127,000 Stars, an 872 MiB Installer and 141 MiB of Apple and Microsoft Fonts: Auditing MoneyPrinterTurbo

MoneyPrinterTurbo has 127,556 stars, sits on today's GitHub Trending list with 431 stars in a day, and sits at 19,953 forks. I downloaded the 872.79 MiB Windows build and unpacked it: it installs to 1,938.6 MiB and carries a 523 MiB .git pack, a 363 MiB PortableGit, two complete ffmpeg builds and 40 MiB of debug symbols. Of the 202.53 MiB of checked-in bytes, 141.26 MiB (69.7%) is proprietary font data — Microsoft YaHei (© 2022 Microsoft) and STHeiti (© Changzhou SinoType, the Heiti files macOS ships) — redistributed under a bare MIT licence and baked into the GHCR image. Also: 29 YouTube-sourced MP3s, CVE-2025-7897 (CVSS 7.3) plus two more 2025 CVEs that went unfixed for eleven months, and a 'one-click publish' that is really a $16/month third-party API.

MoneyPrinterTurbo is, by the numbers, one of the most popular pieces of AI software on GitHub. Its repository has 127,556 stars and 19,953 forks as I write this — a fork-to-star ratio of 15.6%, which is high even for projects people clone once and never touch again. It appeared at position 6 on GitHub’s daily Trending list today with “431 stars today”. It was created in March 2024, it ships version v1.3.7, its last commit landed yesterday, and it advertises the pitch you would guess from the name: give it a topic or a keyword and it writes the script, picks the footage, voices it, burns subtitles, adds music, renders an HD short video and can upload it to TikTok, Instagram and YouTube Shorts.

That is the top of the funnel. This audit is about the bottom: the objects the project actually puts on your disk.

I downloaded the current Windows release — MoneyPrinterTurbo-Portable-Windows-1.3.7.7z, 872.79 MiB (915,187,824 bytes) — listed every one of its 23,992 entries, pulled the GHCR container manifest, read the font binaries’ internal name tables, inspected the ID3 frames of the bundled music, queried the CVE registry for the project’s advisory history, and scraped the pricing page of the third-party service that implements “one-click cross-platform publishing”. None of it required the author’s cooperation. All of it took an afternoon.

The summary: MoneyPrinterTurbo is a real product with a real user base solving a genuinely boring problem — gluing ffmpeg, a TTS engine, an LLM and a caption renderer together in a way a non-programmer can double-click. Around that core there is a packaging story, a licensing story and a security story that the repository description does not mention. The licensing one is the serious one: 69.7% of the bytes checked into an MIT-licensed repository are proprietary fonts owned by Microsoft and by Apple’s SinoType vendor, and they ship in every release and in the Docker image.

The shape of the project, measured

MetricValue (2026-10-01)
Stars / forks127,556 / 19,953 (15.6%)
Trending todayposition 6, “431 stars today”
Created / last push2024-03-11 / 2026-09-30
Releasesv1.3.7 (2026-09-13), 14 Windows assets in total
Release downloads117,554 across all assets; v1.3.7 alone = 14,221
Bytes served by releases~110.9 TB (110,932,111,965,964 bytes)
Issues / closed813 / 800 (98.4%)
Pull requests / contributors633 / 115
LicenceMIT, “Copyright (c) 2024 Harry”, no third-party notices
Community health57%, no CODE_OF_CONDUCT, no CONTRIBUTING
Checked-in bytes202.53 MiB across 277 files
Docker imageghcr.io/harry0703/moneyprinterturbo:latest, 700.29 MiB (linux/amd64)

A note on that transfer figure before anyone quotes it as proof of importance: it counts GitHub’s own asset counters, and a portable build that re-downloads itself with every release inflates exactly this number. 117,554 downloads of a file that is between 576 MiB and 980 MiB, multiplied out, is 110.9 TB of egress — which is a real infrastructure fact and a vanity metric at the same time.

The more interesting trend is the star curve. I rebuilt it from Wayback Machine snapshots of the repository page, reading the title attribute of GitHub’s star counter:

DateStars
2024-03-24630two weeks after launch
2024-11-0116,738
2025-12-0148,030
2026-03-2350,988
2026-06-0175,373+24,385 in ten weeks
2026-07-2098,299+22,926 in seven weeks
2026-08-19109,793
2026-09-17124,296
2026-10-01127,556

Between launch and 1 June 2026 the project averaged 92.8 stars per day. Since 1 June it has averaged 427.7 per day — and even that understates it, because the repo added 18,297 stars in the twenty days between 12 May and 1 June 2026, and an independent review site recorded it hitting #1 on GitHub Trending in late May 2026 at 62,000 stars with +1,742 in a single day.

The burst lines up with something specific in the wider ecosystem. A rival product’s write-up attributes the surge to the AI short-video boom colliding with the YouTube AI-labelling policy debate — a Hacker News thread on that debate drew 507 upvotes — pushing creators to look for anything that automates the production of Shorts. GitHub trending is a good place to be when a category gets anxious.

And the one data point that makes the star curve look strange: Hacker News has one submission of this project in two and a half years. “Show HN: Generate short videos with one click using AI LLM”, posted 15 November 2024, finished with 2 points and 0 comments. There are 127,556 people who starred it and, by the available evidence, almost none of them posted it to the site where developers argue about tools.

The 872 MiB installer

The Windows release is a single .7z. Here is what it contains, by uncompressed size:

ComponentFilesUncompressed
lib/python — embedded CPython 3.11 + site-packages17,437769.0 MiB
MoneyPrinterTurbo/.git — the full git repository33523.4 MiB
lib/git — portable Git for Windows6,289362.8 MiB
MoneyPrinterTurbo/resource — fonts and music39197.1 MiB
lib/ffmpeg — a standalone ffmpeg build181.5 MiB
everything else193~4.8 MiB
Total23,9921,938.6 MiB

872.79 MiB of download becomes 1,938.6 MiB on disk — a factor of 2.22. A user double-clicking start.bat on a laptop with a 256 GB drive has just spent 0.76% of it on a tool whose job is to assemble 60-second vertical videos.

The individual file list is where the packaging decisions show up:

  • MoneyPrinterTurbo/.git/objects/pack/pack-696c4752….pack — 523.16 MiB. The release ships the entire git history of the project, not a source tarball.
  • lib/python/Lib/site-packages/imageio_ffmpeg/binaries/ffmpeg-win-x86_64-v7.1.exe — 83.58 MiB.
  • lib/ffmpeg/ffmpeg-7.0-essentials_build/ffmpeg.exe — 81.53 MiB. So the archive ships two complete ffmpeg builds, 165 MiB combined, for one job.
  • lib/python/Library/bin/libcrypto-3-x64.pdb (24.14 MiB) and lib/python/python311.pdb (16.14 MiB) — 40.3 MiB of Windows debug symbols from OpenSSL and CPython, which nothing in a shipped runtime needs.
  • lib/python/Lib/site-packages/pydeck/nbextension/static/index.js.map — 18.51 MiB — shipped twice, again as share/jupyter/nbextensions/pydeck/index.js.map. A JavaScript source map for a Streamlit dependency appears twice and accounts for 37 MiB.
  • lib/git/mingw32/bin/scalar.exe and lib/git/mingw32/libexec/git-core/scalar.exe — Microsoft’s scalar binary, also duplicated, 10.84 MiB each.

Two files explain the size: the git pack and the portable Git installation, together 886 MiB uncompressed. That weight is not an artefact of the unpacking, either: git packs are already zlib-compressed, and gzipping 200 MiB of this one takes it from 200.0 MiB to 199.9 MiB — 99.9% incompressible. The 523 MiB pack makes the download 523 MiB bigger, not a theoretical figure that evaporates on extraction. update.bat in the archive’s root is 306 bytes and explains why both are there:

@echo off
set "CURRENT_DIR=%~dp0"
%CURRENT_DIR%lib\git\bin\git.exe -C %CURRENT_DIR%MoneyPrinterTurbo pull
%CURRENT_DIR%\lib\python\Scripts\pip.exe install -r %CURRENT_DIR%MoneyPrinterTurbo\requirements.txt
echo ##### Update completed #####
pause

The “one-click package” is a git checkout with a bundled Git client so that it can git pull from main and then reinstall dependencies with pip. That is a defensible choice for a Chinese-audience project where a fresh clone is often the fastest way to get fixes — and it is also the reason a 300 MiB application has shipped at ~900 MiB for eight consecutive releases: v1.3.0 through v1.3.7 have all been between 872.79 and 979.13 MiB.

There is a supply-chain consequence worth naming, not because anything bad has happened but because it is the design: a versioned release with a version number in its filename self-updates from an unpinned branch on first run, and requirements.txt pins the same packages as pyproject.toml, so the second command re-resolves from PyPI. Users who trust the release number they downloaded are running whatever main was that morning.

69.7% of this repository is other people’s fonts

resource/fonts contains nine files. Four of them are these, and I read their internal name tables with fontTools rather than trusting the filenames:

FileSizeWhat the font says about itself
STHeitiLight.ttc53.20 MiBCopyright © 2000–2007 Changzhou SinoType Technology Co., Ltd.; families Heiti TC, Heiti SC; PostScript name STHeitiTC-Light; version 17.0d1e2; 2021-06-23
STHeitiMedium.ttc53.17 MiBSame copyright; Heiti SC Medium/Heiti TC Medium
MicrosoftYaHeiNormal.ttc18.79 MiB“© 2022 Microsoft Corporation. All Rights Reserved. Portions © 2022 Beijing Founder Electronics Co. Ltd.”; trademark “Microsoft YaHei is a trademark of the Microsoft group of companies.”
MicrosoftYaHeiBold.ttc16.10 MiBSame, bold weight

The Microsoft font carries its own licence text inside the file, and it is not a redistribution licence:

“Microsoft supplied font. You may use this font to create, display and print content as permitted by the license terms, or terms of use, of the Microsoft product, service or content in which this font was included. You may only (i) embed this font in content as permitted by the embedding restrictions included in this font; and (ii) temporarily download this font to a printer or other output device…”

“Microsoft supplied font” is the operative phrase: the file is licensed to the operating system it was supplied with, not to third parties. The STHeiti pair is the same story with a different owner — Heiti SC and Heiti TC are the simplified and traditional Chinese system fonts in macOS, licensed by Apple from SinoType, and the internal version string (17.0d1e2, dated 2021-06-23) is consistent with a macOS system font build.

Together: 141.26 MiB out of 202.53 MiB of checked-in file bytes — 69.75%. The repository’s licence is a bare MIT text, Copyright (c) 2024 Harry, with no third-party notice file, no font exception, and no statement in either README about where the fonts came from. The English README’s subtitle section says only:

“Fonts for rendering video subtitles are located in the project’s resource/fonts directory, and you can also add your own fonts.”

This is not decorative weight, either. config.example.toml documents the default caption font as font_name = "MicrosoftYaHeiBold.ttc", so the proprietary file is the default rendering path for subtitles — which means the glyphs are also baked into the finished videos users upload.

The distribution goes further than GitHub Releases. The GHCR image ghcr.io/harry0703/moneyprinterturbo:latest is 700.29 MiB for linux/amd64; its COPY . . layer is 134.02 MiB, and when I downloaded and listed that layer, its four largest entries were STHeitiLight.ttc (53.20 MiB), STHeitiMedium.ttc (53.17 MiB), MicrosoftYaHeiNormal.ttc (18.79 MiB) and MicrosoftYaHeiBold.ttc (16.10 MiB), followed by the 29 MP3s. The repository does have a .dockerignore — it excludes .git and storage — but it does not exclude resource/. Anyone pulling that image gets the fonts regardless of which entry point they use.

The 29 songs

resource/songs contains 29 MP3s named output000.mp3 … output029.mp3, 55.3 MiB in total. I sampled four and analysed them with mutagen:

  • All four are exactly 180.0 seconds long.
  • Bitrates 89–100 kbps at 48 kHz.
  • Every one carries a single metadata frame: TSSE = Lavf60.16.100 — FFmpeg’s encoder tag. No artist, title, album, year or licence fields survive.

A directory of uniformly-trimmed three-minute tracks at low bitrate with stripped metadata is what a bulk audio extraction looks like. And the project does not hide it — the Chinese README and the English README both say so:

“The current project includes some default music from YouTube videos. If there are copyright issues, please delete.”

“Please delete it if it infringes” is not a licence, and it does not work in the direction that matters: the default bgm_type = "random" picks one of those files for your video, and the user uploading the result to YouTube is the one holding the stake if Content ID matches. The right fix is one line in a build script — delete resource/songs and resource/fonts/*.ttc — and it is not in the project’s .dockerignore or packaging notes.

The “Azure TTS V1” that is not Azure

MoneyPrinterTurbo offers eleven voice paths. The default, and the one the UI labels Azure TTS V1, is edge-tts 7.2.7 — which is not an Azure product at all. It is a community client that reverse-engineers the endpoint behind Microsoft Edge’s “Read Aloud” button.

Three facts about that, none of them controversial:

  1. It is not licensed for this. The endpoint is not a public developer API; it exists for the Edge browser. As a commenter on the library’s own Hacker News thread put it five years into its life: the Edge API “is not licensed for any use, commercial or otherwise (outside of Edge itself)”.
  2. It breaks. In 2024, Microsoft began requiring a Sec-MS-Token header, and every dependent library was broken for weeks while the community reverse-engineered the new flow. The library’s author, rany_, wrote on Hacker News in January 2025: “Basically, it’s a very bad idea to use this library for anything serious/mission critical.” Microsoft also restricted the endpoint to the basic SSML tags Edge itself uses, so emotion and prosody controls that commercial Azure voices expose are unavailable through it.
  3. The obvious alternative has a licence trap of its own. Azure Speech has a free tier, F0, providing 500,000 neural characters per month — but Microsoft’s Product Terms say commercial output rights belong to paid-tier customers only: “For Customers of the paid tier TTS Service only, Customer may use the audio output of prebuilt neural voices generated using the TTS Service, including for commercial purposes.” That was clarified on Microsoft’s own Q&A in March 2026, where a volunteer moderator told a user that F0 is “a pricing allowance for evaluation/testing and does not carry those output use rights.”

So the two cheapest voice options in the default configuration — the free one and the free tier of the paid one — are both the wrong choice if the video is going to be monetised. If that reads like pedantry, note that the tool’s entire marketing premise is monetisation; the repository is called MoneyPrinterTurbo.

The genuinely safe options are boring and available: Kokoro-82M (Apache-2.0, runs locally on CPU, currently ranked near the top of the TTS Arena leaderboard), Piper (MIT, runs on a Raspberry Pi), or a paid Azure Speech S0/ElevenLabs/Cartesia key where the output rights are explicit.

Three CVEs, published in July 2025, in the API nobody had to authenticate to

MoneyPrinterTurbo has a security history that is not mentioned anywhere in its README. The CISA weekly vulnerability summary for the week of 14 July 2025 lists three advisories against it, all assigned by VulDB and published 2025-07-20:

CVEIssueCVSS 3.1Affected
CVE-2025-7897verify_token in app/controllers/base.py — missing authentication on the API endpoint, remotely exploitable, no privileges required7.3 HIGH (AV:N/AC:L/PR:N/UI:N)1.2.0–1.2.6
CVE-2025-7896Path traversal in download_video/delete_video in app/controllers/v1/video.py6.3 MEDIUM1.2.0–1.2.6
CVE-2025-7895Unrestricted file upload in upload_bgm_file in app/controllers/v1/video.py6.3 MEDIUM1.2.0–1.2.6

The timeline is the interesting part. v1.2.6 was tagged 2025-05-10. The CVEs were published 2025-07-20. The next release, v1.2.7, arrived on 2026-04-03 — roughly eleven months later, in a project that then shipped fourteen releases in the following six months. Whatever the reason, a project with 50,000 stars at that point took almost a year to produce a version after being assigned a HIGH-severity missing-authentication CVE.

Is it fixed now? Partly, and it is worth being precise, because this is the exact pattern that makes security advisories hard to consume. I read app/controllers/base.py at v1.3.7:

configured_key = config.app.get("api_key", "")
if configured_key in (None, ""):
    return None          # <- unauthenticated by design when no key is set

The function is now fail-closed only when a key is configured. With an empty key it returns None immediately and every API route is public — documented in the Chinese docstring as “空 Key 保留现有的本地免认证模式” (“an empty key preserves the existing local no-authentication mode”). The implementation around it improved: duplicate x-api-key headers are now rejected outright rather than resolved ambiguously, and comparison uses secrets.compare_digest over UTF-8 bytes with a comment about Latin-1 header attacks. The upload and delete handlers were also refactored into validated service calls.

But config.example.toml — the file the project copies to config.toml on first run — still ships:

listen_host = "0.0.0.0"
listen_port = 8080
api_key = ""

Bound to every interface, on port 8080, with no key, that is the same posture that got the project a 7.3. The Docker compose file does the right thing by mapping to 127.0.0.1:8080, and the WebUI launcher defaults to MPT_WEBUI_HOST=127.0.0.1, so the container path is fine. The manual uv run python main.py path — the one the README recommends for developers, and the one a user runs after extracting the portable build — is unauthenticated on the local network until the user reads the comment and sets a key.

“One-click cross-platform publishing” is a $16/month API

The feature list says: “支持一键跨平台发布,生成完成后可自动上传至 TikTok、Instagram 和 YouTube Shorts.” I looked for the implementation, expecting per-platform OAuth flows. What is there is app/services/upload_post.py, a 402-line client for Upload-Post, a commercial third-party service at api.upload-post.com:

  • It needs upload_post_api_key and upload_post_username.
  • It polls job status every 10 seconds with a one-hour timeout, and treats a platform as failed if the result is missing or marked skipped.
  • Defaults in the example config: upload_post_enabled = false, upload_post_platforms = ["tiktok", "instagram"], upload_post_youtube_privacy_status = "public".

Upload-Post’s own pricing page, which I scraped today, has a free tier (10 uploads per month, per its developer docs), then $16/month ($192/yr), $33/month ($400/yr), $118/month ($1,411/yr) and $350/month ($4,205/yr); attaching links on X costs +$19/month.

None of that is dishonest — delegating publishing to a specialist API is a reasonable engineering decision, and it means the project does not have to maintain four brittle unofficial upload clients. It is simply not what “one-click” implies to the person reading the feature list, and it is a recurring cost the README’s comparison with “free” alternatives never mentions. There is a related risk worth stating plainly: automated publishing at volume is exactly the behaviour platform enforcement systems are built to detect, and Upload-Post’s job is to push the same file to several of them.

The credential surface, and who pays for the free tool

config.example.toml is 698 lines and declares 47 credential-bearing keys across 41 distinct provider slots: OpenAI, Anthropic, Gemini, Moonshot/Kimi, DeepSeek, Qwen, Azure OpenAI, xAI, Groq, MiniMax, MiMo, Volcano Ark, ModelScope, OpenRouter, AIHubMix, AIMLAPI, API Route, APIMart, CheaperInference, Cloudflare AI Gateway, EvoLink, Fluxion AI, OneAPI, Pollinations, Requesty, Shengsuanyun, Sonilo, Metaso, MuAPI, Ofox, WaveSpeed, Pexels, Pixabay, Coverr, OpenAI-image, TwelveLabs, LoomLoom and Upload-Post. The first-run workflow is: obtain at least two of these (an LLM plus a stock-footage key, unless you use local Ollama and local media) before anything renders.

Where the money actually flows is visible in the README. After the feature list, roughly 110 of the README’s 568 lines are sponsorship blocks, and they are not decorative logos:

  • Kimi / Moonshot AI as the headline sponsor, with a tracked link (track_id=…&aff=moneyprinterturbo) offering 10% bonus credit on a user’s first top-up, up to CN¥1,000, through 31 December 2026.
  • API resellers advertising prices as multiples below list: Infistar.cc (“large models as low as 0.1 of official price”, i.e. 90% off, plus a $5 credit), Fluxion AI (“API call costs 40%–98% lower than official or baseline prices”, plus $3), APIMart, Ofox, UCloud AstraFlow (CN¥50 compute credit), Shengsuanyun (CN¥10 token credit), Metaso (MiniMax H3 video at ¥0.09/s for 768p and ¥0.15/s for 2K).
  • Cross-promotion of the author’s commercial product, MangoDisk, in a full-width banner block.
  • And a code path: script_generation_backend = "loomloom" with loomloom_base_url = "https://loomloom.shengsuanyun.com/loom/v1" — a sponsored vendor’s hosted SkillBot wired directly into the configuration as a selectable script generator.

Advertising at 90% below the list price of frontier models is a business model that requires either bulk enterprise contracts resold against their terms, or something else entirely. Whichever it is, the fact that it is the pitch says something about the audience the project monetises: people who want to make money from AI video without spending money on AI.

Before this reads as an attack on the author, the counter-argument is real. Sponsorship is how Chinese open-source projects of this size get paid, the code is MIT and genuinely useful, and the alternative for most readers is nothing at all. The objection is narrower: a reader deciding whether to build a business on this stack deserves to know that the tool’s own documentation is also its ad inventory, and that the recommended paid paths are affiliate links.

What independent reviewers say

Two reviews found through research on the project are worth quoting, because they agree with each other and with the artifacts:

Wavect’s 2026 review (published 20 August, revised 2 September 2026, at which point it recorded “around 120,000 stars and released v1.3.6”) frames the cost question usefully: track cost per approved video, not cost per render, “because discarded renders and rewrites still consume LLM tokens, stock API calls, compute and human review time”. On exposure: “Treat the default WebUI and API as developer services, not a public SaaS boundary.” On monetisation: the tool “does not make a channel eligible or ineligible by itself”, but YouTube’s guidance treats mass-produced, repetitive content with minimal variation as ineligible.

AI Fruit’s comparison (May 2026) is blunter about the onboarding: 30–90 minutes of setup, with the top three install complaints being Python version mismatches, ffmpeg paths and missing CUDA libraries; expected monthly cost $0–30 if you self-host the language model, $30–80 with hosted APIs; and the output problem nobody mentions in the feature list — “stock footage feels generic… output looks like every other AI-stitched Short because the underlying clips come from the same free libraries”, with weak results outside news and listicles.

That last point is the one no packaging fix addresses. The technical pipeline is competent; the differentiating input is the same Pexels library everyone else is pulling from.

Reproducing this audit

Everything above is reproducible in an afternoon. The four commands that produced the most interesting numbers:

# 1. The installer's true contents (~872 MiB download, ~1.9 GiB extracted)
curl -L -o mpt.7z https://github.com/harry0703/MoneyPrinterTurbo/releases/download/v1.3.7/MoneyPrinterTurbo-Portable-Windows-1.3.7.7z
uv run --with py7zr python3 -c "import py7zr;z=py7zr.SevenZipFile('mpt.7z');print(len(z.list()))"

# 2. What the bundled fonts are (not what they are called)
uv run --with fonttools python3 -c "from fontTools.ttLib import TTCollection;t=TTCollection('resource/fonts/MicrosoftYaHeiNormal.ttc').fonts[0];print([n.toUnicode() for n in t['name'].names if n.nameID==0][:1])"

# 3. The container image's largest layer, entry by entry
#    token: https://ghcr.io/token?scope=repository:harry0703/moneyprinterturbo:pull&service=ghcr.io
#    then GET /v2/harry0703/moneyprinterturbo/blobs/<digest> and list it as a tar

# 4. The advisory history, which the README does not mention
curl -s "https://cveawg.mitre.org/api/cve/CVE-2025-7897" | head -c 2000

The lesson generalises past this project. Star counts measure attention; release assets measure intent; checked-in file bytes measure what a maintainer was willing to commit. When a repository’s byte count is dominated by files nobody wrote, that is usually where both the licensing risk and the size problem live — and both are visible without reading a line of application code.

Practical guidance

If you want to use it. Do use it — for learning and internal experiments it is genuinely capable, and the local model path (Ollama plus local media plus a self-hosted TTS) costs nothing but time. Before you publish anything:

  1. Delete the fonts and the music. rm -rf resource/songs resource/fonts/*.ttc. Install Noto Sans CJK or Source Han Sans (both SIL OFL) and put yours in. font_name accepts any file you drop in the directory.
  2. Change the voice. Kokoro or Piper locally, or Azure Speech S0 / ElevenLabs / Cartesia if you are monetising. Do not ship YouTube narration built on edge-tts or on Azure’s free F0 tier.
  3. Do not use the default network posture. Set listen_host = "127.0.0.1" and a non-empty api_key. If it must be reachable, put a reverse proxy with TLS and auth in front and keep the compose file’s 127.0.0.1: port mappings.
  4. Do not use the portable Windows build as your production install. It re-pulls main on update, carries a 523 MiB git pack, and pins nothing. Use uv sync --frozen against uv.lock, or the container image with your own build stage.
  5. Keep provenance. Per video: source asset IDs, the font and music files used, the TTS provider and account tier, and the final file hash. Regulations on synthetic media disclosure (EU AI Act Article 50) and platform policies both point the same way, and “I did not know which music file it picked” is not a defence.
  6. Expect the Content ID and policy layer, not just the render. Read YouTube’s channel monetisation policy on mass-produced and repetitive content before scaling, and declare synthetic content in the upload flow.

FAQ

Is MoneyPrinterTurbo free? The code is MIT. Running it is not: an LLM key plus a stock-footage key is the minimum for the default path, and independent reviewers put real usage at $0–30/month self-hosting the model and $30–80/month with hosted APIs. Automated cross-posting adds $0 (10 uploads/month) to $350/month on Upload-Post.

Are the bundled fonts a problem for me if I only use the tool locally? The redistribution is the maintainer’s exposure, not yours — but the rendered subtitle glyphs are baked into your exported video, and using a font file you did not license for that purpose is a separate question. Replace the fonts; it costs two minutes and removes the ambiguity.

Do the 2025 CVEs affect the current version? The advisory range is 1.2.0–1.2.6 and the project is on 1.3.7. The code was restructured and the auth path hardened, but the default remains “no key configured means no authentication”, and the example config still binds the API to 0.0.0.0:8080. Treat any instance with an empty api_key as public.

Can videos made with it be monetised? Nothing in the licence stops you, and nothing in the tool makes a channel eligible either. YouTube evaluates the content: original work that happens to follow a repeatable format can monetise, mass-produced interchangeable clips generally cannot. Voice and music licensing are the two components most likely to cause a claim before the algorithm does.

Why is the star count so high if developers barely discuss it? Because “star” and “adopt” are different actions, and this project’s audience arrives through Chinese short-video monetisation content rather than through developer discussion. 15.6% of starrers forked it; the most-downloaded asset has 20,664 downloads; there is one Hacker News post with two points. None of that is fraud — it is a different audience from the one star-dense tool lists are built to measure.

Would I tell someone to build a business on it? As a rendering engine you own and modify, yes with the fixes above. As a revenue system, no: the bottleneck is not the pipeline, it is that every competitor is stitching the same free stock library into the same vertical format, and the platforms are increasingly explicit about not rewarding that.

Conclusion

MoneyPrinterTurbo is a competent, genuinely popular tool with an unusual amount of machinery behind a simple promise, and the honest version of the pitch is better than the marketing one: an integrated local pipeline — script, voice, footage, captions, music, render, publish — with eleven TTS options and ten video sources, that a person who has never installed Python can run. 115 contributors, 800 of 813 issues closed, a 70% branch-coverage gate in pyproject.toml, and a project that keeps shipping. None of the findings here require its maintainers to be cynical.

But three things should not survive the next release. 141.26 MiB of Apple and Microsoft fonts redistributed under an MIT licence is a legal risk concentrated on the maintainer and shipped to 117,554 downloaders. 29 YouTube-sourced MP3s with the disclaimer “delete if it infringes” is the same problem with the admission already written down. And an example config that binds an unauthenticated API to every interface is how the project got its HIGH-severity CVE, which stayed open for eleven months.

Fix those three — delete resource/fonts/*.ttc and resource/songs from the build, default listen_host to 127.0.0.1, and add Noto Sans CJK — and roughly a third of the checked-in bytes disappear, the image gets smaller, and the audit becomes uninteresting. That is usually the goal.