# @xhmikosr/downloader

> Download and extract files

Latest version **16.3.1** (published 2026-08-05) · MIT license · 0 weekly downloads

## Install

```sh
npm install @xhmikosr/downloader
pnpm add @xhmikosr/downloader
yarn add @xhmikosr/downloader
bun add @xhmikosr/downloader
```

## Health

**Score 60/100 (C)** — status: active.

Positive: esm support; no vulnerabilities; recently updated; high maintenance score.

Warnings: low downloads; no types.

## Facts

| | |
|---|---|
| Version | 16.3.1 |
| Published | 2026-08-05 |
| First published | 2023-03-15 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | ESM + CommonJS |
| Node | >=20 |
| Dependencies | 7 |
| Unpacked size | 8.8 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 7 |
| Author | Kevin Mårtensson |
| Maintainers | xhmikosr |
| Keywords | download, extract, http, request, url |

## Links

- npm: https://www.npmjs.com/package/@xhmikosr/downloader
- Repository: https://github.com/XhmikosR/download
- Homepage: https://github.com/XhmikosR/download#readme
- Issues: https://github.com/XhmikosR/download/issues
- npm.io page: https://npm.io/package/@xhmikosr/downloader

## Dependencies (7)

- [got](https://npm.io/package/got.md) ^14.6.6
- [ext-name](https://npm.io/package/ext-name.md) ^5.0.0
- [file-type](https://npm.io/package/file-type.md) ^21.3.4
- [filenamify](https://npm.io/package/filenamify.md) ^7.0.2
- [content-disposition](https://npm.io/package/content-disposition.md) ^2.0.1
- [@xhmikosr/decompress](https://npm.io/package/@xhmikosr/decompress.md) ^11.1.4
- [@xhmikosr/archive-type](https://npm.io/package/@xhmikosr/archive-type.md) ^8.1.0

## Alternatives

- [launchdarkly-js-client-sdk](https://npm.io/package/launchdarkly-js-client-sdk.md) — 2.5M weekly downloads
- [@elastic/elasticsearch](https://npm.io/package/@elastic/elasticsearch.md) — 2.1M weekly downloads
- [@c8y/client](https://npm.io/package/@c8y/client.md) — 15.3K weekly downloads
- [@signaldb/maverickjs](https://npm.io/package/@signaldb/maverickjs.md) — 1.7K weekly downloads
- [@bbc/http-transport-cache](https://npm.io/package/@bbc/http-transport-cache.md) — 1.2K weekly downloads

## Recent versions

- 16.3.1 (latest) — 2026-08-05
- 16.3.0 — 2026-07-16
- 16.2.0 — 2026-06-08
- 16.1.3 — 2026-05-30
- 16.1.2 — 2026-04-15
- 16.1.1 — 2026-03-06
- 16.1.0 — 2026-02-28
- 16.0.1 — 2026-02-24
- 16.0.0 — 2026-02-24
- 15.2.0 — 2025-07-28
- 15.1.1 — 2025-07-23
- 15.1.0 — 2025-07-22
- 15.0.2 — 2025-07-16
- 15.0.1 — 2024-04-02
- 15.0.0 — 2024-04-01
- … 11 more at https://npm.io/package/@xhmikosr/downloader/versions

## README

# @xhmikosr/downloader [![npm version](https://img.shields.io/npm/v/@xhmikosr/downloader?logo=npm&logoColor=fff)](https://www.npmjs.com/package/@xhmikosr/downloader) [![CI Status](https://img.shields.io/github/actions/workflow/status/XhmikosR/download/ci.yml?branch=master&label=CI&logo=github)](https://github.com/XhmikosR/download/actions/workflows/ci.yml?query=branch%3Amaster)

> Download and extract files

*See [download-cli](https://github.com/kevva/download-cli) for the command-line version.*

## Install

```sh
npm install @xhmikosr/downloader
```

## Usage

```js
import fs from 'node:fs';
import download from '@xhmikosr/downloader';

(async () => {
	await download('http://unicorn.com/foo.jpg', 'dist');

	fs.writeFileSync('dist/foo.jpg', await download('http://unicorn.com/foo.jpg'));

	download('http://unicorn.com/foo.jpg').pipe(fs.createWriteStream('dist/foo.jpg'));

	await Promise.all([
		'http://unicorn.com/foo.jpg',
		'http://cats.com/dancing.gif'
	].map(url => download(url, 'dist')));
})();
```

### Proxies

To work with proxies, read the [`got documentation`](https://github.com/sindresorhus/got/blob/main/documentation/tips.md#proxying).

### SSL

TLS certificate verification is enabled by default. It honors npm's [`strict-ssl`](https://docs.npmjs.com/cli/v11/using-npm/config#strict-ssl) config, so running `npm config set strict-ssl false` disables it for self-signed certificates or proxy setups. Override per call with [`options.got.https.rejectUnauthorized`](https://github.com/sindresorhus/got/blob/v14.6.6/documentation/5-https.md).

## API

### download(url, destination?, options?)

Returns both a `Promise<Buffer>` and a [Duplex stream](https://nodejs.org/api/stream.html#stream_class_stream_duplex) with [additional events](https://github.com/sindresorhus/got/blob/main/documentation/3-streams.md#events).

#### url

Type: `string`

URL to download.

#### destination

Type: `string`

Directory to save the file to.

#### options

##### options.got

Type: `Object`

Same options as [`got`](https://github.com/sindresorhus/got#options).

##### options.decompress

Same options as [`decompress`](https://github.com/XhmikosR/decompress#options).

##### options.extract

* Type: `boolean`
* Default: `false`

If set to `true`, try extracting the file using [`decompress`](https://github.com/XhmikosR/decompress).

##### options.filename

Type: `string`

Name of the saved file.

##### options.hash

Type: `string`

Expected hash of the downloaded data as `"<algorithm>:<hex>"`, checked before it's extracted or written. A mismatch throws. `algorithm` is any digest [`crypto.createHash`](https://nodejs.org/api/crypto.html#cryptocreatehashalgorithm-options) accepts.

```js
await download('http://unicorn.com/foo.tar.gz', 'dist', {
	hash: 'sha256:9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08'
});
```

---
_Source: https://npm.io/package/@xhmikosr/downloader · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
