AppKavo

VulnerableApp

com.testapp.vulnerablev1.0.36 October 2026
45
/ 100
D · Poor

Overall score

Based on 16 findings across security, architecture and production-readiness checks.

4 critical 5 high 6 medium 1 low
FrameworkANDROID_NATIVE
Target SDK28
Permissions4
Files scanned6

Score by category

memory
100
appstore
96
security
0
performance
100
architecture
100

Requested permissions

READ_CONTACTSACCESS_FINE_LOCATIONREAD_SMSINTERNET

AI Agent Security Assessment

AI Security Score
56
HIGH Risk
9
Controls Met
7
Violations
16
Total Controls

Violated AI Security Controls

AI-SEC-002
API Key & Credential Management
Authentication
AI-SEC-007
Error Handling & Secure Failures
Error Handling
AI-SEC-008
Monitoring & Anomaly Detection
Monitoring
AI-SEC-003
Sensitive Data in Prompts
Privacy
AI-SEC-009
AI Service Authentication & Authorization
Authentication
AI-SEC-013
Data Retention & Deletion
Privacy
AI-SEC-010
Third-Party AI Service Risk Management
Third-Party Integration

OWASP MASVS Compliance

Level 1 (Basic)
44%
8/18 controls met
Level 2 (Advanced)
45%
9/20 controls met
Level R (Resilience)
75%
3/4 controls met

Violated Controls (12)

MASVS-CODE-2MASVS-CODE-3MASVS-STORAGE-1MASVS-CRYPTO-1MASVS-STORAGE-2MASVS-NETWORK-1MASVS-NETWORK-2MASVS-PLATFORM-2MASVS-CODE-4MASVS-PRIVACY-1MASVS-PLATFORM-1MASVS-RESILIENCE-1

Findings (16)

Critical security CWE-489

App is debuggable in production

AndroidManifest.xml:1
android:debuggable="true"

Your app is shipping in debug mode. This lets anyone connect to your app, read its internal data, and inspect how it works. It must be turned off before release.

How to fix

Remove android:debuggable="true" from the <application> tag, or set debuggable false in your release build type.

Estimated effort: 5 min
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Debug mode in production violates build configuration requirements

AI Security Risks

Debug mode in production → API keys, prompts, and responses visible in debug output

Critical security CWE-798

Google API Key found in source

res/values/strings.xml:4
AIzaSyD-…WY

A Google API Key is stored directly in your app's files. Anyone can extract this from your published app in minutes and use it — potentially running up bills on your account or accessing your backend. This is the most common serious issue we find.

How to fix

Remove the Google API Key from the code. Store secrets on your backend server and have the app request them at runtime, or use a secrets manager. If this key was exposed, rotate (regenerate) it immediately.

Estimated effort: 1 hour
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Hardcoded secrets violate secure storage and encryption requirements

AI Security Risks

Hardcoded API keys for AI services → Anyone with code access can use your API quota and access sensitive data

Critical security CWE-798

Stripe Secret Key found in source

res/values/strings.xml:8
sk_live_…dc

A Stripe Secret Key is stored directly in your app's files. Anyone can extract this from your published app in minutes and use it — potentially running up bills on your account or accessing your backend. This is the most common serious issue we find.

How to fix

Remove the Stripe Secret Key from the code. Store secrets on your backend server and have the app request them at runtime, or use a secrets manager. If this key was exposed, rotate (regenerate) it immediately.

Estimated effort: 1 hour
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Hardcoded secrets violate secure storage and encryption requirements

AI Security Risks

Hardcoded API keys for AI services → Anyone with code access can use your API quota and access sensitive data

Critical security CWE-798

Razorpay Key found in source

res/values/strings.xml:6
rzp_live…2P

A Razorpay Key is stored directly in your app's files. Anyone can extract this from your published app in minutes and use it — potentially running up bills on your account or accessing your backend. This is the most common serious issue we find.

How to fix

Remove the Razorpay Key from the code. Store secrets on your backend server and have the app request them at runtime, or use a secrets manager. If this key was exposed, rotate (regenerate) it immediately.

Estimated effort: 1 hour
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Hardcoded secrets violate secure storage and encryption requirements

AI Security Risks

Hardcoded API keys for AI services → Anyone with code access can use your API quota and access sensitive data

High security CWE-319

Cleartext (HTTP) traffic allowed

AndroidManifest.xml:1
android:usesCleartextTraffic="true"

Your app allows unencrypted network connections. Data sent over these connections can be read or modified by anyone on the same network (public WiFi, etc).

How to fix

Set android:usesCleartextTraffic="false" and ensure all API calls use HTTPS. Use a network security config to enforce it.

Estimated effort: 30 min
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Unencrypted data transmission violates TLS/encryption requirements

AI Security Risks

Unencrypted API calls → AI credentials and prompts exposed in transit

High security CWE-927

Exported components without permission protection

AndroidManifest.xml:1
<activity android:name="com.testapp.MainActivity" android:exported="true">

A part of your app (MainActivity) is open to other apps on the device without any protection. Malicious apps could trigger it or send it data.

How to fix

Add android:permission to the activity, or set android:exported="false" if it doesn't need to be accessed by other apps.

Estimated effort: 15 min
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Unprotected exported components violate platform security

AI Security Risks

Exported component with AI credentials → Third-party can access AI services

High security CWE-927

Exported components without permission protection

AndroidManifest.xml:1
<service android:name="com.testapp.SyncService" android:exported="true">

A part of your app (SyncService) is open to other apps on the device without any protection. Malicious apps could trigger it or send it data.

How to fix

Add android:permission to the service, or set android:exported="false" if it doesn't need to be accessed by other apps.

Estimated effort: 15 min
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Unprotected exported components violate platform security

AI Security Risks

Exported component with AI credentials → Third-party can access AI services

High security CWE-798

Hardcoded JWT found in source

assets/config.json:4
eyJhbGci…5N

A Hardcoded JWT is stored directly in your app's files. Anyone can extract this from your published app in minutes and use it — potentially running up bills on your account or accessing your backend. This is the most common serious issue we find.

How to fix

Remove the Hardcoded JWT from the code. Store secrets on your backend server and have the app request them at runtime, or use a secrets manager. If this key was exposed, rotate (regenerate) it immediately.

Estimated effort: 1 hour
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Hardcoded secrets violate secure storage and encryption requirements

AI Security Risks

Hardcoded API keys for AI services → Anyone with code access can use your API quota and access sensitive data

High security CWE-798

Hardcoded Secret / Token found in source

assets/config.json:4
auth_tok…N"

A Hardcoded Secret / Token is stored directly in your app's files. Anyone can extract this from your published app in minutes and use it — potentially running up bills on your account or accessing your backend. This is the most common serious issue we find.

How to fix

Remove the Hardcoded Secret / Token from the code. Store secrets on your backend server and have the app request them at runtime, or use a secrets manager. If this key was exposed, rotate (regenerate) it immediately.

Estimated effort: 1 hour
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Hardcoded secrets violate secure storage and encryption requirements

AI Security Risks

Hardcoded API keys for AI services → Anyone with code access can use your API quota and access sensitive data

Medium security CWE-200

Auto backup enabled — app data exposed

AndroidManifest.xml:1
android:allowBackup="true"

Your app's data can be copied off the device through Android backup. If it stores anything sensitive (tokens, user data), that data leaves the device unprotected.

How to fix

Set android:allowBackup="false" in the <application> tag unless you specifically need backups.

Estimated effort: 5 min
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Sensitive data exposed to unauthorized parties

AI Security Risks

Sensitive data exposure → Including via error messages leaking to LLM or exposed in logs

Medium security CWE-250

Sensitive permissions requested

AndroidManifest.xml:1
android.permission.READ_CONTACTS
android.permission.ACCESS_FINE_LOCATION
android.permission.READ_SMS

Your app requests permissions to: read all contacts, precise GPS location, read SMS messages. Each sensitive permission you request that isn't strictly needed increases privacy risk and can hurt Play Store approval. Review whether all of these are required.

How to fix

Remove any permission from AndroidManifest.xml that your app does not actively use. Request sensitive permissions at runtime, only when the feature is used.

Estimated effort: 30 min
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Excessive permissions violate principle of least privilege

AI Security Risks

Excessive permissions → AI service can access more data/features than needed

Medium appstore CWE-1035

Target SDK version is outdated

AndroidManifest.xml:1
targetSdkVersion="28"

Your app targets an older Android version (API 28). Google Play requires recent target versions for new apps and updates. An old target also misses newer security protections.

How to fix

Update targetSdkVersion to 34 or higher in build.gradle and test thoroughly.

Estimated effort: 2 hours
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Dependencies with known vulnerabilities bypass security controls

AI Security Risks

Vulnerable AI SDK or dependency → Compromise of LLM integration layer

Medium security CWE-798

Firebase Database URL found in source

assets/config.json:5
https://…om

A Firebase Database URL is stored directly in your app's files. Anyone can extract this from your published app in minutes and use it — potentially running up bills on your account or accessing your backend. This is the most common serious issue we find.

How to fix

Remove the Firebase Database URL from the code. Store secrets on your backend server and have the app request them at runtime, or use a secrets manager. If this key was exposed, rotate (regenerate) it immediately.

Estimated effort: 1 hour
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Hardcoded secrets violate secure storage and encryption requirements

AI Security Risks

Hardcoded API keys for AI services → Anyone with code access can use your API quota and access sensitive data

Medium security CWE-295

No certificate pinning detected

Certificate pinning configuration
1 dex file and 0 res/xml files scanned — no pin-set element or known pinning library found

The app does not appear to pin certificates — neither a Network Security Config <pin-set> nor a known pinning library (OkHttp, TrustKit) was found. Without pinning, a compromised or coerced Certificate Authority (or a device with a malicious root CA installed) can intercept the app's traffic even over HTTPS.

How to fix

Add a Network Security Config with a <pin-set> for your API domains, or use a library like OkHttp's CertificatePinner or TrustKit.

Estimated effort: 2-4 hours
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Improper TLS validation allows MITM attacks, violates network security

AI Security Risks

MITM attacks possible → API credentials and sensitive data intercepted

Medium security CWE-693

No root detection found

Root detection
1 dex file scanned — no known root-detection library found

The app does not appear to check whether it is running on a rooted device — no known root-detection library (RootBeer, Play Integrity, SafetyNet, freeRASP) was found. On a rooted device, an attacker with elevated privileges can bypass app-level protections, extract secrets from memory, or tamper with the app at runtime.

How to fix

Integrate a root-detection library (Play Integrity API is Google's current recommendation) and respond appropriately (warn, restrict functionality, or block) on rooted devices for sensitive features.

Estimated effort: 1-2 days
Violated MASVS Controls

Missing anti-tampering protection allows attackers to bypass app-level security controls

Low security CWE-295

No network security config defined

AndroidManifest.xml:1
networkSecurityConfig not set

Your app has no network security configuration. This is a missed opportunity to enforce HTTPS-only connections and certificate pinning at the system level.

How to fix

Add a network_security_config.xml restricting cleartext traffic and reference it via android:networkSecurityConfig in the <application> tag.

Estimated effort: 30 min
Defensive Measures (D3FEND)

Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities

Violated MASVS Controls

Improper TLS validation allows MITM attacks, violates network security

AI Security Risks

MITM attacks possible → API credentials and sensitive data intercepted

Scope: This is an automated audit based on static analysis of your app. It catches common security, quality and production-readiness issues but is not a substitute for a full manual security review for apps handling sensitive financial or health data. Findings marked “suspected” are strong signals to confirm against your live setup.

Your data: uploaded code is processed in memory and never written to disk. This report is kept only so you can view it, and auto-deletes after 24 hours.