Drop an IPA to start
your security scan.
Binary analysis, secret detection, OWASP scoring, tracker SDKs, transport security and supply-chain CVE matching — results in seconds, grouped and prioritised like the PDF report.
A static analyzer
for iOS apps.
Pavise reads an IPA the way a reviewer would, without running it. It unpacks the archive, parses the Mach-O binary and every manifest inside, and reports what it finds, ordered by how much it matters.
What gets checked
- Binary
- PIE, ARC, stack canaries, NX, RPATH and FairPlay encryption. Also flags risky C and Objective-C APIs like
strcpyandNSLog. - Secrets
- 29 patterns for hardcoded credentials, including AWS, GCP, Azure, GitHub, Stripe, Slack and OpenAI keys. Bundled private keys are flagged too. Matches are masked in the report.
- Manifests
- Info.plist, entitlements, the privacy manifest, permission usage strings and the embedded provisioning profile.
- Transport
- App Transport Security exceptions, cleartext
http://endpoints and certificate pinning. - Trackers
- 20 advertising and analytics SDKs, identified by their frameworks and domains.
- Supply chain
- An inventory of embedded frameworks, with end-of-life library versions (OpenSSL, FFmpeg, Qt, Unity and more) and Firebase configuration issues.
How the grade works
The score starts at 100. Each finding deducts points based on its severity and area: hardening, secrets, network, platform, dependencies or API usage. Each area has a cap, so a pile of weak signals can't outweigh one leaked private key. The result is a grade from A (90 and up) to F (below 40).
A risky API imported by an embedded library is rated one level lower than the same API in the app's own code. Every rule maps to the OWASP Mobile Top 10 (2024) and MASVS v2, so the report shows which risk categories the app falls short on.
What happens to your file
- The IPA is deleted from the server when the scan finishes, including when it fails.
- The result is kept in memory for one hour so you can reopen it or download the PDF and JSON reports. After that it's gone.
- Scan history lives in your browser's local storage, not on the server.
- The web scanner makes no network lookups for your app. DNS, geolocation and CVE queries run only in the CLI, with
--network.
Limits
Static analysis only sees what's in the package. It can't observe runtime behavior, server-side logic or code downloaded after launch. App Store binaries are FairPlay-encrypted, so most of their code is unreadable. Decrypted or development builds give the most complete results.
Run it yourself
The same engine is available as a CLI, a Docker image and a GitHub Action. It outputs JSON, SARIF 2.1.0 for code scanning, HTML or PDF, and exits non-zero on high-severity findings, so it can gate a CI build.
cargo install --locked --git https://github.com/ahmetmutlugun/pavise --bin pavise
pavise App.ipa --format sarif -o report.sarif