# TongchengOpenSource/AppScan

安全隐私卫士（AppScan）一款免费的企业级自动化App隐私合规检测工具。

Repository: https://github.com/TongchengOpenSource/AppScan
Canonical: https://ross.abutalabs.com/products/appscan
Homepage: https://github.com/TongchengOpenSource/AppScan/wiki
Language: JavaScript
License: Apache-2.0
License Family: permissive
Last push: 2025-03-16T03:39:59+00:00

## Health v2 (maintenance only)
Score: 26/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 11, release rhythm 8, longevity 90
- inputs: {"age_days": 1265, "days_push": 535, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1128, forks 134 (observed 2026-08-28T04:03:41.687943+00:00)

## What it is
AppScan is a free, enterprise-grade automated privacy compliance detection tool for Android apps, based on dynamic analysis. It identifies privacy violation risks such as improper personal information collection, permission abuse, and data transmission issues, covering major Chinese regulatory standards like GB/T 35273.

## Use cases
- scan android apps for privacy compliance violations
- detect illegal collection of personal information in mobile apps
- automate app privacy compliance checks before release
- audit app permission requests and data transmission behavior
- check compliance with Chinese cybersecurity law and GB/T 35273
- replace manual code review for app privacy risk detection
- batch-scan multiple apps for privacy risks

## When to choose
- you need automated dynamic-analysis privacy compliance scanning for Android apps
- your app must comply with Chinese privacy regulations like GB/T 35273 or the App violation determination methods
- you want an out-of-the-box tool with no environment setup
- you need to process large batches of apps regularly instead of manual review

## When to avoid
- you need iOS app privacy scanning (Android only)
- your app is hardened/obfuscated or relies on anti-detection third-party SDKs
- you cannot use a real device or supported emulator (requires clearing /data/local/tmp on the device)
- you need a fully mature CI-integrated compliance pipeline with extensive automation

## Facets
- artifact type: application
- maturity: active
- function: security, vulnerability-scanning, monitoring, developer-tools
- domain: security, privacy, mobile-development, android-tools, legal
- platform: windows, cross-platform
- tags: privacy-compliance, app-security, dynamic-analysis, personal-information-protection, regulatory-compliance, china-regulations, gb-t-35273, mobile-app-scanning, macos, android

## Member repositories
- TongchengOpenSource/AppScan (main) score 26

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:41.687943+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:38:31.588521+00:00, confidence not recorded.
  - readme: https://github.com/TongchengOpenSource/AppScan (fetched 2026-08-28T04:03:41.687943+00:00, sha 632dfa08a702)
  - homepage: https://github.com/TongchengOpenSource/AppScan/wiki (fetched 2026-08-29T12:43:07.528156+00:00, sha a96a12a1a107)
- Data as of 2026-08-30T08:39:29.467469+00:00.
