usesCleartextTraffic=true: Scope the Exception, Do Not Disable Security Globally
android:usesCleartextTraffic="true" permits cleartext traffic in participating Android network components; it does not encrypt HTTP or make an insecure.
Detect whether your app allows insecure cleartext (HTTP) traffic, and where to lock it down.
Cleartext Traffic Checker is part of APKLint, an online toolkit for inspecting Android APK files. Detect whether your app allows insecure cleartext (HTTP) traffic, and where to lock it down. Paste your AndroidManifest.xml or network security config in your browser to view the relevant details; results reflect what you paste.
Detect whether your app allows insecure cleartext (HTTP) traffic, and where to lock it down.
Cleartext Traffic Checker is part of APKLint’s manifest & configuration toolkit — Audit your AndroidManifest and security config. It’s free to use and needs no account.
Your privacy is the default: what you submit is processed on our servers over an encrypted connection for that request only — it isn’t written to file or object storage, and never shared.
Good to know: Paste either your AndroidManifest or your network_security_config.xml — it detects which and checks accordingly.
Every tool is free with no login and no paywall. Reasonable file and input limits keep the free service stable.
A clean, focused interface with no third-party ad banners cluttering your results.
What you submit is processed for the request only — it isn't written to file or object storage, and never shared.
Parses the XML or text you paste with a hardened parser (defusedxml).
Start immediately — no account, login, or email required.
Runs in any modern browser, on desktop or mobile.
Detect whether your app allows insecure cleartext (HTTP) traffic, and where to lock it down.
Yes. Paste the manifest or the network security config XML — the tool detects the root element and runs the right check.
Yes. Every tool on APKLint is completely free, with no sign-up and no account.
What you submit is sent to our backend over an encrypted connection only to produce your result. It isn't written to file storage, used for analytics, or shared.
Paste your AndroidManifest.xml or network_security_config.xml.
All product names, logos, and trademarks are property of their respective owners. APKLint is an independent toolset and is not affiliated with, endorsed by, or sponsored by Google, Android, or any other party.