Moatgator Scan
See what an attacker sees.
Send your app and get a report of the protection gaps in it, graded and mapped to OWASP MASVS. Free.
A first look in minutes.
Scan analyses your app the way an attacker would and maps the findings to OWASP MASVS-RESILIENCE, so you know where you stand and what to fix first.
- APK, AAB and IPA, or a store URL
- Findings mapped to OWASP MASVS
- Fix them with a pull request
What you get
01
APK, AAB and IPA analysis
Send the build you ship. Scan unpacks and analyses it the way a reverse engineer would.
02
A graded report
An A to F grade mapped to OWASP MASVS-RESILIENCE, with every finding tied to a control.
03
Secrets and insecure settings
Hard-coded keys and tokens, cleartext traffic, debuggable flags and other common misconfigurations.
04
No login needed
Start without an account. Reports are delivered by email.
05
A badge for your README
Show "Protected by Moatgator" once your app is hardened.
06
A CLI for your CI
gator-check is an open-source CLI that runs the same checks in your pipeline.
From report to fix
- 1
Send your app
Upload an APK, AAB or IPA, or send a public store URL for a review.
- 2
Read the report
Each finding says what it is, why it matters and what to do about it, in plain language.
- 3
Fix with a pull request
Turn the findings into a pull request that adds Shield and Runtime to your build.
# same checks as Scan, in your CI$ npx gator-check ./app-release.aabWhat Scan checks
Resilience
- Root and jailbreak detection
- Tamper and integrity checks
- Debuggable build flags
- Presence of code obfuscation
Secrets and configuration
- Hard-coded API keys and tokens
- Cleartext traffic allowed
- Backup and exported-component settings
Delivery
- Report mapped to MASVS
- A to F grade
- Link to the fix pull request
Frequently asked questions
Is Scan really free?
Yes. Scan is included on every plan, including the free one.
What do you analyse?
The build you send: an APK, AAB or IPA, or the public version of your app from the store.
What happens to my upload?
Uploads are checked for malware, limited in size and retained only briefly, and the service is protected against abuse.
How is the grade calculated?
From the findings mapped to OWASP MASVS-RESILIENCE, from A for a well-protected app to F for an app with serious gaps.
Can I run Scan in CI?
Yes. The open-source gator-check CLI runs the same checks in your pipeline.
Ready to protect your app?
Start free, or tell us what you need.