# sulab999/AppMessenger

一款适用于以APP病毒分析、APP漏洞挖掘、APP开发、HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、鸿蒙)辅助分析工具

Repository: https://github.com/sulab999/AppMessenger
Canonical: https://ross.abutalabs.com/products/appmessenger
Homepage: https://github.com/sulab999/AppMessenger/wiki
License Family: other
Last push: 2026-06-11T14:45:16+00:00

## Health v2 (maintenance only)
Score: 86/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 87, release rhythm 76, longevity 100
- inputs: {"age_days": 2810, "days_push": 83, "days_rel": 83, "gap_med": 68.5, "n_releases_24m": 7}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1308, forks 111 (observed 2026-08-28T04:04:19.152967+00:00)

## What it is
AppMessenger is a free cross-platform (Windows/Mac/Linux, Java-based) GUI tool for analyzing mobile application packages including APK (Android), IPA (iOS), and HAP (HarmonyOS) files. It extracts key asset information such as package name, version, signatures, MD5 hashes, SDKs, URLs, and IPs, and performs vulnerability detection, packer/obfuscation identification, and sensitive information scanning for security analysts and penetration testers.

## Use cases
- analyze apk files for package name, version, and signature info
- detect android app packers and obfuscation
- find vulnerabilities in android apps
- extract urls and ips from mobile apps during pentesting
- scan ipa files for sensitive information
- parse harmonyos hap packages
- generate mobile app security assessment reports
- identify sdk api keys leaked in mobile apps

## When to choose
- you need quick static analysis of APK/IPA/HAP files without deep reverse engineering
- you are a red team or HW action member collecting asset info from mobile apps
- you want automated packer detection and basic vulnerability checks on Android apps
- you need to generate security assessment documents for mobile apps

## When to avoid
- you need dynamic analysis, runtime instrumentation, or Frida-based testing
- you require APK repackaging, which is not supported
- you need deep decompilation and code-level reverse engineering
- you need a fully open-source tool with auditable source code

## Facets
- artifact type: application
- maturity: active
- function: security, vulnerability-scanning, parser, developer-tools, reverse-engineering
- domain: security, mobile-development, penetration-testing, reverse-engineering
- platform: windows, cross-platform, jvm
- tags: android, ios, harmonyos, apk-analysis, ipa-analysis, hap-analysis, malware-analysis, red-team, pentesting, gui-tool, packer-detection, sensitive-info-detection, macos, linux

## Member repositories
- sulab999/AppMessenger (main) score 86

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:19.152967+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:50:06.412139+00:00, confidence not recorded.
  - readme: https://github.com/sulab999/AppMessenger (fetched 2026-08-28T04:04:19.152967+00:00, sha a1576427370d)
  - homepage: https://github.com/sulab999/AppMessenger/wiki (fetched 2026-08-29T12:08:47.639258+00:00, sha e3e21eb0761d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
