Static analysis · iOS · v3
Ship safer
Ship safer
iOS apps.
A static security scanner for .ipa files. Real Mach-O internals, entitlements, ATS, entropy-aware secrets. All running in your browser. Nothing leaves the tab.
or drop a file anywhere on the page
100% client-side
No upload, no telemetry
Browser-based, no install
~/Downloads/MyApp.ipa
READY
Drop
.ipa to scanor click to select · max 1 GB
Mach-OPIE · Canary · ARC · Code Signature · LC_*
ProvisioningTeam ID · Expiry · Entitlements · Certs
ATSPer-domain TLS · PFS · Pinning · CT
SecretsAWS · Stripe · JWT · PEM · Entropy
App Name
bundle.id
Application
Permissions
URL Schemes
Trackers & SDKs
Findings
0
Checksec
Mach-O Details
Provisioning Profile
Entitlements
App Transport Security
Select a file from Quick Access or the tree