# How Word Length Filtering Works in CUPP: wcfrom and wcto Parameters Explained

> Master CUPP's word length filtering with wcfrom and wcto parameters. Learn how to precisely control password dictionary output for better security profiling. Optimize your password analysis today.

- Repository: [Mebus/cupp](https://github.com/Mebus/cupp)
- Tags: deep-dive
- Published: 2026-07-03

---

**CUPP (Common User Passwords Profiler) uses the `wcfrom` and `wcto` settings in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) to enforce exclusive bounds, keeping only candidate passwords whose length is strictly greater than `wcfrom` and strictly less than `wcto` before writing the final dictionary to disk.**

CUPP generates personalized password wordlists for security testing by profiling target information. The **word length filtering** capability ensures generated dictionaries meet specific complexity requirements by discarding candidates that are too short or too long based on user-defined constraints in the configuration file.

## Configuration Parameters in cupp.cfg

The filtering behavior is controlled through two numeric entries located in the `[nums]` section of the configuration file.

### The wcfrom and wcto Settings

As defined in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg), these parameters establish the boundaries for acceptable password lengths:

- **`wcfrom`**: Sets the minimum word length (exclusive lower bound)
- **`wcto`**: Sets the maximum word length (exclusive upper bound)

The default configuration specifies `wcfrom=5` and `wcto=12`, meaning the final output will only contain passwords ranging from 6 to 11 characters in length.

## Loading Configuration at Runtime

When CUPP initializes, the `read_config()` function in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) parses [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) and stores the values in a global `CONFIG` dictionary under the `"global"` key.

```python

# From cupp.py - read_config()

CONFIG["global"]["wcfrom"] = config.getint("nums", "wcfrom")
CONFIG["global"]["wcto"] = config.getint("nums", "wcto")

```

This makes the bounds available throughout the application for filtering operations.

## Applying the Length Filter in Code

CUPP applies word length filtering at the final stage of wordlist generation using Python list comprehensions that check the length of each candidate password against the configured bounds.

### Filter Implementation in improve_dictionary()

For the wordlist improvement mode (invoked with `python3 cupp.py -w`), the `improve_dictionary()` function filters the `unique_list` before writing output:

```python

# From cupp.py - improve_dictionary() (lines 88-93)

unique_list_finished = [
    x for x in unique_list
    if len(x) > CONFIG["global"]["wcfrom"] and len(x) < CONFIG["global"]["wcto"]
]

```

### Filter Implementation in generate_wordlist_from_profile()

The same logic applies to interactive profile mode (invoked with `python3 cupp.py -i`) within the `generate_wordlist_from_profile()` function:

```python

# From cupp.py - generate_wordlist_from_profile() (lines 96-101)

unique_list_finished = [
    x for x in unique_list
    if len(x) < CONFIG["global"]["wcto"] and len(x) > CONFIG["global"]["wcfrom"]
]

```

Both implementations use strict inequality operators (`>` and `<`), meaning passwords exactly equal to `wcfrom` or `wcto` are excluded from the final `unique_list_finished`.

## Default Behavior and Range Calculation

With the default settings of `wcfrom=5` and `wcto=12`, the filter expression becomes:

```python
len(x) > 5 and len(x) < 12

```

This evaluates to **True** only for passwords with lengths of 6, 7, 8, 9, 10, or 11 characters. Any candidate of 5 characters or fewer, or 12 characters or more, is discarded before the final dictionary is written to disk.

## Customizing Word Length Constraints

To adjust the filtering bounds, modify the `[nums]` section in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg):

```ini
[nums]
wcfrom=8
wcto=16

```

With these settings, only passwords of 9 to 15 characters will survive the filtering process. After editing the configuration, run CUPP normally:

```bash

# Interactive mode with custom length filters

python3 cupp.py -i

# Improve existing wordlist with custom filters

python3 cupp.py -w existing_wordlist.txt

```

## Summary

- **`wcfrom` and `wcto`** in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) define exclusive minimum and maximum word length bounds.
- **`read_config()`** in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) loads these integers into `CONFIG["global"]` at startup.
- **Both `improve_dictionary()` and `generate_wordlist_from_profile()`** apply identical list comprehension filters checking `len(x) > wcfrom and len(x) < wcto`.
- **Default values** of 5 and 12 produce output containing only 6-11 character passwords.
- **Strict inequality operators** ensure exact boundary values are always excluded from results.

## Frequently Asked Questions

### What do wcfrom and wcto stand for in CUPP?

These parameters represent "word count from" and "word count to" respectively. They define the lower and upper exclusive boundaries for password lengths in the generated dictionary, though the actual implementation checks character length rather than word count.

### How do I configure CUPP to only generate passwords longer than 8 characters?

Edit the `[nums]` section in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) and set `wcfrom=8`. Leave `wcto` at a sufficiently high value (such as 20). This configuration will exclude any password of 8 characters or fewer, keeping only candidates of 9 characters or longer.

### Why are passwords of exactly 5 or 12 characters excluded with default settings?

The filter logic uses strict greater-than (`>`) and less-than (`>`) operators rather than inclusive comparisons. With `wcfrom=5` and `wcto=12`, the condition requires length to be greater than 5 AND less than 12, meaning exactly 6-11 characters pass the filter.

### Does word length filtering apply to both interactive mode and wordlist improvement?

Yes. The same filtering logic is implemented in both `generate_wordlist_from_profile()` (used with the `-i` interactive flag) and `improve_dictionary()` (used with the `-w` wordlist improvement flag). Both functions reference `CONFIG["global"]["wcfrom"]` and `CONFIG["global"]["wcto"]` to enforce consistent length constraints across all CUPP operation modes.