Mobile App Security Best Practices: An Android Developer Checklist

Mobile App Security Best Practices: An Android Developer Checklist

Good mobile app security is a set of small, checkable habits rather than one big feature. This checklist is organized around the OWASP Mobile Application Security Verification Standard (MASVS) and highlights the items you can verify straight from your APK's manifest.

Key takeaways
  • Follow the OWASP MASVS's eight areas: storage, crypto, auth, network, platform, code, resilience and privacy.[1]
  • Keep keys in the Android Keystore[2], use TLS only[3], and never hard-code secrets.
  • Export only the components you must, declare android:exported explicitly[4], and validate every intent and deep link.
  • Verify the final release APK: debuggable off, backup intended, cleartext off, exported components expected.

The framework: OWASP MASVS

The OWASP MASVS groups mobile security requirements into eight areas: STORAGE, CRYPTO, AUTH, NETWORK, PLATFORM, CODE, RESILIENCE and PRIVACY.[1] The companion Mobile Application Security Testing Guide explains how to test each one.[6] The sections below translate them into Android actions.

Storage and cryptography

Authentication

Network communication

Platform interaction: components, intents and WebViews

This is where the manifest matters most, because it declares what other apps on the device can reach. Android's general security tips cover the same ground.[7]

Code quality and resilience

Privacy

Verify the release build, not the source

Security settings can drift between source and shipped build, for example a debug flag that survives or a library that adds an exported component. Inspect the final APK. Upload it to the APK analyzer and confirm: debuggable is off, backup is intended, cleartext traffic is off, every exported component is expected, and pinning is configured if you rely on it. The steps for deeper inspection are in our APK analysis guide.

Frequently asked questions

What is OWASP MASVS?

The Mobile Application Security Verification Standard is an OWASP framework that lists security requirements for mobile apps across eight areas, from storage and cryptography to privacy and resilience.

Should I set allowBackup to false?

If your app stores anything sensitive, yes, or define explicit backup rules that exclude it. Leaving backup on by default can copy private app data into device backups.

Is code obfuscation enough to protect my app?

No. Obfuscation slows down reverse engineering but does not stop it. Real protection comes from keeping secrets and authorization on the server.

How do I check my app for exported components?

Inspect the final APK's manifest. Look for components with android:exported="true" and confirm each is intentional and, where appropriate, permission-guarded. App Checker's analyzer lists them for you.

What are the eight MASVS categories?

MASVS-STORAGE, MASVS-CRYPTO, MASVS-AUTH, MASVS-NETWORK, MASVS-PLATFORM, MASVS-CODE, MASVS-RESILIENCE and MASVS-PRIVACY. Each groups numbered security controls that an app can be verified against.

How do I store secrets securely on Android?

Use the Android Keystore for cryptographic keys, keep long-lived secrets on the server, and never embed API keys or passwords in the app, since anyone can unpack an APK to read them.

What is the OWASP MASTG?

The Mobile Application Security Testing Guide is OWASP's companion to the MASVS. It describes how to test each requirement, with techniques for both Android and iOS.

Should every app use certificate pinning?

No. It is most valuable for high-risk apps such as banking or health. Pinning needs backup pins and a rotation plan, and a mistake can lock users out, so weigh the risk for your app.

How often should I update dependencies?

Regularly, and immediately for known vulnerabilities. Outdated libraries are a common source of exposure, so scan your dependencies and rebuild whenever a security fix is released.

References
  1. OWASP Mobile Application Security Verification Standard (MASVS) — the eight control groups used to organize this checklist.
  2. Android Keystore system — Android Developers — preventing key extraction, secure hardware and StrongBox on Android 9+.
  3. Network security configuration — Android Developers — cleartext traffic disabled by default from API level 28.
  4. Behavior changes: Apps targeting Android 12 — Android Developers — explicit android:exported requirement for components with intent filters.
  5. Unsafe implementation of the TrustManager interface — Android Developers — why custom certificate validation is dangerous.
  6. OWASP Mobile Application Security Testing Guide (MASTG) — how to test each MASVS requirement.
  7. Security tips — Android Developers — general secure-coding guidance for Android.
  8. Android exported components risk — Android Developers — risks of exposing components to other apps.

Analyze an APK →

App Checker FAQ

What is Paxio App Checker?

App Checker is a free tool that shows what an Android app declares before you install it. Search any app to see its Google Play permissions, ads, age rating and privacy policy, or upload an APK to see its manifest: permissions, exported components, deep links and certificate pinning.

Is App Checker free, and do I need an account?

Yes, it is free and there is no signup or account. Searches and APK uploads are rate-limited so the service stays available for everyone.

Where does the data come from?

Play Store results are fetched live from the app's current Google Play listing, not from a curated database, so they reflect what the developer has published right now. APK results are parsed directly from the file you upload.

Is my uploaded APK stored or shared?

No. An uploaded APK is analyzed for that single request and deleted immediately afterward. It is not stored, shared or kept for later.

Does App Checker scan my child's phone?

No. It never touches a device. It reads an app's public Play Store listing or a file you choose to upload, and nothing is installed or run.

Does a result mean an app is safe or unsafe?

No. App Checker reports what an app declares: the permissions it can request, whether it shows ads, its age rating. That is useful evidence, but it is not a review, an endorsement or a safety guarantee, and a permission shows what an app can ask for, not what it does with it.

How is App Checker different from the Paxio app?

App Checker is a standalone lookup tool and does not require the Paxio app. Paxio is a separate parental control app for Android that sets screen time limits, blocks apps and filters content on a child's own device.

Who builds App Checker, and how do I report a problem?

It is built by the team behind Paxio. Write to support@paxio.in with anything that looks wrong and, if you can, the app name or package ID.

See all questions, including APK analysis →