mrkeyoor.com_
Mon 14 Sept 15:50 UTC
Self-Hostedevaluationupdated 14 Sept 2026

tvbox review

qist/tvbox is a Chinese-language collection of configuration files, scripts, playlists, and source lists for OK Video, TVBox, and CatVod clients. Its README is in Chinese and provides no English guide. The repository supplies feeds for compatible players; it is not a player application itself.

Verdict

Our lab found no supported runnable ecosystem and no Dockerfile for qist/tvbox, so it produced no install, build, or test evidence. Treat this as a personal, Chinese-language feed bundle for an existing client, not as deployable software. Organizations should walk away because there is no declared license, the README bars commercial use, and the external sources carry availability and account risks.

We ran it

Screenshot of tvbox (github.com/qist/tvbox)

Answers from our run

Did you run tvbox yourself?

No. Its code is JavaScript, and it carries no manifest our lab installs from, and no Dockerfile, so there was nothing standard to install, build or test. This review is written from the repository's own documentation.

Who should not use tvbox?

Companies needing a clear open-source license: GitHub reports no license, while the README restricts commercial use and redistribution.

What are the alternatives to tvbox?

FongMi TV, TVBoxOS, Box. Our lab found no supported runnable ecosystem and no Dockerfile for qist/tvbox, so it produced no install, build, or test evidence.

Setup2/5No runnable target; setup happens through a separate client and feeds
Docs2/5Many Chinese notes and warnings, but no English guide or clean flow
Community3/511,283 stars and a same-day push, with support questions still open
Maturity2/5Actively changed configuration, but sources and login state can break

Who it’s for

Chinese-reading TVBox users who already understand how to import and troubleshoot third-party configuration feeds.
Hobbyists willing to fork the repository privately and maintain their own source list.
CatVodOpen users prepared to manage a private GitHub or Gitee repository, DAV storage, and an access token.
People who can verify each stream's legality, availability, and account impact in their own location.

Who it’s NOT for

Companies needing a clear open-source license: GitHub reports no license, while the README restricts commercial use and redistribution.
Readers who need English documentation: the setup, warnings, and source descriptions are written in Chinese with no English guide.
Anyone expecting a self-contained TV app: this repository provides configurations and points users to separate clients such as FongMi/TV.
Users unwilling to risk cloud-drive account disruption: the README warns about more than 10 concurrent Aliyun connections and token sharing, while issue 93 reports lost login state after a client update.
People who need stable, verified channels: the maintainer says feed validity and timeliness are not guaranteed, and no GitHub release is published.

Setup reality

Our lab did not run qist/tvbox at commit 577412f because it found no supported ecosystem for the JavaScript repository and no Dockerfile. There are therefore no measured install, build, test, dependency, or vulnerability results.

Use starts in a separate compatible player, not at a package manager. The README lists configuration URLs and says CatVodOpen users should import through a private GitHub or Gitee repository plus DAV. Its V1.1.3-and-newer example embeds a repository token in a github:// configuration string.

Cloud-drive sources require their own tokens or login flows. The README warns about connection limits, shared tokens, storage permission, expiring sources, and proxy replacement in some configurations. Forking the files does not make the remote streams or bundled third-party components dependable.

Thirteen named feeds make a configuration shelf, not a TV app

qist/tvbox collects configurations for OK Video, TVBox, and CatVod clients. The README describes 13 numbered files or feeds, ranging from a small selection to large combinations of video-on-demand sources, live channels, parsers, and JavaScript-based providers. You bring the player; this repository tells that player where and how to look.

That distinction changes the buying decision. There is no single server or desktop program to launch, and a working configuration can depend on remote URLs maintained by unrelated people. The maintainer calls this a personal repository, asks users to fork it, and says validity and timeliness are not guaranteed.

Version 1.1.3 changes how CatVodOpen reads a private fork

For CatVodOpen, the README splits its advice around version 1.1.3. Newer clients use a github:// string that includes a token and points to dist/index.js.md5; older clients use a different Gitee path. It also says CatVodOpen supports only private repositories with DAV in this setup. That is enough to get an experienced user oriented, though it assumes familiarity with the client and its configuration screen.

Embedding an access token in a configuration URL deserves care. Scope the token to the smallest private repository permission available, keep the string out of screenshots and shared logs, and rotate it if exposed. Those are operational precautions, not features supplied by qist/tvbox. The README also says the app needs storage permission or authentication data can be lost because it cannot write to disk. On a managed device, that permission must fit the organization's policy.

What happened when we ran it

commit 577412f produced no install, build, test, dependency, or vulnerability result in the lab. The harness classified the JavaScript repository as having no supported ecosystem and found no Dockerfile. That outcome fits what the root contents show: qist/tvbox behaves as data and scripts consumed by other apps, rather than a package with a documented local build target.

The absence of a run result should not be read as a pass or a failure. We have no measured claim about whether jsm.json, any playlist, or any third-party parser worked on September 14, 2026. Validating those items would require a compatible client, network access to each source, and any required accounts. The repository's own disclaimer tells users to judge legality, accuracy, completeness, and validity for themselves, which is a larger burden than syntax checking a JSON file.

More than 10 Aliyun connections can put an account at risk

Cloud-drive integration brings account consequences. The README says Aliyun may restrict or ban accounts when accelerated use exceeds 10 concurrent connections. It describes Xunlei restrictions as stricter and warns against one token being used by several people in different locations. It also mentions 32-character token and open-token flows for original-quality transfers. These are warnings from the repository, not guarantees about either provider's current policy.

Issue 93, opened May 26, 2026 and updated August 19, reports that cloud-drive logins disappeared after upgrading a client to version 5.5.2. The reporter says rescanning showed success while the client still appeared logged out. That report does not identify the cause, but it is directly relevant to anyone adopting configurations around stored credentials. Test account login, restart behavior, and playback before relying on a living-room device that is hard to debug remotely.

The September 14 push shows upkeep, while 22 issues and PRs remain

GitHub recorded a last push on September 14, 2026, the day we fetched the repository. It also showed 11,283 stars and 22 open issues and pull requests. Recent threads include login loss, unusable configuration files, token placement, and basic requests for usage instructions. That mix suggests the files are being changed and people use them, while the support surface still assumes community troubleshooting rather than a maintained product contract.

GitHub returned no latest release for the repository. A missing release does not mean the project is abandoned, especially with a same-day push. It does remove a convenient stable checkpoint for users. Pinning a commit in a private fork gives you a known configuration state, but streams and remote parsers can still change underneath it. Review diffs before pulling updates, especially when they touch executable JavaScript, JAR files, proxy domains, or credential handling.

No declared license blocks a clean organizational adoption

GitHub reports no license for qist/tvbox. The README adds its own restrictions: study and research only, no commercial use, no redistribution by public accounts or media, no use in mainland China, and deletion within 24 hours. Those terms do not resemble a standard open-source license. A company that needs clear rights to modify, redistribute, or ship the material has enough reason to stop before assessing the technical convenience.

Rights to the streams are a separate question. The repository says resources came from other contributors and disclaims their legality and accuracy. A configuration that loads in FongMi TV is not evidence that each underlying source is authorized in your country. For a personal experiment, verify every source and accept that it may vanish. For a product, school, workplace, or paid service, use licensed media sources and software with explicit redistribution terms.

A player repository is the better starting point for owned software

FongMi/TV, q215613905/TVBoxOS, and takagen99/Box are actual client repositories named in the qist README. They do not solve content licensing, but they let a developer inspect application code, releases, and build instructions rather than beginning with somebody else's changing feed list. Choose among them by target device and playback needs, then supply sources you are permitted to use.

qist/tvbox makes sense for a narrow audience: Chinese-reading hobbyists who already have a compatible client and want a maintained menu of community configurations. The lack of a runnable target is only part of the caution. No declared license, explicit use restrictions, volatile external feeds, token handling, and account warnings make it a poor foundation for organizational use. Its 11,283 stars do not cancel those terms.

Alternatives

ProjectWhat it isPick it when
FongMi TVAn Android media client that the qist/tvbox README recommends for several configurations.pick this instead when you need the actual player source and releases rather than a bundle of third-party feeds.
TVBoxOSA TVBox application fork with playback and live-TV features.pick this instead when you want to inspect or build a client and need live replay support mentioned by qist/tvbox.
BoxAnother TVBox client fork cited by the README for its interface and replay support.pick this instead when the client experience matters more than adopting qist's changing configuration bundle.

What people are saying

  1. [github-trending] qist/tvbox

Sources

  1. qist/tvbox repository
  2. qist/tvbox Chinese README and usage warnings
  3. Issue 93: cloud-drive login lost after client update
  4. qist/tvbox releases

More self-hosted reviews

Mailspring · kvm · nango · SmartTubeLegacy · danmu_api · opendisplay · the whole board →