Known weaknesses.
INSECURE DATA STORAGE
Sensitive values in preferences, files, logs or caches.
INSECURE COMMUNICATION
Unencrypted traffic, or validation disabled.
HARD-CODED SECRETS
Extracted trivially from the binary.
WEAK AUTHORISATION
Decisions made client-side, or identifiers that can be altered.
EXPOSED COMPONENTS
Application components callable by other applications unintentionally.
WHAT TO DO ABOUT THAT
Export only what must be, and validate everything received.
INSECURE DEEP LINKS
Links triggering actions without verification.
WHAT TO DO
Treat link parameters as untrusted input.
EXCESSIVE PERMISSIONS
Requesting more than needed, which reviewers and users notice.
LOGGING SENSITIVE DATA
Which persists and may be collected.
VULNERABLE DEPENDENCIES
WHAT TO DO
Scan them, and update routinely.
WHAT TO RUN
Automated security scanning on every build.
WHAT TO CONSIDER
An independent review, for applications handling money or sensitive data.