Safety for a crossword client starts with knowing where the binary came from. Prefer GitHub Releases for mrichards42/xword. Match XWord-Windows.exe or XWord-macOS.zip exactly. Skip Softonic-style rename portals that only chase search rankings.
Licence
COPYING in the repository is GPL-3.0. That is good news for labs that require public source. It does not magically clear copyright on every .puz file you download from elsewhere.
Audits
No third-party audit firm or year was found on pages checked 2026-09-15. Do not invent audits. Read the security page for how upstream wants reports.
Package managers
winget and Homebrew cask were not found. An invented package id is a safety problem because it can point people at the wrong binary. Prefer Releases filenames on the machine ticket.
Signing
Code signing status is UNVERIFIED. If SmartScreen or Gatekeeper warns, return to the Releases URL rather than grabbing a second mirror. Details: download safe.
Network habits
XWord can solve offline after install. Package Manager downloaders need network when you opt in. Keep those optional until the first local puzzle works. Guide: lua packages.
What this guide cannot promise
We cannot promise a binary is free of bugs. We can promise the filenames we map and the UNVERIFIED labels when we did not run an installer on a real machine during research.
Shared desk pin
Shared desks should pin the Releases URL beside the OS version. After every reimage, prove one local crossword open before workshops begin. Travel laptops should download once on a trusted network, then solve offline with puzzles already on disk.
Club download discipline
Club volunteers invent Softonic mirrors when a first launch is blocked. Prefer returning to GitHub Releases for mrichards42/xword instead. Write the exact filename on the machine ticket so the next bump stays honest for the whole room.
Classroom images
Classroom images drift when someone keeps a private copy of an old exe. Prefer the current tag that still ships XWord-Windows.exe and XWord-macOS.zip together. Linux builders should document their wxWidgets version beside the commit they built.
Family PCs
Family PCs benefit from a boring puzzle folder path. Keep Across Lite or a browser board as a fallback until the new window feels normal. Subscription newspaper apps remain optional for archives and are a different job than a local .puz client.
Publisher note
Across Bind publishes install maps for people who searched for crossword software. Upstream XWord remains GPL-3.0. When Releases change asset names, re-check the live list before you refresh a lab image.
Related
Desk logistics
- Ticket line: OS, asset name, puzzle folder
- Demo door: one official path for volunteers
- Travel rule: trusted network first
Write the OS version, asset name, and puzzle folder on one ticket line. Clubs should assign a single demo door so volunteers stop mixing Across Lite, browser tabs, and XWord without notes. Travel kits should carry puzzles on disk only when policy allows encrypted storage.
After the first week
Only then add Package Manager downloaders, heavy layout floating, or diagramless drills. Prefer one documented update habit. Re-check Releases whenever upstream publishes a new tag that still lists your OS asset.
More desk notes
Prefer one Releases bookmark in the browser profile used for installs. Refuse email attachments that claim to be a crossword updater. After every lab reimage, open one cached .puz before you call the image ready for students. Keep Across Lite only as a labeled fallback, never as a silent second installer path without a ticket note.
Frequently asked questions
Is XWord open source?
Yes. The repository reports GPL-3.0 via COPYING. You can read the source at mrichards42/xword. That licence covers the client; puzzle content you open still follows its own copyright rules from the publisher.
Are the downloads signed?
Code signing and notarisation for XWord-Windows.exe and XWord-macOS.zip are UNVERIFIED on this review date. Prefer HTTPS downloads from GitHub Releases and the exact filenames this install guide maps for crossword desks.
Where should I report a security issue?
Use the GitHub security page for mrichards42/xword. Product bugs that are not security reports can go to the public issue tracker. This install guide does not triage upstream vulnerabilities for you.