Behind the project
Why I Built a Free, Open-Source CleanMyMac Alternative
Worm Cleaner started as a disagreement about one design decision: a tool that deletes your files should not ask you to trust it. I wanted a Mac cleaner where the complete list of what gets deleted is a file in a public repository, so I could read it before running it — and so could you.
By Naman Namdev
Clepsydra Technologies
Updated
Version 1.0.4
I am not going to argue that commercial cleaners are badly made. Several are excellent pieces of software, and the people who build them are good at what they do. My objection was narrower, and it is a design objection rather than a business one.
The problem with trusting a cleaner
A disk cleaner is a program whose entire purpose is to delete files you care about. That makes it structurally unlike almost every other category of software, where the failure mode is a crash rather than data loss.
So the important question is not “is this cleaner good?” It is “can I check what it does?” And for a closed-source cleaner, the honest answer is no. You can read the marketing page, the privacy policy and the permissions it requests. You cannot read the list of paths it will delete, the conditions under which it deletes them, or what happens when a path does not match expectations.
This is not a security allegation. I have no evidence that any commercial Mac cleaner deletes files it should not. The point is that you cannot check, and for a tool in this category, “cannot check” is a permanent tax on trust rather than a temporary inconvenience.
What open source actually buys you
Worm's scan catalog is Sources/WormCore/ScanCatalog.swift. That single file is the complete list of everything the Mac app can delete, one labelled entry per target with its path, category, age gate and risk tier. The protected paths are Sources/WormCore/SafetyPolicy.swift.
You can read both before installing. That is not a small thing. It means the security question has an answer that does not involve trusting me: if a rule in that file could delete something you care about, you can see it.
It also made development better, which I did not anticipate. Because the catalog is one readable list rather than logic scattered through the UI, adding a target is a single entry, and reasoning about what the app deletes is a normal code review rather than an archaeology exercise.
Four risk tiers, and why the default matters
Most cleaners present a binary choice: clean this category, or do not. That pushes the decision onto you for categories with mixed contents, so people either clean everything or nothing.
Every target carries one of four risk tiers, and the tier decides what is ticked by default:
- Safe — rebuilt automatically by the app. Deleting costs only time.
- Re-download — fetched again from the network. Anything expired in there is gone for good.
- Keep — your content, not a cache. Off by default, and needs an explicit per-item opt-in.
- Blocked — system-owned or not rebuildable. Never offered as a target at all.
The consequence I was after: a first-time user who presses the obvious button deletes genuinely disposable data and nothing else. No tutorial required.
Positive absence verification
The bug I most wanted to avoid is the one that makes people afraid of uninstall tools. Identify an app's leftovers by pattern-matching folder names, and you will eventually delete the settings of an application that is still installed — wiping offline data, saved logins, or local databases.
So Worm does not guess. Before flagging anything as an orphan it performs positive absence verification: it checks for the app bundle in system locations and queries Spotlight to confirm the application is genuinely gone. On Windows the equivalent uses token matching against every registered app plus a check against each install location — deliberately not substring matching, which both hid real orphans and flagged live ones.
That is slower than pattern matching and it occasionally misses an orphan. Both are the right trade.
The blast-radius allowlist
Rules should be trustworthy, but a mistake in one rule should not be catastrophic. So every path a rule produces is checked against a cleanable-root set derived from the rules themselves, before anything is deleted.
The practical effect: even if a rule constructs a path incorrectly, it still cannot delete outside a folder the catalog declares cleanable. A bug becomes a no-op rather than an incident.
Recoverable by default
macOS deletions go to the Trash. Windows deletions go to the Recycle Bin. Every destructive operation is also appended to a plain-text TSV log — ~/Library/Logs/Worm/deletions.tsv on macOS, %LOCALAPPDATA%\Worm\Logs\deletions.tsv on Windows.
This was the second decision I cared most about. “Undo” in a cleaner is usually not offered, which pushes all the risk onto you getting it right the first time. Making the default path recoverable means a mistake costs one click rather than the afternoon it would take to reconstruct a working environment.
On the name, and the obvious question
No. Worm Cleaner is a disk cleaning utility, not malware and not a self-replicating computer worm. It does not copy itself, does not attach to other files, and has no payload. Its entire source code is public under the MIT licence, so every claim on this page can be checked line by line. The name refers to the earthworm that burrows through soil, which is also the product metaphor: it tunnels past the surface junk into the deeper filesystem strata.
The name was settled before the code existed, which is why it needed a page like this one. A tool called “Worm” that deletes files will be searched for as malware by definition, and the answer has to be verifiable rather than reassuring.
What I got wrong
Being honest here because a post like this that lists only successes is not useful.
- The macOS build is not notarised. There is no paid Apple Developer account behind this project, so Gatekeeper blocks the first launch until the user clicks through. That is a genuine adoption cost and it is entirely self-inflicted.
- Scope is narrow. No malware scanning, no scheduled cleaning, no login-item management. Some people need those and this is not a substitute.
- One maintainer. A real bus-factor consideration. The source being public mitigates it somewhat, since anyone can continue it.
- The Windows app arrived late. It reached feature parity with the Mac app only in v1.0.4.
What is next
The catalog is the product, and it is incomplete. CocoaPods is not supported yet, which is an obvious gap given how much space it occupies. macOS is where the interesting residue is; Windows has broader surface area but less to offer any single user.
If you find a cleanup target that is missing, or a rule that looks wrong, the issue tracker is the right place — and if you would rather fix it yourself, it is one entry in one file.
Frequently asked questions
Why is Worm Cleaner free?
Because the interesting part is trust, and a subscription is a poor fit for it. Charging for a cleaner makes the reader wonder what the money is for, and if the answer is a business that needs revenue, that business will eventually want data or advertising. Keeping it free and MIT licensed means the incentive is aligned with the tool remaining auditable and quiet.
Is Worm Cleaner open source in the strict sense?
Yes. Both apps are in one public repository under the MIT licence: the macOS app in Swift 6 with SwiftUI, the Windows app in .NET 9 with WPF. The scan catalog and safety policy are readable source, so you can confirm exactly what is deleted and what is protected before installing anything.
Why call it Worm if that sounds like malware?
The name was chosen first, for the metaphor of an earthworm tunnelling past surface junk into deeper strata, and it stuck. The obvious consequence is that people search for 'is worm cleaner malware' — so the answer has to be verifiable rather than a reassurance: no self-replication, no payload, no network calls during cleaning, and the entire source public.
What did you learn building a Mac cleaner?
Mostly that the hard part is not deletion, it is deciding what is safe to delete and proving it. The risk-tier model, positive absence verification for orphans, and the blast-radius allowlist were all harder to get right than the reclaimer itself, and they are the parts that actually determine whether the tool deserves to be trusted with a system directory.
Download Worm Cleaner
Worm Cleaner is free, MIT licensed and runs on macOS 14+ and Windows 10/11. No account, no subscription, no telemetry in the app.