Android Static Analysis: What the Binary Can Tell You
Android static analysis covers several different activities: checking source code, inspecting a compiled APK and reviewing dependency metadata. Choosing.
Scan an APK for security weaknesses: insecure settings, exposed components, hard-coded secrets, risky permissions, and suspicious code patterns. Not a CVE scan.
APK Vulnerability Scanner is part of APKLint, an online toolkit for inspecting Android APK files. Scan an APK for security weaknesses: insecure settings, exposed components, hard-coded secrets, risky permissions, and suspicious code patterns. Not a CVE scan. Upload an APK in your browser to view the relevant details; results reflect what the file itself exposes.
Drop your file here
or click to choose from your device
Scan an APK for security weaknesses: insecure settings, exposed components, hard-coded secrets, risky permissions, and suspicious code patterns. Not a CVE scan.
APK Vulnerability Scanner is part of APKLint’s security & malware toolkit — Find risky behavior, trackers, and suspicious patterns. It’s free to use and needs no account.
Your privacy is the default: files you upload are processed on our servers over an encrypted connection and permanently deleted by a scheduled hourly cleanup after analysis finishes, and never shared.
Good to know: Finds weaknesses in the app's own configuration and code. It does NOT match bundled libraries against a CVE database.
Every tool is free with no login and no paywall. Reasonable file and input limits keep the free service stable.
A clean, focused interface with no third-party ad banners cluttering your results.
Files you upload are deleted by a scheduled hourly cleanup after analysis finishes, and never shared.
Uses androguard manifest and DEX analysis plus YARA heuristic indicators.
Start immediately — no account, login, or email required.
Runs in any modern browser, on desktop or mobile.
Scan an APK for security weaknesses: insecure settings, exposed components, hard-coded secrets, risky permissions, and suspicious code patterns. Not a CVE scan.
No. It finds configuration and code weaknesses in the APK itself. CVE/dependency matching needs source/lockfiles — not available from a built APK here.
Yes. Every tool on APKLint is completely free, with no sign-up and no account.
Your uploaded file and its result are processed on our servers over an encrypted connection, then removed by the next hourly cleanup after analysis finishes. We never share them.
An Android APK — a .apk file — up to 1 GB.
All product names, logos, and trademarks are property of their respective owners. APKLint is an independent toolset and is not affiliated with, endorsed by, or sponsored by Google, Android, or any other party.