Skip to content
Contact us

Moatgator Scan

See what an attacker sees.

Send your app and get a report of the protection gaps in it, graded and mapped to OWASP MASVS. Free.

Scan reportapp-release.aab · OWASP MASVSGrade
Scan report, Grade, No root detection, Hard-coded API key, Debuggable build, Readable strings

A first look in minutes.

Scan analyses your app the way an attacker would and maps the findings to OWASP MASVS-RESILIENCE, so you know where you stand and what to fix first.

  • APK, AAB and IPA, or a store URL
  • Findings mapped to OWASP MASVS
  • Fix them with a pull request

What you get

  • 01

    APK, AAB and IPA analysis

    Send the build you ship. Scan unpacks and analyses it the way a reverse engineer would.

  • 02

    A graded report

    An A to F grade mapped to OWASP MASVS-RESILIENCE, with every finding tied to a control.

  • 03

    Secrets and insecure settings

    Hard-coded keys and tokens, cleartext traffic, debuggable flags and other common misconfigurations.

  • 04

    No login needed

    Start without an account. Reports are delivered by email.

  • 05

    A badge for your README

    Show "Protected by Moatgator" once your app is hardened.

  • 06

    A CLI for your CI

    gator-check is an open-source CLI that runs the same checks in your pipeline.

From report to fix

  1. 1

    Send your app

    Upload an APK, AAB or IPA, or send a public store URL for a review.

  2. 2

    Read the report

    Each finding says what it is, why it matters and what to do about it, in plain language.

  3. 3

    Fix with a pull request

    Turn the findings into a pull request that adds Shield and Runtime to your build.

gator-checkIllustrative example
# same checks as Scan, in your CI$ npx gator-check ./app-release.aab

What Scan checks

Resilience

  • Root and jailbreak detection
  • Tamper and integrity checks
  • Debuggable build flags
  • Presence of code obfuscation

Secrets and configuration

  • Hard-coded API keys and tokens
  • Cleartext traffic allowed
  • Backup and exported-component settings

Delivery

  • Report mapped to MASVS
  • A to F grade
  • Link to the fix pull request

Frequently asked questions

Is Scan really free?

Yes. Scan is included on every plan, including the free one.

What do you analyse?

The build you send: an APK, AAB or IPA, or the public version of your app from the store.

What happens to my upload?

Uploads are checked for malware, limited in size and retained only briefly, and the service is protected against abuse.

How is the grade calculated?

From the findings mapped to OWASP MASVS-RESILIENCE, from A for a well-protected app to F for an app with serious gaps.

Can I run Scan in CI?

Yes. The open-source gator-check CLI runs the same checks in your pipeline.

Ready to protect your app?

Start free, or tell us what you need.