NEW Store readiness & privacy policy generator for Play and App Store

Audit your app.
Down to the last line.

Upload an APK, AAB or IPA, your source, or just a live URL. AppKavo decodes the binary, hunts hardcoded secrets, and reviews every line across nine categories — including production readiness (crash reporting, analytics, Play Integrity, memory leaks), then hands you a scored report.

no source needed for APKs · code never hits disk · reports auto-delete in 24h
Works with SwiftReact NativeFlutterKotlinJavaXamarinCordova
AUDIT
01

Upload your app.

Drop in a compiled APK, AAB or IPA. No source code, no setup.

02

We decode & scan.

Manifest, hardcoded secrets, dependencies: every line an attacker would read.

03

Get your score.

A ranked 0–100 report with real severities and fixes, in minutes.

app-release.apkAPK
73Security score
Hardcoded API keyHIGH
Cleartext trafficMED
Debuggable buildLOW
View full report
Secret foundin app bundle
Report ready73 / 100 · grade C
APK Audit

Everything an attacker would find.

AppKavo runs the same playbook a security researcher would — manifest to bytecode, dependency tree to network config. Before your app ships.

Run a free audit  →
🔑
Hardcoded Secrets

API keys, tokens, and passwords embedded in bytecode or string resources — visible to anyone with apktool.

12 detection patterns
📄
Manifest Analysis

Exported components, dangerous permissions, backup flags, debuggable build, and network security config.

22 manifest checks
🌐
Cleartext Traffic

Network calls without TLS, domain-scoped cleartext exceptions, and certificate pinning coverage gaps.

5 network checks
🔐
Weak Cryptography

ECB mode, DES/3DES, MD5/SHA-1 for integrity, static IVs, and insecure random sources in crypto operations.

8 crypto patterns
💾
Insecure Storage

World-readable files, unprotected SharedPreferences, sensitive data on external storage, and SQLite in cleartext.

7 storage checks
📦
Dependency Vulnerabilities

CVE lookup against your exact resolved dependency versions — including transitive and framework-bundled libs.

Real-time CVE database
🐛
Debug Artifacts

Log.d leaks, BuildConfig.DEBUG flags, test credentials, stack trace exposure, and verbose error dialogs.

Fully automatic
🔒
Code Obfuscation

R8/ProGuard coverage, class name exposure, and reverse-engineering surface area relative to your risk profile.

Decompiler-verified
Platform

One upload. Every check before launch.

Security is only the first gate. AppKavo also tells you whether the stores will accept your app, writes your privacy paperwork, and keeps watching after you ship.

APK / AAB
IPA
GitHub repo
AppKavo
Security score
Store readiness
Privacy docs
01

Get through store review

Store Readiness

Predicts Google Play and App Store rejections from your APK, AAB or IPA, ranked as blocker, risk or check. Kept separate from your security score.

Play + App Store
Privacy & Data Safety

Reads the SDKs and permissions in your build and drafts the Play Data Safety form, the Apple privacy label, and a full privacy policy.

3 documents, one upload
Store policy alerts

Every night we re-check your app against current store rules and email you when a new rule turns into a blocker.

Nightly
Performance Audit

Install size against store limits, dex method count against the 64K limit, and duplicated or uncompressed assets. No device needed.

APK · AAB · IPA
ASO Lint

Paste your store listing URL. We check title and description against current store limits, plus your Apple keywords field.

Play + App Store
iOS builds

IPA audits read Info.plist, entitlements and App Transport Security, and flag apps still calling Apple's deprecated receipt endpoint.

.ipa
02

Audit more than the binary

Live URL Scan Free

Paste a deployed URL, no signup. A read-only check for keys leaked in the bundle, an open Supabase or Firebase backend, missing headers and exposed source maps.

Lovable · Bolt · Replit · v0
API & Backend Audit

Finds endpoints from your OpenAPI spec or GraphQL schema, then flags ones that answer without auth, leak error details, or show no rate limit.

Read-only · no exploit payloads
Design Audit

Captures real screens from a connected device and checks colors, type, spacing and touch targets against your chosen design system.

Material · Apple HIG · WCAG
GitHub, built in

Connect GitHub to audit any repo, public or private, without zipping anything. Pushed commits get reviewed automatically.

Public + private repos
Invented packages

AI tools sometimes import packages that don't exist, and attackers register those names. We flag any npm or PyPI dependency missing from its registry.

npm · PyPI
Audit Checkpoints

Every audited commit becomes a restore point on its branch. If an AI session breaks things later, reset to the last audited commit.

Last 5 per branch
03

Stay safe after launch

Continuous Watch

Your dependencies are re-checked against the OSV database every night, so a CVE published after your audit still reaches you. Sync from CI with @appkavo/watch.

CLI + GitHub Action
What changed

Re-audits show the difference: new dependencies, new permissions and exported components, and changes to the data your app collects.

Re-audit diffs
SBOM

A CycloneDX 1.5 software bill of materials from your manifests and lockfiles, for EU Cyber Resilience Act reporting.

7 ecosystems
Security badge

Embed a live score badge in your README or website. It updates every time you re-audit.

README · website
Credential expiry alerts

We email you 30, 14, 7 and 1 days before an APNs certificate or FCM key expires, because push silently stops when it does.

APNs · FCM
App Shield Coming soon

An Android SDK that detects rooted devices, emulators, debuggers, hooking tools and re-signed copies of your app at runtime, and can block them.

Android SDK

Source-level security,
in every corner.

Beyond the binary: AppKavo reads your actual source, dependency tree, and config files to surface vulnerabilities no APK scan can find.

// deep.source
AI + Static Analysis

Every file, every function — two passes at once. A fast static engine catches injection points, hardcoded secrets, and anti-patterns in seconds. Then Claude reviews the logic a regex can't see: broken auth flows, race conditions, N+1 queries, and architecture flaws.

Static Rules AI Review Secret Scanner
9 Categories Scored
Weighted A–F grade + 0–100 score
Security
28%
Architecture
13%
Quality
11%
Performance
11%
+5 more
37%
Verdict
A
Grade + readiness verdict
on every scan
Secret Scanner
Finds what ships by accident
10 Patterns
0
Fix-Ready Prompts

Every finding ships with a copy-paste prompt. Drop it into Cursor, Claude, or Lovable and get the fix applied. No hunting through raw output.

fix: SQL injection in db/queries.js:42
severity: CRITICAL · effort: 1 hour
Quality Checks
Static + AI analysis across every file
Copy-paste blocks Deep nesting Empty catches No tests found Unpinned deps any type
Checks run
35+
per scan
// what a code audit covers

Every line, read three ways.

A review isn't one pass. AppKavo scores your source across nine categories, grouped into three lenses, so a clean bill of health actually means clean.

RUN A FREE AUDIT
Security & secrets Illustrative findings
D
By severity
3Critical
5High
8Medium
OWASP and CWE mapped
OSV.dev CVE scan
Findings
CRITSQL injectiondb/queries.js:42
CRITHardcoded API keyconfig.js:8
HIGHWeak crypto (MD5)auth/hash.js:19
HIGHBroken session flowauth/session.js:57
MEDExported componentAndroidManifest.xml
lodash 4.17.11 1 vulnerable dep
Architecture & quality Weighted scoring
Category weights
Security28%
Architecture13%
Quality11%
Performance11%
Checks per scan 35+
What it flags
Duplication Deep nesting Dead code Circular deps God objects Untyped surfaces N+1 queries Main-thread work
On the hot path
PERFN+1 in feed loaderfeed.js:210
ARCHCircular importstore, api
Reliability & readiness Illustrative findings
A
Readiness checklist
Crash reportingwired
Analytics trackingwired
Play Integritymissing
Memory-leak hygiene2 leaks
Release hardeningR8 on
Error handling
ERREmpty catch blockupload.js:88
ERRUnhandled rejectionsync.js:33
Test coverage
Critical paths64%
Overall41%
Verdict Ship with fixes
// the premise

We read your app the way an attacker would.

Decompiled and picked apart, byte by byte, then handed back as a ranked list of exactly what they'd find. Before they find it.

A·

Start free. Scale when it pays.

Every plan runs the full security engine. You pay for volume, not features.

Free
Get started risk–free
$0
  • 2 APK/IPA audits / month
  • 3 live URL scans / month
  • 1 design audit / month
  • Expiry alerts for 2 push credentials
  • Full security engine, 0–100 score
Basic
Perfect for solo builders
$10 per month
  • 10 APK/IPA audits & 10 code reviews / month
  • 10 store-readiness checks (Play & App Store)
  • 10 privacy policy & Data Safety generations
  • 10 each: API, design, performance & ASO audits
  • 10 SBOM generations
  • 20 live URL scans / month
  • Continuous Watch for 3 projects
  • AI code review with fix-ready prompts
  • CI sync via CLI or GitHub Action
  • PDF reports with findings
Pro
Built for production teams
$15 per month
  • Everything in Basic, without limits
  • Unlimited audits & code reviews
  • Unlimited store-readiness & privacy generations
  • Unlimited API, design, performance & ASO audits
  • Unlimited SBOMs & live URL scans
  • Continuous Watch for every project
  • PDF reports with findings

Questions we get a lot.

What can I upload?

Compiled Android (.apk, .aab) and iOS (.ipa) builds up to 500 MB, from any framework: Kotlin, Java, Swift, React Native, Flutter, Xamarin or Cordova. For Code Review, upload a .zip of your source (up to 300 MB) or connect GitHub and pick a repo. Live URL Scan and API Audit only need a URL.

Is my code or binary stored after the scan?

Uploads are processed in memory and never written to disk, and full reports auto-delete after 24 hours. We keep a short summary of each audit and a snapshot of each project (dependencies, permissions, store metadata) so re-audits can show what changed and Watch can alert you. Both are deleted when you delete your account. Details are in our Privacy Policy.

How does the AI analysis work?

Binary audits (APK, AAB, IPA) are deterministic static analysis: we decode the build, read the manifest or Info.plist, and run signature checks for secrets, crypto, network config and storage. Code Review adds a second pass by Claude, Anthropic’s AI. Excerpts from your largest developer-written files are sent to Anthropic’s API, which reviews the logic a static rule can’t see and writes a fix for each finding.

Is the Live URL Scan safe to run on my site?

Yes. It only does what any visitor’s browser could do: read-only requests, no exploit payloads, no login attempts and no writes. The same rule applies to the API & Backend Audit.

Can I use it in CI?

Yes, for dependency monitoring. The @appkavo/watch CLI and GitHub Action send your manifests and lockfiles to Continuous Watch on every push, and --fail-on=critical fails the build when a critical vulnerability is found. Connect the GitHub App and pushed commits are reviewed automatically too.

What happens when my plan’s monthly limit runs out?

That audit type pauses until the 1st of next month, and everything else keeps working. Upgrade at any time for higher limits, or go Pro for no limits at all.

Catch it before it ships.

Audit your APK and review your next PR in the same five minutes. No card needed for the free plan.

Start free  → View a sample report