Everything about how Paxio App Checker works, what its results mean, and how its APK analyzer handles your files.
App Checker is a free tool that shows what an Android app declares before you install it. Search any app to see its Google Play permissions, ads, age rating and privacy policy, or upload an APK to see its manifest: permissions, exported components, deep links and certificate pinning.
Yes, it is free and there is no signup or account. Searches and APK uploads are rate-limited so the service stays available for everyone.
Play Store results are fetched live from the app's current Google Play listing, not from a curated database, so they reflect what the developer has published right now. APK results are parsed directly from the file you upload.
No. An uploaded APK is analyzed for that single request and deleted immediately afterward. It is not stored, shared or kept for later.
No. It never touches a device. It reads an app's public Play Store listing or a file you choose to upload, and nothing is installed or run.
No. App Checker reports what an app declares: the permissions it can request, whether it shows ads, its age rating. That is useful evidence, but it is not a review, an endorsement or a safety guarantee, and a permission shows what an app can ask for, not what it does with it.
App Checker is a standalone lookup tool and does not require the Paxio app. Paxio is a separate parental control app for Android that sets screen time limits, blocks apps and filters content on a child's own device.
It is built by the team behind Paxio. Write to support@paxio.in with anything that looks wrong and, if you can, the app name or package ID.
It reads the app's manifest: declared permissions (with risk labels), which activities, services, receivers and providers are exported and reachable by other apps, deep links, and whether certificate pinning is configured in the network security config. It also flags settings such as debuggable and backup.
It analyzes the manifest only, so it does not decompile or run code. Things implemented in code, such as root detection or certificate pinning done with a library like OkHttp, are not detected. It reports pinning only when it is declared in the network security config.
Copy it from a device you control with the Android Debug Bridge. Our step-by-step guide, How to analyze an APK, shows how. Only analyze apps you are allowed to inspect.
The analyzer accepts a single .apk file up to 200 MB. Android App Bundles (.aab) are an upload format for Google Play and are not supported; analyze the APK installed on a device instead.
The usual causes are a file that is not a .apk, a file that is not a valid APK archive, a file over 200 MB, or too many uploads in a short time (uploads are limited to 10 per 15 minutes). Fix the file or wait a few minutes and try again.
"Dangerous" marks permissions that Android asks the user to approve at runtime, such as camera or location. "Exported" marks a component that other apps on the device can reach. Neither means an app is malicious; they are the places worth reading closely.