mrkeyoor.com_
Tue 29 Sept 06:36 UTC
Self-Hostedevaluationupdated 29 Sept 2026

usque-custom-pro review

Usque Custom Pro is a Chinese-language browser tool for registering Cloudflare WARP MASQUE devices and generating configurations for Clash, Mihomo, Shadowrocket, sing-box, and a local VLESS bridge. Its README is written in Chinese, and the repository provides no English documentation.

Verdict

Our usque-custom-pro run installed 45 packages in 18 seconds with 0 known vulnerabilities, but it had no build or test target and the repository has no stated license. It is useful for a Chinese-reading individual who wants disposable WARP configuration files and accepts Cloudflare deployment. A company should wait for explicit licensing, tests, versioned releases, and answers to the open routing reports.

We ran it

Lab card: what happened when we ran usque-custom-proScreenshot of usque-custom-pro (usque-custom-pro.pages.dev)
Install✓ · 18s45 packages · 220 MB
Buildn/ano build script
Testsn/ano test script
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo24 files~4,406 lines of source · 0.3 MB · 0 CI workflows

Answers from our run

Does usque-custom-pro build from source?

Dependencies installed in 18 seconds (45 packages), and the project has no separate build step. We cloned commit 8719fa0 into a clean Debian container with 3 CPUs and no project-specific setup.

Does usque-custom-pro have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does usque-custom-pro have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use usque-custom-pro?

Organizations that need clear reuse rights: GitHub reports no license, and the repository tree contains no license file.

What are the alternatives to usque-custom-pro?

wgcf, sing-box, Mihomo. Our usque-custom-pro run installed 45 packages in 18 seconds with 0 known vulnerabilities, but it had no build or test target and the repository has no stated license.

Setup3/5Fast install, but Cloudflare deployment and config handling are manual
Docs3/5Detailed Chinese guide, with conflicting 6.17 and 6.7 labels
Community3/51,422 stars and 2,305 forks, with four unanswered issues
Maturity1/5No license, release tags, CI, build target, or test target

Who it’s for

Chinese-reading WARP users who want a form instead of editing MASQUE JSON and YAML by hand.
Clash or Mihomo users who need multiple candidate endpoints and service-specific routing groups.
Cloudflare users comfortable deploying a Pages or Workers application.
Operators who understand that the downloaded config contains a private key and device credentials.

Who it’s NOT for

Organizations that need clear reuse rights: GitHub reports no license, and the repository tree contains no license file.
English-only teams: the 1,500-line README and deployment instructions are Chinese, with no English version in the repository.
Users expecting an online subscription URL: open issue 1 says each change currently requires downloading and importing another file.
Router operators who need verified domestic traffic rules: open issue 3 reports that Chinese sites stopped working under OpenClash.
Teams requiring a tested release process: our checkout had no test target, CI workflow, tests directory, or published GitHub release.

Setup reality

Our run installed 45 npm packages in 18 seconds and used 220 MB on disk. There was no build script or target and no test script or target, so both steps were skipped. Npm audit reported 0 known vulnerabilities.

The recommended Pages route needs a Cloudflare account, a GitHub connection or direct upload, and pages/ as the deployment root. The Workers route needs Node.js, Wrangler login, and deployment from workers/.

The generated config.json contains a private key, access token, license value, and device identifiers. The README says the app does not store these in KV, D1, R2, localStorage, or sessionStorage, leaving you responsible for protecting each downloaded file.

The browser replaces hand-edited WARP configuration files

Usque Custom Pro turns a fiddly Cloudflare WARP MASQUE setup into a web form. It registers a device, generates a P-256 key in the browser, enrolls the public key, and lets you download the resulting native configuration. That file can then feed generators for Clash or Mihomo, Shadowrocket, sing-box, and a local VLESS bridge. The project also creates groups for specific services and candidate endpoints for connection testing.

The documentation is Chinese throughout its roughly 1,500 lines, and there is no English README in the 24-file tree. That is a practical limit because the tool handles private keys, tokens, routing rules, and client-specific output. Machine translation may explain a button, but a production operator needs to understand the warning that entry endpoints and final WARP exit addresses are different things.

The 18-second install prepares Wrangler, not a finished route

Our commit 8719fa0 checkout occupied 0.3 MB and contained about 4,406 lines of source. The npm project lives in workers/. Installing 45 packages took 18 seconds and expanded the environment to 220 MB. The package has commands for Wrangler development, deployment, and a JavaScript syntax check, while the measured harness found no conventional build target.

Deployment offers 2 paths. Cloudflare Pages is the recommended route: point the project root at pages/, leave the build command empty, and publish the directory as-is. The Workers route runs from workers/, asks Wrangler to authenticate your Cloudflare account, and deploys the static assets plus API worker. A health endpoint confirms the page and worker route are reachable after publication.

What happened when we ran it

Our sandbox installed 45 npm packages in 18 seconds, using 220 MB after installation. Npm audit reported 0 known vulnerabilities across the measured dependency tree. The run used Node 22 in a fresh unprivileged Debian container with 3 CPUs, 8 GB of RAM, and no secrets. The repository itself held 24 files and about 4,406 source lines.

There was no build script or build target, so the build step was skipped. The same was true for tests: no test script or target was available. Our scan found 0 CI workflow files, no Dockerfile, and no tests directory. We did not deploy to Cloudflare or register a WARP device, so the clean dependency audit says nothing about generated routing correctness or live account registration.

The downloaded file carries the account secrets

The native configuration can include the MASQUE private key, access token, license field, device ID, and assigned addresses. The README says the key is generated in the browser and that the application does not persist credentials in Cloudflare KV, D1, R2, localStorage, or sessionStorage. That reduces server-side storage, though it moves the lasting custody problem to every downloaded usque-config.json.

The project tells users to exclude that file, Wrangler state, environment files, logs, and egress reports from Git. That advice matters because the workflow encourages repeated download and import. Open issue 1 asks for a subscription URL precisely because changing settings currently means generating another file and importing it again. Adding server-side subscriptions would change the current no-database security model and require a fresh design review.

Four open issues leave routing compatibility unsettled

The repository was created on September 4, 2026 and last pushed on September 9. GitHub showed 1,422 stars, 2,305 forks, 4 open issues, and 0 open pull requests. No GitHub release was published. The short activity window and high fork count show interest, but they provide little evidence about maintenance after Cloudflare or a client changes behavior.

One open report says Chinese websites became unreachable when the generated configuration ran in OpenClash. Another includes rule-provider failures and MASQUE connection closures on an Android client. User reports do not establish a universal defect, yet both touch the product's central promise: generating working client configurations. A router owner should validate domestic routes, DNS behavior, and each required service before replacing an existing profile.

Missing license terms stop serious reuse

GitHub's API reports no license, and the commit tree has no LICENSE file. Public source code is still governed by copyright when no permission is granted. That leaves companies without clear rights to copy, modify, redistribute, or deploy a fork. The omission matters more here because the README explicitly tells users to upload the project to their own GitHub account for Cloudflare Pages deployment.

Version labels also need cleanup. The README title says v6.17, its introduction and directory section say v6.7, and workers/package.json declares 6.7.0. With 0 published releases, there is no tag that resolves which label marks the reviewed state. Our 18-second install and clean audit make experimentation easy, but explicit licensing and a repeatable test path should come before organizational adoption.

Alternatives

ProjectWhat it isPick it when
wgcf gh↗A command-line tool that generates Cloudflare WARP profiles.pick this instead when you want a smaller CLI workflow and do not need browser-based multi-client conversion.
sing-box gh↗A general proxy platform with broad protocol and routing support.pick this instead when you need the maintained client runtime itself and are comfortable writing its configuration.
MihomoA rule-based proxy core compatible with Clash-style configurations.pick this instead when routing behavior and client compatibility matter more than WARP registration automation.

What people are saying

  1. [velocity-scout] KJGX66F/usque-custom-pro

Sources

  1. Usque Custom Pro README
  2. Online subscription request
  3. OpenClash domestic routing report
  4. Workers package manifest

More self-hosted reviews

Qwen3.8-Flash-Next-Single-DGX-Spark · superlocal · anythingmcp · Calibre-Web-Automated · CF-Server-Monitor · niubigeo · the whole board →