Migration assessment / LOCAL CLI

VBA Modernization Assessment

Find likely blockers before planning an Excel modernization.

A local CLI that inspects trusted internal .xlsm workbooks and exported VBA, then produces source-based migration assessment reports.

Purchase flow not yet enabledRead the documentation

REQUIRED TRUST BOUNDARY

Trusted internal inputs only

Only analyze workbooks your organization owns, already trusts and obtained from a known internal source. Never use unknown, external or suspicious files.

This is a usage requirement, not an automated source or safety verification.

THE PROBLEM

Map the work before rewriting it.

Internal workbook portfolios often contain VBA modules, events and dependencies that need review before a rewrite can be scoped.

Teams inventorying their own trusted Excel/VBA assets before considering Office Scripts or Microsoft 365 workflows.

The assessment flags findings in:

  • VBA modules and procedures
  • Worksheet and workbook events
  • UserForms and ActiveX
  • COM, Win32 and Shell/file dependencies
  • External links and connections
  • Missing sheet and table references
INPUT

Organization-owned, already-trusted internal .xlsm workbooks or exported VBA modules; an associated workbook can be supplied for structure checks.

OUTPUT

Single-item HTML, JSON, CSV and Markdown reports; batch HTML, JSON and CSV summaries.

WORKFLOW

From workbook to review plan.

  1. 01Trusted internal asset

    Provide a known, organization-owned workbook or exported source.

  2. 02Local static inspection

    Extract and inspect source and workbook structure without running macros.

  3. 03Migration assessment

    Review blockers, uncertain items and inspection status.

  4. 04Portable reports

    Use HTML, CSV, JSON and Markdown outputs for review.

BEFORE PURCHASE · PLANNED

Free preflight is in design.

A limited local check could help establish whether a trusted internal workbook is a supported input before purchase. It is not available in this preview.

See availability

Proposed checks

  • Valid supported .xlsm container
  • VBA project presence
  • Encryption or unsupported container signals
  • Obvious incomplete-inspection condition

A preflight would not generate the paid blocker report. The trust declaration would still be required.

SYNTHETIC EXAMPLE

What a report can surface.

Illustrative data only. No customer workbook or company data is shown.

ASSESSMENT / DEMO PORTFOLIO35 WORKBOOKS · SYNTHETIC
MIGRATION STATUSBLOCKED

Worksheet events · ActiveX · COM

REVIEW ITEMREVIEW_REQUIRED

External links · missing sheet references

INSPECTIONINSPECTION_INCOMPLETE

Read failure requires follow-up

P-CODE TRUSTNOT_VERIFIED

Separate from migration findings

A low-friction candidate still needs workbook and target-platform testing. A separate NO_VBA_PROJECT state may apply when no VBA project is found.

EXPLICIT LIMITS

What this tool does not do.

Use this assessment to identify work for human review, not as a conversion or security verdict.

  • Does not execute macros or generate Office Scripts
  • Does not convert VBA or guarantee migration success
  • Is not malware analysis and is not for unknown or untrusted files
  • Does not verify P-code and VBA source equivalence
  • Does not upload workbooks

BEFORE YOU RUN IT

Know the source of every file.

Analyze only workbooks that belong to your organization, are already trusted and came from a known internal source.

Do not analyze

  • Unknown external workbooks
  • Suspicious attachments
  • Files downloaded from strangers
  • Malware samples

The --trusted-internal flag records your declaration. The software cannot establish provenance.

PRIVACY & SAFETY

Analysis stays on the local machine.

Analysis runs locally. The analysis path has no telemetry or workbook upload. Temporary analysis data is removed after processing, and reports omit VBA source, cell values and external-link URLs.

Resource limits and a separate analysis process reduce some failure modes. They do not isolate an exploited parser from local files or network access. Use the stated trusted-input boundary.

Read the trust model

NEXT STEP

Read the usage guide.

Requirements, commands, output meanings and common errors are documented for a self-service run.

View usage docs