Upload an APK, AAB or IPA, your source, or just a live URL. AppKavo decodes the binary, hunts hardcoded secrets, and reviews every line across nine categories — including production readiness (crash reporting, analytics, Play Integrity, memory leaks), then hands you a scored report.
Drop in a compiled APK, AAB or IPA. No source code, no setup.
Manifest, hardcoded secrets, dependencies: every line an attacker would read.
A ranked 0–100 report with real severities and fixes, in minutes.
AppKavo runs the same playbook a security researcher would — manifest to bytecode, dependency tree to network config. Before your app ships.
API keys, tokens, and passwords embedded in bytecode or string resources — visible to anyone with apktool.
Exported components, dangerous permissions, backup flags, debuggable build, and network security config.
Network calls without TLS, domain-scoped cleartext exceptions, and certificate pinning coverage gaps.
ECB mode, DES/3DES, MD5/SHA-1 for integrity, static IVs, and insecure random sources in crypto operations.
World-readable files, unprotected SharedPreferences, sensitive data on external storage, and SQLite in cleartext.
CVE lookup against your exact resolved dependency versions — including transitive and framework-bundled libs.
Log.d leaks, BuildConfig.DEBUG flags, test credentials, stack trace exposure, and verbose error dialogs.
R8/ProGuard coverage, class name exposure, and reverse-engineering surface area relative to your risk profile.
Security is only the first gate. AppKavo also tells you whether the stores will accept your app, writes your privacy paperwork, and keeps watching after you ship.
Predicts Google Play and App Store rejections from your APK, AAB or IPA, ranked as blocker, risk or check. Kept separate from your security score.
Reads the SDKs and permissions in your build and drafts the Play Data Safety form, the Apple privacy label, and a full privacy policy.
Every night we re-check your app against current store rules and email you when a new rule turns into a blocker.
Install size against store limits, dex method count against the 64K limit, and duplicated or uncompressed assets. No device needed.
Paste your store listing URL. We check title and description against current store limits, plus your Apple keywords field.
IPA audits read Info.plist, entitlements and App Transport Security, and flag apps still calling Apple's deprecated receipt endpoint.
Paste a deployed URL, no signup. A read-only check for keys leaked in the bundle, an open Supabase or Firebase backend, missing headers and exposed source maps.
Finds endpoints from your OpenAPI spec or GraphQL schema, then flags ones that answer without auth, leak error details, or show no rate limit.
Captures real screens from a connected device and checks colors, type, spacing and touch targets against your chosen design system.
Connect GitHub to audit any repo, public or private, without zipping anything. Pushed commits get reviewed automatically.
AI tools sometimes import packages that don't exist, and attackers register those names. We flag any npm or PyPI dependency missing from its registry.
Every audited commit becomes a restore point on its branch. If an AI session breaks things later, reset to the last audited commit.
Your dependencies are re-checked against the OSV database every night, so a CVE published after your audit still reaches you. Sync from CI with @appkavo/watch.
Re-audits show the difference: new dependencies, new permissions and exported components, and changes to the data your app collects.
A CycloneDX 1.5 software bill of materials from your manifests and lockfiles, for EU Cyber Resilience Act reporting.
Embed a live score badge in your README or website. It updates every time you re-audit.
We email you 30, 14, 7 and 1 days before an APNs certificate or FCM key expires, because push silently stops when it does.
An Android SDK that detects rooted devices, emulators, debuggers, hooking tools and re-signed copies of your app at runtime, and can block them.
Beyond the binary: AppKavo reads your actual source, dependency tree, and config files to surface vulnerabilities no APK scan can find.
Every file, every function — two passes at once. A fast static engine catches injection points, hardcoded secrets, and anti-patterns in seconds. Then Claude reviews the logic a regex can't see: broken auth flows, race conditions, N+1 queries, and architecture flaws.
Every finding ships with a copy-paste prompt. Drop it into Cursor, Claude, or Lovable and get the fix applied. No hunting through raw output.
A review isn't one pass. AppKavo scores your source across nine categories, grouped into three lenses, so a clean bill of health actually means clean.
RUN A FREE AUDITDecompiled and picked apart, byte by byte, then handed back as a ranked list of exactly what they'd find. Before they find it.
Every plan runs the full security engine. You pay for volume, not features.
Compiled Android (.apk, .aab) and iOS (.ipa) builds up to 500 MB, from any framework: Kotlin, Java, Swift, React Native, Flutter, Xamarin or Cordova. For Code Review, upload a .zip of your source (up to 300 MB) or connect GitHub and pick a repo. Live URL Scan and API Audit only need a URL.
Uploads are processed in memory and never written to disk, and full reports auto-delete after 24 hours. We keep a short summary of each audit and a snapshot of each project (dependencies, permissions, store metadata) so re-audits can show what changed and Watch can alert you. Both are deleted when you delete your account. Details are in our Privacy Policy.
Binary audits (APK, AAB, IPA) are deterministic static analysis: we decode the build, read the manifest or Info.plist, and run signature checks for secrets, crypto, network config and storage. Code Review adds a second pass by Claude, Anthropic’s AI. Excerpts from your largest developer-written files are sent to Anthropic’s API, which reviews the logic a static rule can’t see and writes a fix for each finding.
Yes. It only does what any visitor’s browser could do: read-only requests, no exploit payloads, no login attempts and no writes. The same rule applies to the API & Backend Audit.
Yes, for dependency monitoring. The @appkavo/watch CLI and GitHub Action send your manifests and lockfiles to Continuous Watch on every push, and --fail-on=critical fails the build when a critical vulnerability is found. Connect the GitHub App and pushed commits are reviewed automatically too.
That audit type pauses until the 1st of next month, and everything else keeps working. Upgrade at any time for higher limits, or go Pro for no limits at all.
Audit your APK and review your next PR in the same five minutes. No card needed for the free plan.