Ross ROSS = Recommend OSS · open-source software intelligence for agents

sulab999/AppMessenger

一款适用于以APP病毒分析、APP漏洞挖掘、APP开发、HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、鸿蒙)辅助分析工具 observed · 2026-08-28

github.com/sulab999/AppMessenger · homepage observed · 2026-08-28

Health v2 · maintenance only

86/100

  • Activity 87
  • Release rhythm 76
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 68.5
  • age_days: 2810
  • days_rel: 83
  • days_push: 83
  • n_releases_24m: 7

Full methodology

Adoption not part of the score

1308 stars · 111 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

AppMessenger is a free cross-platform (Windows/Mac/Linux, Java-based) GUI tool for analyzing mobile application packages including APK (Android), IPA (iOS), and HAP (HarmonyOS) files. It extracts key asset information such as package name, version, signatures, MD5 hashes, SDKs, URLs, and IPs, and performs vulnerability detection, packer/obfuscation identification, and sensitive information scanning for security analysts and penetration testers.

Use cases

  • analyze apk files for package name, version, and signature info
  • detect android app packers and obfuscation
  • find vulnerabilities in android apps
  • extract urls and ips from mobile apps during pentesting
  • scan ipa files for sensitive information
  • parse harmonyos hap packages
  • generate mobile app security assessment reports
  • identify sdk api keys leaked in mobile apps

When to choose

  • you need quick static analysis of APK/IPA/HAP files without deep reverse engineering
  • you are a red team or HW action member collecting asset info from mobile apps
  • you want automated packer detection and basic vulnerability checks on Android apps
  • you need to generate security assessment documents for mobile apps

When to avoid

  • you need dynamic analysis, runtime instrumentation, or Frida-based testing
  • you require APK repackaging, which is not supported
  • you need deep decompilation and code-level reverse engineering
  • you need a fully open-source tool with auditable source code

Facets

application · maturity active

security vulnerability-scanning parser developer-tools reverse-engineering security mobile-development penetration-testing reverse-engineering windows cross-platform jvm android ios harmonyos apk-analysis ipa-analysis hap-analysis malware-analysis red-team pentesting gui-tool packer-detection sensitive-info-detection macos linux

2 sources

Member repositories

RepositoryRoleHealth v2
sulab999/AppMessengermain86

For agents

markdown · JSON · MCP: product_card(name="sulab999/AppMessenger")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem