Skip to content
Solvex Space

Cybersecurity · free, no signup

Mobile App Permission Auditor

Paste an AndroidManifest.xml or Info.plist and see the permissions, exported components and transport settings it declares, with what each one grants in practice. A permission is a capability the app can use at any time, not a promise about what it does — so findings describe reach rather than intent. A manifest fragment that omits the security-relevant elements is reported as insufficient rather than clean, because the checks that would produce the reassurance are exactly the ones that could not run.

Authorized, defensive use only. Check assets you own or lawfully public data. This tool is educational and never provides another party's private data.

Paste an AndroidManifest.xml or Info.plist to see the permissions, exported components and transport settings it declares, and what each one grants in practice. A permission is a capability the app can use at any time, not a promise about what it does — so findings describe reach, never intent.

A fragment that omits the security-relevant elements is reported as insufficient rather than clean: the checks that would produce the reassurance are exactly the ones that could not run. Nothing is uploaded — the manifest is parsed and discarded.

The platform is detected from the document.

What happens to what you enter

  • The analysis runs on Solvex servers. What is recorded afterwards is a SHA-256 hash of your input and a coarse summary of the outcome — never the input itself, and never a result you could be identified from.
  • Tools that read public sources (certificate logs, DNS, a public chain) contact those sources from our servers through a fetcher that refuses private and internal addresses.
  • An email address is stored only where a tool offers to send you a report and you choose to give one.

Limits: ten runs of this tool per minute from one address, and three signed reports per minute. Past that the tool says so and tells you when to try again.

When a free check is not enough

This tool reads what is public and reports what it can see. The Mobile Application Penetration Testing engagement is the authorized, specialist-led version: signed scope, findings proven by hand, a signed report, and a retest.

Explore Mobile Application Penetration Testing
Mobile App Permission Auditor — Solvex Space