SUMMARY
ISSUES SEVERITY
MANIFEST SCANNER
exported activity
MEDIUM
resources/AndroidManifest.xml
VULNERABILITIES
weak crypto algorithms
LOW
sources/com/ss/mediakit/vcnlib/X509Util.java
STRINGS
facebook client id
LOW
resources/res/values/strings.xml
ASSETS
relative endpoint
LOW
sources/internal/network/JagoSdkSavingsDeactivateConfigApi.java
0 CRITICAL severity MANIFEST issues present
0 HIGH severity MANIFEST issues present
16 MEDIUM severity MANIFEST issues present
0 LOW severity MANIFEST issues present
0 INFO severity MANIFEST issues present
0 RESILIENCE severity MANIFEST issues present
0 CRITICAL severity VULNERABILITIES issues present
0 HIGH severity VULNERABILITIES issues present
19 MEDIUM severity VULNERABILITIES issues present
45 LOW severity VULNERABILITIES issues present
80 INFO severity VULNERABILITIES issues present
0 RESILIENCE severity VULNERABILITIES issues present
0 CRITICAL severity STRINGS issues present
0 HIGH severity STRINGS issues present
4 MEDIUM severity STRINGS issues present
249 LOW severity STRINGS issues present
0 INFO severity STRINGS issues present
0 RESILIENCE severity STRINGS issues present
0 CRITICAL severity ASSETS issues present
0 HIGH severity ASSETS issues present
0 MEDIUM severity ASSETS issues present
3837 LOW severity ASSETS issues present
0 INFO severity ASSETS issues present
0 RESILIENCE severity ASSETS issues present
ISSUES
Weak Crypto Algorithms - 19 issues
Weak Crypto Algorithm - AES with weak ECB - 2 issues
Possible Object Deserialization - 4 issues
Insecure Random Used - 74 issues
CBC Padding Oracle Attack Possible - 10 issues
Accept Self Signed Certificate - 6 issues
WebView ignores SSL errors - 2 issues
Insecure Activity Start - 5 issues
Storage of sensitive information in Shared Preferences - 8 issues
Check for rooted device by app - 6 issues
WebView javascript enabled - 6 issues
Frida server detection by app - 1 issues
Remote WebView debugging enabled - 1 issues
MALWARES
0
MALWARES
APKiD
16
APKiD
STRINGS
Facebook Client ID - 1 matches
Generic API Key - 1 matches
Facebook Oauth - 1 matches
Generic Secret Key - 2 matches
Google API Key - 3 matches
Generic Basic Auth token - 1 matches
ASSETS
Relative Endpoint - 8 matches
REST API - 777 matches
URL - 1712 matches
File path - 543 matches
Hostname - 275 matches
Filename - 156 matches
PERMISSIONS SUMMARY
Permissions
Count
Safe
16
Risky
13
Dangerous
0
ASSETS WORDCLOUD
www.gojek.com - 23 count
consumer-app-23d4b.firebaseio.com - 1 count
gofood.link - 1 count
customer-tagihan.gopayapi.com - 1 count
api.gojekapi.com - 3 count
api-cons.go-life.co.id - 1 count
customer.gopayapi.com - 3 count
merchants-gws-app.gopayapi.com - 1 count
www.go-jek.com - 4 count
journeyapps.com - 1 count
github.com - 1 count
api.midtrans.com - 2 count
gate-integration.go-life.co.id - 2 count
gate.go-life.co.id - 2 count
go-jek.com - 1 count
TRACKERS
8
TRACKERS
THIRD PARTY LIBRARIES
94
THIRD PARTY LIBRARIES
CONTACT
Website
Email
HIDE REPORT
Are you the developer or owner of this app? Choose to keep your report private from BeVigil's Search for 30 days.