mrkeyoor.com_
Fri 02 Oct 15:37 UTC
Automationevaluationupdated 02 Oct 2026

WA-AKG review

WA-AKG turns one or more WhatsApp accounts into a self-hosted dashboard and REST API by connecting through Baileys. It handles sessions, messages, recurring schedules, broadcasts, auto-replies, media, and webhooks, with an optional n8n community node for workflow automation.

Verdict

Our WA-AKG run built successfully in 87 seconds, but its 1,343-package install had 58 known vulnerabilities and the repository supplied no test target. It is a credible starting point for a small operator who accepts Baileys, owns the database and session state, and can test every messaging path before use. Delivery-sensitive businesses and teams that require an official WhatsApp channel should choose another route.

We ran it

Lab card: what happened when we ran WA-AKGScreenshot of WA-AKG (wa-akg.aikeigroup.net)
Install✓ · 105s1343 packages · 1197 MB
Build✓ · 87s
Testsn/ano test script
Known vulns585 critical · 22 high · 29 moderate · 2 low (npm audit)
Repo274 files~32,052 lines of source · 4.7 MB · 0 CI workflows · Dockerfile

Answers from our run

Does WA-AKG build from source?

Dependencies installed in 105 seconds (1343 packages), and the build succeeded in 87 seconds. We cloned commit c7dd01a into a clean Debian container with 3 CPUs and no project-specific setup.

Does WA-AKG have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does WA-AKG have known vulnerabilities in its dependencies?

npm audit flagged 58 known advisories in the dependency tree, including 5 critical at the time of our run.

Who should not use WA-AKG?

Organizations that require Meta's official WhatsApp Business Platform: WA-AKG connects through Baileys rather than the official business API.

What are the alternatives to WA-AKG?

Evolution API, WPPConnect Server, WhatsApp Business Platform. Our WA-AKG run built successfully in 87 seconds, but its 1,343-package install had 58 known vulnerabilities and the repository supplied no test target.

Setup3/5Build passed, but SQL, secrets, pairing, and storage remain
Docs4/5Detailed API, environment, PM2, Docker, and operator guides
Community3/5401 stars, a September push, and a small active queue
Maturity2/5No test target or CI, with open Docker and delivery reports

Who it’s for

Developers building internal WhatsApp workflows around a REST API and webhooks.
Small operators who need several QR-linked sessions in one dashboard.
n8n users who want WhatsApp actions and incoming events in existing workflows.
Teams able to run a Node service, a SQL database, persistent media storage, and session monitoring.

Who it’s NOT for

Organizations that require Meta's official WhatsApp Business Platform: WA-AKG connects through Baileys rather than the official business API.
Teams that require a tested delivery guarantee for broadcasts: open issue 90 reports messages shown as sent that never reached recipients.
Release processes that require repository-owned regression checks: our checkout had no test script, no tests directory, and no CI workflows.
Operators expecting a fresh-clone Docker path with no investigation: open issues 61 and 88 report startup and image-build trouble.
Anyone unwilling to maintain WhatsApp sessions, a SQL database, uploaded media, API secrets, and admin credentials on their own server.

Setup reality

Our sandbox installed 1,343 npm packages in 105 seconds and used 1,197 MB. The production build passed in 87 seconds. There was no test script or target, so tests were skipped. Npm audit reported 58 known vulnerabilities: 5 critical, 22 high, 29 moderate, and 2 low.

Running the gateway needs MySQL or PostgreSQL, DATABASE_URL, a strong AUTH_SECRET, public URL settings, an admin account, and QR pairing for each WhatsApp session. Remove.bg needs its own API key, but it is optional.

The repository includes a Dockerfile and Compose stack with MySQL, plus a PM2 path. Media and app data need persistent storage. The documented Swagger defaults must be changed, and open issues report fresh-clone Docker build and startup problems.

Baileys turns linked accounts into an operator-owned gateway

WA-AKG connects WhatsApp accounts by QR code, keeps their sessions on your server, and exposes messaging through a dashboard and REST endpoints. That is useful when an internal system needs to send a document, react to an incoming message, or schedule a reply without a person holding a phone. The project uses Baileys to speak to WhatsApp, so adoption includes that library's behavior and the ongoing job of keeping linked sessions healthy. This is different from buying Meta's official Business Platform.

The dashboard manages multiple sessions, chats, contacts, groups, labels, auto-replies, and webhooks. The README documents more than 109 endpoints and includes a Swagger interface at /docs. Recurring schedules can run every set number of minutes or hours, on selected weekdays, or from a cron expression. Media-only scheduled messages and replies arrived in v1.6.3. An n8n community package adds action and trigger nodes for teams already using that workflow runner.

A broad API does not prove message delivery

The feature list reaches beyond a simple send endpoint. You can register event callbacks, apply session-level settings, restrict commands through allowlists and blocklists, and use roles for super administrators, owners, and staff. Broadcasts add randomized delays and batching. Those are useful controls, but the phrase "sent" still needs an application-level meaning: accepted by the local gateway, accepted upstream, or received by the destination are three different states.

Open issue 90 supplies the uncomfortable example. A user on v1.6.3 reported two broadcast attempts that the interface marked as sent, while neither recipient received a message. That report does not establish a failure rate, and our sandbox did not connect a WhatsApp account. It does show why a business should run delivery probes with its own number formats and message types before trusting campaign totals. The README separately warns against using its status-update endpoint in production because text styling and media upload can fail.

What happened when we ran it

Our run checked commit c7dd01a in a fresh unprivileged container with 3 CPUs and 8 GB of RAM. Npm installed 1,343 packages in 105 seconds and occupied 1,197 MB. The production build completed successfully in 87 seconds. The 4.7 MB checkout contained 274 files and about 32,052 lines of source, so most of the local footprint arrived through dependencies rather than the application code.

There was no test script or target, so the lab skipped tests rather than manufacturing a command. Our scan also found no tests directory and no CI workflow files. Npm audit reported 58 known vulnerabilities: 5 critical, 22 high, 29 moderate, and 2 low. We did not determine exploitability from the totals alone, but 27 critical or high findings deserve package-level triage before the API is exposed to the internet.

Production needs a database, durable state, and changed defaults

The shortest manual route still has several moving parts. WA-AKG needs MySQL or PostgreSQL, a Prisma schema push, a generated admin account, and an authentication secret. Public URL values must agree when the app sits behind a reverse proxy. Each WhatsApp account then needs QR pairing. Uploaded media defaults to a project-relative directory, while scheduled campaigns use the configured timezone. Lose the session or media volumes and the gateway does not behave like the server you thought you backed up.

The environment guide sets a 24-hour login session, a 50 MB upload limit, and 60 requests per minute by default. Swagger is enabled with admin and admin123 shown as the example credentials, and the docs explicitly tell operators to change them. The remove.bg integration needs a separate API key only if automatic sticker background removal is used. Otherwise, the central secrets are the database connection, authentication secret, API keys issued by the app, and administrator password.

Docker exists, but two open reports weaken the easy path

The repository includes a multi-stage Dockerfile and a Compose file that starts the application beside MySQL 8.0. Named volumes preserve database, application, and upload data. The container starts by pushing the Prisma schema and can create an administrator from environment values. There is also a PM2 route and a start.sh helper for dependency installation, configuration checks, build, database setup, and process startup. On paper, both deployment choices are unusually well documented for a project this size.

Open issues make the container path less settled. Issue 88 says docker build . after a fresh clone failed unless the reporter first ran npm install on the host. Issue 61 reports a container that repeatedly failed to start. Neither report includes enough log detail for us to name a cause. Our successful 87-second application build does not resolve them because the lab did not run the Docker image. A first evaluation should build and restart the exact deployment form you plan to keep.

No test target is the main maturity limit

The missing test command matters because WA-AKG touches authentication, message routing, scheduled work, file uploads, database mutations, and external callbacks. A TypeScript build can catch type and bundling errors. It cannot prove that a recurring job fires once, a webhook retries safely, an allowlist blocks the right sender, or a broadcast status matches delivery. With no repository test target and no CI workflow, an adopter inherits the work of creating smoke checks for those paths.

GitHub showed 401 stars and 10 open issues and pull requests on October 2, 2026. The API split that queue into 5 issues and 5 pull requests. The last push was September 21, while v1.6.3 shipped June 30 with recurring schedules, media-only messages, deployment scripting, and an MIT license. That activity is current enough to justify a trial. The decision turns on risk tolerance: our 87-second build passed, but 58 audit findings, no tests, and an unresolved delivery report make monitored internal use a better fit than an unattended customer channel.

Alternatives

ProjectWhat it isPick it when
Evolution API gh↗A self-hosted WhatsApp integration API with a wider connector ecosystem.pick this instead when an API-first platform and its surrounding integrations matter more than WA-AKG's bundled dashboard.
WPPConnect ServerA ready-to-run server that exposes WhatsApp automation through HTTP endpoints.pick this instead when you want a narrower WhatsApp server and do not need WA-AKG's scheduler and admin interface.
WhatsApp Business PlatformMeta's official business messaging API and webhook service.pick this instead when official support, policy alignment, and provider-backed delivery matter more than self-hosting.

What people are saying

  1. [github-trending] mrifqidaffaaditya/WA-AKG

Sources

  1. WA-AKG repository
  2. WA-AKG README
  3. WA-AKG environment variables guide
  4. WA-AKG v1.6.3 release
  5. Open issue 90 on broadcast delivery
  6. Open issue 88 on Docker builds

More automation reviews

MacDuo · flycoinrh · IDM_Pro_Tool · stonkfly · gongwen-gbt9704-skill · mactap-app · the whole board →