Home / Services / Security Inspect / Mobile App Assessment

Security Inspect / Android / iOS static assessment

Find weaknesses in your mobile apps
just by uploading them.

Mobile App Assessment is a static assessment service for Android APKs and iOS IPAs. Following OWASP MASVS / MASTG, it uses AI and analysis tools to check the manifest and configuration, use of cryptography, network communication, data storage, and vulnerabilities in bundled libraries, then compiles the results into a report.

Challenges

Sound familiar?

No assessment on every release

External assessments have long lead times and cannot keep up with frequent updates.

Cross-platform blind spots

Assessment methods built for native apps cannot fully inspect what is inside Flutter or React Native apps.

Vulnerabilities in bundled libraries

Vulnerabilities in SDKs and libraries bundled with an app go unnoticed if you only look at the source code.

Features

Mobile App Assessment key features

01Assessment based on OWASP MASVS

Checks against OWASP MASVS / MASTG criteria for each area: configuration, cryptography, platform interaction, network communication, data storage and code.

02Android analysis

Decompiles the APK and checks the manifest, exported components, WebView bridges and native libraries.

03iOS analysis

Checks Info.plist, entitlements, ATS, URL schemes, binary protection settings, Keychain usage and WKWebView bridges.

04Cross-platform support

Identifies Flutter, React Native, Xamarin, Cordova and Capacitor, and also extracts and analyzes JavaScript bundles and .NET assemblies.

05AI code review

Starting from the analysis tool results, AI reads the code area by area and organizes the locations that are real issues, along with the evidence.

06SBOM of bundled libraries

Lists the SDKs and native libraries bundled with the app and matches them against known vulnerabilities.

07Coverage check

Before issuing the report, checks for each assessment area whether it could be verified or not, to prevent oversights.

08Items needing dynamic testing

Items that static assessment cannot verify and that require testing on a real device are listed separately in the report. This helps you plan your next assessment.

What we check

Inspect what is inside the app,
area by area in MASVS

Weaknesses in mobile apps hide in many places: how data is sent and stored, how the app interacts with the OS, the libraries it bundles, and more. Mobile App Assessment splits analysis by OWASP MASVS area and examines each one in depth.

CONFIG

Configuration and manifest

Checks what the app declares: debug settings, exported components, URL schemes, permission requests and more.

NETWORK

Network communication

Checks whether cleartext traffic is allowed, certificate validation, and relaxed ATS or network security settings.

STORAGE

Data storage

Checks sensitive information stored on the device, use of the Keychain and encrypted storage, and output to logs.

CRYPTO

Cryptography

Checks for weak algorithms, hardcoded keys or initialization vectors, and insecure random number generation.

PLATFORM

Platform interaction

Checks WebView-to-JavaScript bridges, interaction with other apps, and use of OS features.

BINARY / SBOM

Binary and dependencies

Checks binary protection settings, bundled native libraries and SDKs, and known vulnerabilities.

Cross-platform

Flutter or React Native,
we read what is inside

Analysis methods built for native apps cannot see inside cross-platform apps. Mobile App Assessment identifies the framework in use, extracts the code in the way that fits each one, and then analyzes it.

DETECT

Framework detection

Automatically identifies native, Flutter, React Native, Xamarin, Cordova and Capacitor apps and switches the analysis method accordingly.

RECOVER

Code extraction

Extracts React Native JavaScript bundles and Xamarin .NET assemblies and analyzes them the same way as native code.

Specifications

Scope and delivery

Targets
  • Android: APK
  • iOS: decrypted IPA
Deployment
  • Just upload the file from the console
Method
  • Static assessment (dynamic testing on real devices or emulators is not included)
Output
  • PDF report
Pricing
  • Charged per completed assessment

Please note: Static assessment only. For iOS, you need an IPA with App Store encryption (FairPlay) removed; encrypted IPAs are not accepted.

Getting started

Getting started

  1. Upload the app

    Upload the APK or IPA from the console.

  2. Run the assessment

    Analysis and AI review run automatically.

  3. Review the report

    Review the findings and recommended actions.

FAQ

FAQ

Can I use an IPA downloaded from the App Store?

App Store builds are encrypted, so they cannot be assessed as is. Please provide an IPA built during development.

Works well with

Mobile App Assessment — details and demo requests

Our team will explain deployment options and pricing for your environment.