Skip to main content
The App Scanner analyzes your mobile application builds for security and privacy issues. Upload an app package and Osto inspects it, then reports vulnerabilities, high-severity findings, privacy risks, and hardcoded secrets.
Path: Scanner → App Scanner
App Scanner page with a Vulnerabilities Overview donut chart and four metric cards: Security Score, High Severity Findings, Privacy Risk, and Hardcoded Secrets

The App Scanner overview after a scan — a vulnerability breakdown plus four posture metrics.

Upload an app

Click Upload Application File (top-left) to open the upload panel, then drag in your file or click to browse.
Upload Application File panel with a drag-and-drop area and supported platforms Android (.apk) and iOS (.ipa)

The Upload Application File panel — drop an .apk or .ipa, up to 100 MB.

Supported platforms and formats: The maximum file size is 100 MB.
Uploading a build only submits it for analysis. Osto never publishes, distributes, or modifies your app.

Vulnerabilities Overview

Once you’ve uploaded an app, the Vulnerabilities Overview summarizes what the scan found — a donut chart breaks the findings down by severity (High / Warning / Info) with an overall risk rating in the center. Until your first scan completes it shows “No scans yet — Upload an app to see vulnerability analysis.” Alongside it, four metric cards give you a quick read on the app’s posture:

Scanned Applications

The Scanned Applications table lists every app you’ve submitted, so you can revisit past results and compare builds over time. Each row shows: Before your first upload it shows “No scanned applications yet — Upload your first application to start security scanning.” Select View Details on any row to open its full report.

The app report

Opening View Details shows the complete analysis for that build.
App report showing app metadata, a security score out of 100, a Critical Findings panel, and tabs for Code Vulnerabilities, Attack Surface, Permissions, Secrets, and Network

A per-app report — metadata, critical findings, and the analysis tabs.

At the top you’ll find the app’s metadata — version, size, target and minimum SDK, and file hashes (MD5 and SHA-256) — next to its score out of 100. A Critical Findings panel highlights the most serious issues first. The report then organizes everything into five tabs:

After a scan

When analysis completes, the Vulnerabilities Overview and the four metric cards populate with results, and the app appears in the Scanned Applications list. Upload a new build whenever you want to re-check an app after addressing its findings.