Guides

Android app security guides

Plain-English explainers on rooting, SSL pinning, accessibility services, sideloading and APK analysis — the concepts behind what App Checker shows you.

Permissions

Android App Permissions Explained: Normal, Dangerous and Special

How Android app permissions work: normal, runtime (dangerous) and special permissions, what one-time and auto-reset do, and how to read an app's list.

October 6, 2026 · 6 min read
Android basics

What Is ADB (Android Debug Bridge)? What It Does and Why Parents Should Know

What ADB is, how USB and wireless debugging work, the commands people use to pull and install apps, the security risks, and why developer options matter.

October 6, 2026 · 6 min read
Android basics

APK vs AAB: What Is an Android App Bundle and Which One Do You Analyze?

The difference between an APK and an AAB (Android App Bundle), how Google Play turns bundles into APKs, why split APKs exist, and which file to analyze.

October 6, 2026 · 5 min read
App security

How Android App Signing Works: Keys, Certificates and APK Signature Schemes

How Android app signing works: why every APK is signed, the v1, v2 and v3 signature schemes, Play App Signing keys, and how to verify an APK's certificate.

October 6, 2026 · 6 min read
App security

Android Deep Links vs App Links: How They Work and How to Check Them

The difference between Android deep links and verified App Links, how Digital Asset Links verification works, the security risks, and how to read them.

October 6, 2026 · 6 min read
Best practices

Android Manifest Security Flags: debuggable, allowBackup, Cleartext and Exported

The AndroidManifest settings that matter for security: debuggable, allowBackup, cleartext traffic, exported components and more, with safe defaults for each.

October 6, 2026 · 6 min read
Android basics

What Is Rooting in Android? Risks, Benefits and How Apps Detect It

What rooting an Android phone actually means, why people do it, the security risks it creates, and how banking and security apps detect a rooted device.

October 3, 2026 · 5 min read
App security

What Is SSL Pinning in Android Apps? How It Works and Where It Falls Short

SSL (certificate) pinning explained for Android: what it protects against, how to configure it, the rotation risks, and what it cannot stop.

October 3, 2026 · 6 min read
Permissions

What Is Android's Accessibility Service, and Why Do Some Apps Ask for It?

What the Android Accessibility Service is for, why parental-control and automation apps request it, how malware abuses it, and when to allow it.

October 3, 2026 · 6 min read
How-to

How to Analyze an APK: A Beginner's Guide to Android Static Analysis

A step-by-step beginner's guide to analyzing an Android APK: getting the file, reading the manifest, checking permissions, signatures and code, safely.

October 3, 2026 · 7 min read
Android basics

What Is Sideloading on Android? Risks, Safeguards and Google's New Verification Rules

Sideloading means installing Android apps outside Google Play. How it works, the real risks, how to check an APK first, and Google's new verification plan.

October 3, 2026 · 6 min read
Best practices

Mobile App Security Best Practices: An Android Developer Checklist

A practical Android security checklist built on the OWASP MASVS: storage, crypto, auth, network, platform, code, resilience and privacy, plus manifest checks.

October 3, 2026 · 7 min read

App Checker FAQ

What is Paxio App Checker?

App Checker is a free tool that shows what an Android app declares before you install it. Search any app to see its Google Play permissions, ads, age rating and privacy policy, or upload an APK to see its manifest: permissions, exported components, deep links and certificate pinning.

Is App Checker free, and do I need an account?

Yes, it is free and there is no signup or account. Searches and APK uploads are rate-limited so the service stays available for everyone.

Where does the data come from?

Play Store results are fetched live from the app's current Google Play listing, not from a curated database, so they reflect what the developer has published right now. APK results are parsed directly from the file you upload.

Is my uploaded APK stored or shared?

No. An uploaded APK is analyzed for that single request and deleted immediately afterward. It is not stored, shared or kept for later.

Does App Checker scan my child's phone?

No. It never touches a device. It reads an app's public Play Store listing or a file you choose to upload, and nothing is installed or run.

Does a result mean an app is safe or unsafe?

No. App Checker reports what an app declares: the permissions it can request, whether it shows ads, its age rating. That is useful evidence, but it is not a review, an endorsement or a safety guarantee, and a permission shows what an app can ask for, not what it does with it.

How is App Checker different from the Paxio app?

App Checker is a standalone lookup tool and does not require the Paxio app. Paxio is a separate parental control app for Android that sets screen time limits, blocks apps and filters content on a child's own device.

Who builds App Checker, and how do I report a problem?

It is built by the team behind Paxio. Write to support@paxio.in with anything that looks wrong and, if you can, the app name or package ID.

See all questions, including APK analysis →