Why "free to download" sometimes means free software plus a few uninvited guests.

Section 01The Download You Got, and the Download You Expected

You go to a website, click a button, run an installer — and a week later you notice a toolbar you did not ask for, a new default search engine, or a program cheerfully starting itself at login that you have never heard of. This is bundling: the practice of attaching extra software to the installer of something else. It is legal, extremely common, and worth understanding before you click anything.

Bundling is old. In the early days of boxed software it meant getting trial discs with your modem. Today the mechanics are more sophisticated and the incentives sharper. A developer with a popular free utility can earn several dollars for every user who accepts a bundled offer — multiplied across millions of downloads, that is a real revenue stream. This is one answer to the question of who pays for software nobody sells: sometimes the user is not paying with money, but with attention, defaults and installed footprint.

The offers themselves vary widely in how they behave. Some are genuinely useful programs presented honestly — a PDF reader bundled with a media player, say, where both boxes are clearly labelled and un-ticking one leaves the other untouched. Others rely on the installer moving quickly, with an "Agree" button prominent and the opt-out in pale grey four clicks deep. The difference between those two cases is the difference between an upsell and a trick — but both arrive through the same mechanism.

Section 02Three Routes In

Understanding how extras arrive helps you intercept them.

The official installer. A developer who controls their own installer and chooses to bundle extras. Historically this happened with legitimate, well-known tools — utilities that were genuinely popular but generated no direct revenue — whose authors accepted partnership deals. Users who ran through the installer without reading every screen got something extra. In many cases the developer eventually dropped the bundle after user complaints, but the installs already made stayed made.

Third-party download portals. Here the developer is not directly involved. A portal wraps the original installer in their own wrapper, which shows offers before handing off to the real installer. From the user's perspective the experience looks nearly identical to downloading from the official site; the portal often mirrors the official page closely enough to appear in search results above the real thing. The original developer may not even know their software is being distributed this way. Reading the address bar carefully — and preferring an official project page or a trusted system repository — is the simplest defence.

A portal wraps the original installer in their own wrapper, which shows offers before handing off to the real installer.

Toolbars, extensions and search hijackers. A specific flavour of bundle that targets the browser. An extension installed this way might change your default search engine, inject advertisements into pages, or harvest browsing data. These are particularly persistent because browser extension permissions are not always scrutinised the way application permissions are — users grant them quickly and forget them.

Stack of external hard drives with coiled cables
a stack of external drives and coiled cables — the desk, where all of this actually happens.

Key facts · the words used here

bundling
attaching additional software to another program's installer
opt-out
a pre-selected default the user must actively decline to refuse
EULA
End User Licence Agreement; legal terms presented before installation
checksum
a short fingerprint used to verify a downloaded file is unaltered
wrapper installer
a portal's own installer that wraps the original software

Section 03Reading the Installer as a Document

An installer screen is not a formality; it is a contract being presented quickly. A few habits help.

Choose custom or advanced installation when offered. The "Express" path is where bundles live — it is called Express for a reason. On the custom path, you see individual components, each with its own checkbox, and you can refuse extras without refusing the software you actually wanted.

Read checkbox state carefully. Pre-ticked boxes for additional offers are the norm. A box you must actively un-tick to refuse carries the psychological weight of a default — most people accept defaults without noticing. Legally the developer can say you consented; practically, consent requires you noticed the box existed.

Pause on licence agreements that mention partners, advertisers or "third-party offers". These phrases are signals. You are not obliged to read the full text of every EULA for every piece of software you install — that would be an impossible demand on anyone's time — but a moment's scan for those terms costs little and can tell you a lot.

After installation, open the uninstaller list in your operating system's control panel immediately. If you see anything that was not there before and you do not recognise it, uninstall it now, before it embeds further. Some bundled programs install services or scheduled tasks that make later removal harder.

Section 04Reducing Exposure Before You Click

The most effective defence is not vigilance inside an installer but choosing installers carefully.

Where your operating system or distribution provides a package repository, use it. The packages in Debian, Fedora, or the Windows Package Manager's curated list have been reviewed at least to the degree that they are what they claim to be and do not carry unauthorised extras. App stores on mobile platforms apply similar curation — imperfectly, but consistently. Source matters more than how the download button looks.

For software outside repositories, navigate directly to the official project page rather than searching for the name and clicking the first result. The Apache Software Foundation, the Free Software Foundation and most serious open-source projects publish verifiable checksums alongside their installers; matching the checksum tells you the file you downloaded is the file they intended to distribute, untampered.

None of this requires paranoia — just the same mild scepticism you apply to any form of rapid consent. Installers are designed to be clicked through; the defaults are set by whoever built the installer, not by you.

Apache Software Foundation

Referenced in this piece

major open-source foundation that publishes checksums alongside official releases

Free Software Foundation

Referenced in this piece

foundation publishing free software and verifiable releases

Debian, Fedora

Referenced in this piece

Linux distributions with curated package repositories

Programs and organisations are named as examples, not recommendations. Where we link, we link the official project page. The desk hosts no files and ranks no vendors.