WhatsApp Forensic Tools That Finally Read the Current Android Schema
If you've ever tried to pull messages out of a WhatsApp backup for an investigation or a personal data recovery, you've probably hit the wall: the tools you found were written years ago, and WhatsApp changed its database layout back in 2021. The old parsers just return nothing useful. Whapa is a set of forensic tools built to fix exactly that, and version 2.00 finally reads the current Android schema—plus it adds iOS support for the first time.
What It Does
Whapa is a collection of command-line forensic tools for analyzing WhatsApp on Android and iOS devices. It's written in Python 3.11 and tested on Linux, Windows, and macOS. Each tool does one job and can run on its own from the terminal, or you can drive all of them from a graphical interface.
On Android, there are five tools: Whapa parses the database (both current and legacy schemas), Whacipher handles decryption and encryption for crypt12, crypt14, and now crypt15, Whagodri extracts Google Drive backups, Whamerge merges databases, and Whachat parses exported chats. On iPhone, Whapa parses ChatStorage.sqlite (new in this version), Whacloud extracts from iCloud, and Whachat handles exported chats.
The architecture is deliberately modular. The GUI doesn't do any of the work itself—it builds the command and calls the matching tool in libs/, so whatever you see in the panel is exactly what you'd get from the command line. That's a small design decision that makes a big difference when you're trying to script something or reproduce a result.
Why It's Cool
-
It actually reads modern WhatsApp databases. The 2021 schema change is the reason a lot of older forensic tools quietly stopped working. This version handles both the current and legacy layouts, so you're not stuck choosing between tools depending on when a device was last updated.
-
It recognizes the message types people actually send now. Polls, video notes, view-once media, events, albums, edits, reactions, channels, and communities are all parsed. If you've ever tried to explain to someone why their "view once" photo shows up as an empty row in a report, you'll appreciate this.
-
The search engine is real. Regular expressions, dates, sender, direction, type, and flags. That's the kind of filtering that turns a dump of thousands of messages into something you can actually reason about.
-
The report is self-contained. You get a printable report and CSV export, plus an interactive report that doesn't choke on very long conversations. You open
report/report/index.htmlby double-clicking it—no web server needed. -
The dependency handling is thoughtful. Every tool tells you what it needs. If something's missing, you get a clean line like
[e] Missing requirements for whacloud: pyicloudwith the exact pip command to fix it, instead of a traceback. The GUI's "Install requirements" button uses the same Python that's running the interface, which sidesteps the classic "I installed it and it still says the module is missing" problem. -
It covers both platforms in one toolset. Android and iOS, encrypted backups, cloud backups, and exported chats—all under one roof, with the same interface and the same reporting.
How to Try It
You'll need Python 3.11 or later. Check first:
python3 --version
Clone the repo and install the requirements:
git clone https://github.com/B16f00t/whapa.git && cd whapa
pip3 install --upgrade -r ./doc/requirements.txt
On Windows, use pip install --upgrade -r .\doc equirements.txt instead. If you only need the command line and aren't touching Google Drive or iCloud, pip3 install pycryptodome colorama is enough.
From there, a typical Android workflow looks like this. Decrypt the database if it's encrypted:
python3 libs/whacipher.py -f msgstore.db.crypt15 -d key -o msgstore.db
The key can be the key file, encrypted_backup.key, or the 64 hexadecimal characters of the root key—the format is detected automatically. Then peek inside:
python3 libs/whapa.py msgstore.db -i 3
And build the report:
python3 libs/whapa.py msgstore.db -m -a -wa wa.db -r EN -o ./report
On iOS, it's the same flow, just pointing at ChatStorage.sqlite:
python3 libs/whapa.py ChatStorage.sqlite -m -a -r EN -o ./report
If you'd rather not juggle flags, run python3 whapa-gui.py and work from the tabs. The top bar has buttons for installing requirements, editing cfg/settings.cfg (case details and cloud credentials) without leaving the app, opening the manual, and switching between Spanish and English.
The repository is at github.com/b16f00t/whapa.
Final Thoughts
Whapa is clearly built by someone who got tired of tools that stopped working and decided to fix it properly. The modular design, the honest error messages, and the attention to schema changes all point to a project that's meant to be used in real forensic work rather than demoed once. If you're doing digital forensics, incident response, or even just trying to recover your own chat history, this is worth having in your toolkit. The iOS support and crypt15 decryption are new enough that you'll want to test against your own data before relying on it in a case—but the foundation looks solid, and the changelog suggests the maintainer is keeping pace with WhatsApp's changes.
Follow @githubprojects for more developer tools and open source projects.