywhere in order to be checked.