Live Intelligence · Utilities · on the bench
Diff & Crate
Its script makes no network request, and its CRC-32 checks out. No paste box, no side-by-side view, ZIP only, and a page that overstates its own silence.
Scorecard · 18 of 20 checks met
How the checks workAll four: it reads nothing but your own files.
Missed C4: the page says it makes zero network requests, yet it loads the Google tag and shared site scripts.
All four: its CRC-32 returned the standard check value.
All four: no network call exists anywhere in the tool's script.
Missed R3: no paste box, no side-by-side view, no formats beyond ZIP.
01What it is
Diff & Crate, at labs.llc/diff/, is two local desks on one page. DIFF compares any two files: texts line by line with word marks, images by slider, onion skin and a computed pixel-heat map with a difference figure, and anything else byte by byte in hex. CRATE opens a ZIP, lists every entry, previews texts and images, extracts single files and checks each against its CRC-32.
It is for anyone who needs to compare two versions or look inside an archive without sending the files to a website: writers, developers, people handling confidential documents.
02How it works
Entirely in the browser, by construction: diffcrate.js contains no fetch, XMLHttpRequest, sendBeacon or WebSocket at all. Text uses a hand-written Myers O(ND) line diff with word-level marks inside changed lines (diffcrate.js:116-170). Images are drawn to canvases and compared pixel by pixel into a heat map (diffcrate.js:220-261). Anything else gets a hex comparison over the first 8 MB (diffcrate.js:320-345). When two texts read the same but their bytes differ, it says only invisible bytes differ, encoding or line endings, and shows the byte view (diffcrate.js:180-185).
CRATE reads the ZIP's central directory itself, slices stored entries, inflates deflated ones through the browser's DecompressionStream, and verifies each entry with a hand-written CRC-32 table. Encrypted and ZIP64 entries are named and refused rather than guessed at (diffcrate.js:369-414).
03The test
On 27 September 2026 we lifted the page's own CRC-32 and diff functions out of diffcrate.js, ran them in JavaScriptCore, and searched the script for every kind of network call.
| UTC | What we did | What came back |
|---|---|---|
| 20:00:19Z | Page on the local copy | HTTP 200, 42,405 bytes; diffcrate.js 28,428 bytes. |
| 20:00:58Z | CRC-32 of '123456789', the page's code | cbf43926, the standard check value; Python's zlib gave 0xcbf43926. |
| 20:00:58Z | The page's Myers diff on two short texts | =alpha =beta −gamma +GAMMA =delta +zeta =epsilon: the minimal edit script. |
| 20:00:58Z | Network calls in the script | fetch: 0. XMLHttpRequest, sendBeacon or WebSocket: 0. |
04The comparison
Diffchecker
fetched 2026-09-27What it is
An online and desktop tool that compares text, documents, images, spreadsheets and, on the desktop, folders. Its image page says the comparison runs in your browser and nothing is published.
What it does better
Paste-in text, side-by-side and unified views, whitespace and custom ignore rules, a real-time editor; nine image modes including OCR and EXIF; PDF and spreadsheet comparison; shareable comparisons with comments; a fully offline desktop app.
Where Diff & Crate goes further
Its comparison script makes no network request at all, checkable in 28 KB, and has no saving or sharing path to switch on by mistake (diffcrate.js:3-5). It compares any two files, falling back to hex, flags texts that differ only in invisible bytes, and keeps a CRC-checking ZIP inspector on the same page.
ezyZip
fetched 2026-09-27What it is
A browser-based tool to open, extract and create archives.
What it does better
Far more formats (ZIP, RAR, 7Z, TAR.GZ, ZIPX, ISO, JAR, APK), plus archive creation, password-protected ZIPs and ZIP repair.
Where Diff & Crate goes further
CRATE checks every extracted entry against its stored CRC-32, and its CRC code produced the standard check value in our test; ezyZip's page as fetched does not mention integrity checking. CRATE also previews texts and images inside the archive in place (diffcrate.js:509).
05Where it falls short
- The page overstates its silence. Its introduction says the page makes zero network requests (
index.html:413-415), but the page also loads the Google Analytics tag from googletagmanager.com and a dozen shared labs.llc scripts (index.html:208-216, 636-652). The files you drop still stay in the tab, and the page's own note says none of those scripts reads them (index.html:641-644); the sentence should say that instead. - Files only. There is no paste box, since the inputs are two file pickers and a ZIP picker (
index.html:457-458, 486), so comparing two snippets means saving them first. - One unified view with two lines of context: no side-by-side view, no ignore rules, no share link.
- Hard caps: texts compared to the first 20,000 lines, at most 900 changed rows drawn, binaries scanned to 8 MB (
diffcrate.js:117, 194, 324). - CRATE reads ZIPs only (no RAR, 7Z or TAR, no ZIP64, no encrypted entries) and cannot create an archive.
06The ruling
Diff & Crate earns its marks by the least glamorous route: it wrote its own machinery so it would never need a server or a library, then left the proof in a script small enough to read. Our run confirmed both halves of the promise: no network call anywhere in its script, and a CRC-32 that returns the textbook value. The one mark it drops is for saying more than that: the page claims zero network requests while it loads the Google tag.
The price is convenience. Diffchecker is quicker for pasted text and far richer in views; ezyZip handles every archive you are likely to meet. Choose Diff & Crate when the files must not leave the machine, and the others when they may.
On the docket: 18 of 20 checks met. Its script makes no network request and its CRC-32 checks out; no paste box, no side-by-side view, ZIP only.