KodFixerSecurity
Beta

Find what scanners miss
in mobile binaries.

Upload an APK or IPA. KodFixer decompiles it, runs 67+ SAST checks, hunts for hardcoded secrets, maps every API endpoint, and scores the risk — in under 30 seconds.

$ Free tier: 3 scans/month · No credit card

kodfixer — scan

$ kodfixer scan app-release.apk

Decompiling binary...

Running 67 SAST patterns...

Scanning for secrets...

Extracting endpoints...

CRITICAL SQL Injection (CWE-89) — MainActivity.java:42

CRITICAL Hardcoded AWS Key — BuildConfig.java:8

HIGH Cert Pinning Bypass — NetworkHelper.java:15

HIGH Cleartext HTTP — ApiClient.java:23

MEDIUM Log Leakage — Utils.java:91

12 findings · 3 critical · 4 high · Risk: 8.5/10

67+

SAST Rules

<30s

Avg Scan Time

16

Secret Patterns

APK/IPA

Binary Support

How it works

Upload. Decompile. Report.

01

Upload binary

Drop your .apk, .aab, or .ipa file. We accept up to 500MB.

02

Automated analysis

Decompilation, SAST scanning, secret detection, endpoint mapping, and AI assessment run in parallel.

03

Actionable report

Severity-ranked findings with affected code, CWE references, exploit scenarios, and fix guidance.

Capabilities

What gets scanned

Binary Decompilation

APK, AAB, and IPA files are decompiled with apktool, jadx, and plistutil. Full source recovery from production binaries.

Static Analysis (SAST)

SQL injection, XSS, XXE, path traversal, insecure crypto, certificate pinning bypass, root detection, and 60+ more patterns.

Secret Detection

AWS keys, Firebase configs, Stripe tokens, JWT secrets, private keys, database strings — found and severity-classified automatically.

Shadow API Discovery

Every HTTP endpoint extracted from decompiled source. Categorized as production, staging, internal, or third-party.

AI-Powered Analysis

LLM-driven vulnerability assessment with exploit scenarios, BOLA detection, and remediation guidance for every finding.

Risk Scoring

Weighted 1-10 risk score combining manifest flags, SAST findings, secrets exposure, endpoint security, and platform-specific checks.

Pricing

Start free. Scale when ready.

Free

$0forever

For individual developers

  • 3 scans / month
  • 1 project
  • SAST + secrets
  • Basic risk score
Get started

Pro

$49/ month

For teams shipping mobile apps

  • 50 scans / month
  • 10 projects
  • AI vulnerability analysis
  • PDF reports & certificates
  • Priority support
Start free trial

Enterprise

$199/ month

For security teams at scale

  • Unlimited scans
  • Unlimited projects
  • BOLA engine + deep review
  • SIEM / Firewall integrations
  • White-label & API access
  • SSO & RBAC
Contact us

See what's hiding in your binaries.

Upload your first APK or IPA — results in under a minute.

Start scanning free