Plain-English explainers on rooting, SSL pinning, accessibility services, sideloading and APK analysis — the concepts behind what App Checker shows you.
How Android app permissions work: normal, runtime (dangerous) and special permissions, what one-time and auto-reset do, and how to read an app's list.
What ADB is, how USB and wireless debugging work, the commands people use to pull and install apps, the security risks, and why developer options matter.
The difference between an APK and an AAB (Android App Bundle), how Google Play turns bundles into APKs, why split APKs exist, and which file to analyze.
How Android app signing works: why every APK is signed, the v1, v2 and v3 signature schemes, Play App Signing keys, and how to verify an APK's certificate.
The difference between Android deep links and verified App Links, how Digital Asset Links verification works, the security risks, and how to read them.
The AndroidManifest settings that matter for security: debuggable, allowBackup, cleartext traffic, exported components and more, with safe defaults for each.
What rooting an Android phone actually means, why people do it, the security risks it creates, and how banking and security apps detect a rooted device.
SSL (certificate) pinning explained for Android: what it protects against, how to configure it, the rotation risks, and what it cannot stop.
What the Android Accessibility Service is for, why parental-control and automation apps request it, how malware abuses it, and when to allow it.
A step-by-step beginner's guide to analyzing an Android APK: getting the file, reading the manifest, checking permissions, signatures and code, safely.
Sideloading means installing Android apps outside Google Play. How it works, the real risks, how to check an APK first, and Google's new verification plan.
A practical Android security checklist built on the OWASP MASVS: storage, crypto, auth, network, platform, code, resilience and privacy, plus manifest checks.
App Checker is a free tool that shows what an Android app declares before you install it. Search any app to see its Google Play permissions, ads, age rating and privacy policy, or upload an APK to see its manifest: permissions, exported components, deep links and certificate pinning.
Yes, it is free and there is no signup or account. Searches and APK uploads are rate-limited so the service stays available for everyone.
Play Store results are fetched live from the app's current Google Play listing, not from a curated database, so they reflect what the developer has published right now. APK results are parsed directly from the file you upload.
No. An uploaded APK is analyzed for that single request and deleted immediately afterward. It is not stored, shared or kept for later.
No. It never touches a device. It reads an app's public Play Store listing or a file you choose to upload, and nothing is installed or run.
No. App Checker reports what an app declares: the permissions it can request, whether it shows ads, its age rating. That is useful evidence, but it is not a review, an endorsement or a safety guarantee, and a permission shows what an app can ask for, not what it does with it.
App Checker is a standalone lookup tool and does not require the Paxio app. Paxio is a separate parental control app for Android that sets screen time limits, blocks apps and filters content on a child's own device.
It is built by the team behind Paxio. Write to support@paxio.in with anything that looks wrong and, if you can, the app name or package ID.