finds.dev← search

// the find

momenbasel/PureMac

★ 6,811 · Swift · MIT · updated Sep 2026

Free, open-source macOS cleaner. CleanMyMac alternative with zero telemetry. Native SwiftUI, scheduled auto-cleaning, Xcode/Homebrew/system cache cleanup. MIT licensed.

PureMac is a native SwiftUI macOS cleaner covering app uninstalls, orphan detection, cache/Xcode/Docker/Homebrew cleanup, duplicate and similar-photo finding, plus a companion CLI. It's aimed at people who want CleanMyMac's feature set without the subscription, telemetry, or fear-based UX, and who care enough to actually read the deletion code before trusting it with Full Disk Access.

The 10-level app-matching engine (bundle ID, team identifier, entitlements, container discovery) is a real attempt at solving the hard part of app uninstalling, not just deleting the .app bundle. CleaningEngine re-resolves paths near the actual delete call and enforces an explicit allow-list rather than trusting whatever the scanner found earlier. It's honest to a fault — refusing to list purgeable space as reclaimable junk when every competitor either fakes it or overstates it is a real technical/product stance, not marketing copy. Decent test coverage exists for the riskiest pieces (CleaningEngineTests, DuplicateFinderTests, CleanupExclusionsTests).

Heuristic matching for orphan/uninstall discovery is fundamentally probabilistic — company-name and partial-path heuristics can and will misfire across apps sharing a vendor prefix, and the README admits this by pushing review onto the user rather than solving it. It asks for Full Disk Access, the single highest-trust grant on macOS, for a tool whose core job is permanent deletion; that's a large blast radius for a project with one apparent primary maintainer. Their own docs concede the symlink TOCTOU race is narrowed, not closed, since final removal is still path-based — that's an honest disclosure but also a real unpatched class of bug. Admin escalation goes through NSAppleScript, which has a messier security history than a proper authorization API (SMJobBless/AuthorizationExecuteWithPrivileges successor), even with an allow-list gating it.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →