Home / Services / Security Inspect / Mobile App Assessment
Security Inspect / Android / iOS static assessmentFind weaknesses in your mobile apps
just by uploading them.
Mobile App Assessment is a static assessment service for Android APKs and iOS IPAs. Following OWASP MASVS / MASTG, it uses AI and analysis tools to check the manifest and configuration, use of cryptography, network communication, data storage, and vulnerabilities in bundled libraries, then compiles the results into a report.
Challenges
Sound familiar?
No assessment on every release
External assessments have long lead times and cannot keep up with frequent updates.
Cross-platform blind spots
Assessment methods built for native apps cannot fully inspect what is inside Flutter or React Native apps.
Vulnerabilities in bundled libraries
Vulnerabilities in SDKs and libraries bundled with an app go unnoticed if you only look at the source code.
Features
Mobile App Assessment key features
01Assessment based on OWASP MASVS
Checks against OWASP MASVS / MASTG criteria for each area: configuration, cryptography, platform interaction, network communication, data storage and code.
02Android analysis
Decompiles the APK and checks the manifest, exported components, WebView bridges and native libraries.
03iOS analysis
Checks Info.plist, entitlements, ATS, URL schemes, binary protection settings, Keychain usage and WKWebView bridges.
04Cross-platform support
Identifies Flutter, React Native, Xamarin, Cordova and Capacitor, and also extracts and analyzes JavaScript bundles and .NET assemblies.
05AI code review
Starting from the analysis tool results, AI reads the code area by area and organizes the locations that are real issues, along with the evidence.
06SBOM of bundled libraries
Lists the SDKs and native libraries bundled with the app and matches them against known vulnerabilities.
07Coverage check
Before issuing the report, checks for each assessment area whether it could be verified or not, to prevent oversights.
08Items needing dynamic testing
Items that static assessment cannot verify and that require testing on a real device are listed separately in the report. This helps you plan your next assessment.
What we check
Inspect what is inside the app,
area by area in MASVS
Weaknesses in mobile apps hide in many places: how data is sent and stored, how the app interacts with the OS, the libraries it bundles, and more. Mobile App Assessment splits analysis by OWASP MASVS area and examines each one in depth.
Configuration and manifest
Checks what the app declares: debug settings, exported components, URL schemes, permission requests and more.
Network communication
Checks whether cleartext traffic is allowed, certificate validation, and relaxed ATS or network security settings.
Data storage
Checks sensitive information stored on the device, use of the Keychain and encrypted storage, and output to logs.
Cryptography
Checks for weak algorithms, hardcoded keys or initialization vectors, and insecure random number generation.
Platform interaction
Checks WebView-to-JavaScript bridges, interaction with other apps, and use of OS features.
Binary and dependencies
Checks binary protection settings, bundled native libraries and SDKs, and known vulnerabilities.
Cross-platform
Flutter or React Native,
we read what is inside
Analysis methods built for native apps cannot see inside cross-platform apps. Mobile App Assessment identifies the framework in use, extracts the code in the way that fits each one, and then analyzes it.
Framework detection
Automatically identifies native, Flutter, React Native, Xamarin, Cordova and Capacitor apps and switches the analysis method accordingly.
Code extraction
Extracts React Native JavaScript bundles and Xamarin .NET assemblies and analyzes them the same way as native code.
Specifications
Scope and delivery
| Targets |
|
|---|---|
| Deployment |
|
| Method |
|
| Output |
|
| Pricing |
|
Please note: Static assessment only. For iOS, you need an IPA with App Store encryption (FairPlay) removed; encrypted IPAs are not accepted.
Getting started
Getting started
Upload the app
Upload the APK or IPA from the console.
Run the assessment
Analysis and AI review run automatically.
Review the report
Review the findings and recommended actions.
FAQ
FAQ
Can I use an IPA downloaded from the App Store?
App Store builds are encrypted, so they cannot be assessed as is. Please provide an IPA built during development.
Works well with
Mobile App Assessment — details and demo requests
Our team will explain deployment options and pricing for your environment.