mrkeyoor.com_
Tue 29 Sept 15:34 UTC
Dev Toolsevaluationupdated 29 Sept 2026

kordoc review

The primary documentation is Korean, and a separate English README exists. Kordoc parses Korean HWP and HWPX files alongside PDF and Office documents, then exposes conversion, comparison, form filling, redaction, generation, and rendering through TypeScript, a CLI, or MCP.

Verdict

Our Kordoc run passed all 2,608 tests and npm audit found 0 known vulnerabilities, which makes it an unusually verifiable option for HWP work despite the 1,384 MB install. Use it when Korean document formats are the hard requirement and you can test representative files before rollout. For scientific DOCX conversion or a small deployment image, the current format bugs and dependency footprint are reasons to wait or choose a narrower parser.

We ran it

Lab card: what happened when we ran kordocScreenshot of kordoc (www.npmjs.com/package/kordoc)
Install✓ · 53s254 packages · 1384 MB
Build✓ · 17s
Tests✓ · 126s2608 passed · 0 failed of 2608 (node:test)
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo639 files~112,822 lines of source · 13 MB · 2 CI workflows · tests dir

Answers from our run

Does kordoc build from source?

Dependencies installed in 53 seconds (254 packages), and the build succeeded in 17 seconds. We cloned commit bb71f7f into a clean Debian container with 3 CPUs and no project-specific setup.

Do kordoc's tests pass?

Yes: 2608 of 2608 passed when we ran the project's own test command (node:test). Some failures need services or credentials a bare container does not have.

Does kordoc have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use kordoc?

Scientific DOCX pipelines that cannot tolerate misplaced formulas or missing symbols: issues 104 through 107 document current equation, bidirectional text, and Symbol-font losses.

What are the alternatives to kordoc?

MarkItDown, Docling, Unstructured. Our Kordoc run passed all 2,608 tests and npm audit found 0 known vulnerabilities, which makes it an unusually verifiable option for HWP work despite the 1,384 MB install.

Setup3/5Simple Node install, but 1,384 MB and optional models add weight
Docs5/5Detailed Korean guide, English README, API tables, and fixtures
Community4/52,284 stars with same-day releases and detailed issue reports
Maturity4/52,608 tests pass, though several DOCX fidelity bugs remain open

Who it’s for

Korean public-sector teams that need to turn HWP or HWPX records into Markdown and structured blocks.
Developers building document comparison, form filling, redaction, or RAG ingestion in Node.
Claude Code and MCP users who need local document tools rather than a hosted conversion API.
Archives that need HWP 3.x, HWP 5.x, and HWPX support in one package.

Who it’s NOT for

Scientific DOCX pipelines that cannot tolerate misplaced formulas or missing symbols: issues 104 through 107 document current equation, bidirectional text, and Symbol-font losses.
Workloads accepting DOCX files above 100 MB uncompressed: issue 108 says they are rejected even with images disabled.
Small serverless functions: our install used 1,384 MB after 254 packages, before optional OCR model downloads.
Teams expecting a word processor UI: Kordoc parses, generates, fills, and renders documents, but it is not an interactive WYSIWYG editor.
Layout review that depends on rendered equation objects: the README says HWPX equation rendering is not yet supported.

Setup reality

Our sandbox installed 254 npm packages in 53 seconds at commit bb71f7f, consuming 1,384 MB on disk. The build passed in 17 seconds. Node's test runner completed in 126 seconds with all 2,608 tests passing, and npm audit found 0 known vulnerabilities.

Node 20 or newer is enough for the base package. PDF and OCR dependencies install by default; omitting optional dependencies removes those features. OCR can download an approximately 18 MB model, formula OCR uses about 155 MB more, and Markdown-to-PDF printing separately needs puppeteer-core.

MCP setup can edit supported client configurations automatically. Offline deployments should pre-export models, set KORDOC_OFFLINE=1, and restrict file access with KORDOC_ROOT. Large or unusual DOCX files still need fixture testing against the current open issues.

Kordoc handles Korean formats that general converters skip

Kordoc's reason to exist is HWP. It reads HWP 3.x, HWP 5.x, HWPX, and HWPML, then turns them into Markdown plus structured blocks. It can also compare old and new versions, fill preserved forms, patch text into an original document, place a seal, redact personal data, and generate HWPX from Markdown. PDF, DOCX, XLS, XLSX, and common image formats broaden the input side.

The package exposes those jobs through a TypeScript API, CLI, and 17 MCP document tools. Its setup command can configure Claude Desktop, Claude Code, Cursor, VS Code, Codex, and other clients. This matters because an agent can work on an actual HWPX form instead of receiving pasted plain text with tables already damaged. The maintainer still tells users to review redaction before publication, a sensible boundary for official records.

The clean test run comes with a 1,384 MB install

Our fresh Debian sandbox installed 254 packages in 53 seconds at commit bb71f7f. The checked-out repository contained 639 files, about 112,822 lines of source, and occupied 13 MB before dependencies. After npm finished, the environment used 1,384 MB. There are two CI workflow files and a tests directory, but no Dockerfile. The package is easy to invoke and expensive to carry.

PDF and OCR support account for part of that weight and install by default. --omit=optional makes the footprint smaller at the cost of both features. The built-in Korean OCR can download a model of about 18 MB on first use, while formula OCR needs another model around 155 MB. Printing Markdown to PDF also requires a separate puppeteer-core install. Plan the image around the format paths you will actually enable.

What happened when we ran it

Our run built Kordoc in 17 seconds after the 53-second install. Node's test runner then completed in 126 seconds with 2,608 passed and 0 failed. Npm audit reported 0 known vulnerabilities across critical, high, moderate, and low severities. The container had 3 CPUs, 8 GB of RAM, Node 22, no secrets, and no elevated privileges.

Those results cover the repository's supplied suite, not our own corpus of government files. We did not verify the README's published PDF benchmark, OCR accuracy, or HWPX table fidelity claims. A document parser earns trust file by file because one dropped unit symbol can change meaning while the command still exits successfully. The 2,608 passing tests are a strong start, followed by fixtures from your archive and output comparisons on tables, formulas, and page boundaries.

DOCX equations and symbols still need spot checks

Five open issues on September 29 describe narrow but consequential DOCX failures. Issue 104 says inline equations move to the end of a paragraph. Issue 105 reports Symbol-font characters such as degree, multiplication, and micro signs disappearing. Issue 107 covers text lost inside bidirectional elements, and issue 106 shows malformed LaTeX around angle brackets and equation numbers. These are poor fits for unattended scientific ingestion.

Issue 108 documents a separate 100 MB uncompressed-size ceiling for DOCX packages. The parser rejects the file before reading even when images: false, so a document with heavily compressed media can hit the limit despite a small upload size. The safety reason is ZIP-bomb protection. The operational answer is to test actual large files rather than raise a reverse proxy's upload limit and assume parsing will follow.

Offline mode is useful only after models and roots are prepared

Kordoc can run without a cloud document API. KORDOC_OFFLINE=1 blocks external communication, and its model commands can export assets on a connected machine for import into an isolated network. KORDOC_ROOT restricts MCP file access to a chosen directory. Those controls suit sensitive records, provided the deployment includes every OCR model and font dependency needed before the network disappears.

Version 4.16.3 also fixed a concrete file-boundary flaw. The release notes say MCP document generation could follow a symlink inside an image directory and include a file outside KORDOC_ROOT. The shared loader now checks real paths, refuses symlink traversal for individual files, and requires ordinary files. That same-day security release is evidence of responsive maintenance, while also showing why an MCP parser deserves filesystem containment.

Same-day maintenance is active, and the format surface is young

GitHub showed 2,284 stars and 5 open issues and pull requests on September 29, 2026. Version 4.16.3 and the latest repository push both landed that day. The project began in March 2026, so a v4 label should not be read as years of stable production history. Its current issue queue is small, detailed, and tied to reproducible documents.

Kordoc is the first tool we would trial when HWP or HWPX is nonnegotiable. Our 2,608-test run and clean npm audit make that trial easier to defend. Adoption still needs a representative corpus, especially for DOCX science files, documents above 100 MB uncompressed, and generated pages containing equations. If those checks pass, the package replaces several format-specific scripts with one local interface.

Alternatives

ProjectWhat it isPick it when
MarkItDown gh↗A general file-to-Markdown converter for common office and media formats.pick this instead when mainstream formats matter and Korean HWP parsing, generation, and form filling do not.
Docling gh↗A document conversion toolkit focused on structured PDF and office extraction.pick this instead when broad document understanding and Python integration matter more than HWP workflows.
UnstructuredA Python toolkit for partitioning many document formats for search and RAG.pick this instead when an established Python ingestion pipeline matters more than Korean government document editing.
rhwp gh↗A smaller toolkit centered on reading and working with HWP files.pick this instead when your scope is narrow HWP handling and you do not need Kordoc's PDF, Office, MCP, and generation layers.

What people are saying

  1. [github-trending] chrisryugj/kordoc

Sources

  1. Kordoc README
  2. Kordoc English README
  3. Release v4.16.3
  4. Issue 104: misplaced inline DOCX equations
  5. Issue 105: missing DOCX Symbol characters
  6. Issue 108: DOCX uncompressed-size ceiling

More dev tools reviews

Kaku · hey · wechat-miniapp-radar · omarchy-workspace-layout · fermats-last-theorem · yjs · the whole board →