# OWASP/mastg

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

Repository: https://github.com/OWASP/mastg
Canonical: https://ross.abutalabs.com/products/mastg
Homepage: http://mas.owasp.org/
Language: Python
License: CC-BY-SA-4.0
License Family: other
Topics: mobile-app, pentesting, android-application, ios-app, runtime-analysis, network-analysis, static-analysis, reverse-engineering, dynamic-analysis, mobile-security, android, ios, hacking, reverse-enginnering, mstg, testing-cryptography, compliancy-checklist, mast, mastg
Last push: 2026-08-14T05:36:04+00:00

## Health v2 (maintenance only)
Score: 95/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 97, release rhythm 90, longevity 100
- inputs: {"age_days": 3624, "days_push": 19, "days_rel": 64, "gap_med": 2.5, "n_releases_24m": 3}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 13137, forks 2782 (observed 2026-08-28T04:11:02.295283+00:00)

## What it is
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive open-source manual for mobile app security testing and reverse engineering on Android and iOS. It provides technical test cases and processes for verifying OWASP MASWE weaknesses aligned with the MASVS standard, plus downloadable security checklists.

## Use cases
- test android app for security vulnerabilities
- perform ios penetration testing
- learn mobile app reverse engineering
- verify app against owasp masvs standard
- create mobile security compliance checklist
- analyze app network traffic and runtime behavior
- audit mobile app cryptography usage

## When to choose
- you need authoritative, standards-aligned mobile security testing guidance
- you are pentesting or auditing android or ios applications
- you need checklists for mobile app security compliance
- you want free, community-maintained documentation trusted by industry

## When to avoid
- you need an automated scanning tool rather than a manual guide
- you are testing web or desktop applications instead of mobile apps
- you need executable test suites rather than documented procedures

## Facets
- artifact type: learning-resource
- maturity: active
- function: penetration-testing, reverse-engineering, security, testing, documentation
- domain: security, mobile-development, penetration-testing, developer-tools, tutorials
- platform: cross-platform
- tags: mobile-security, owasp, masvs, maswe, pentesting, android, ios, reverse-engineering, static-analysis, dynamic-analysis, checklists

## Member repositories
- OWASP/mastg (main) score 95

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:02.295283+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:13:30.043470+00:00, confidence not recorded.
  - readme: https://github.com/OWASP/mastg (fetched 2026-08-28T04:11:02.295283+00:00, sha afef5dfc0d4d)
  - homepage: http://mas.owasp.org/ (fetched 2026-08-29T08:08:54.639653+00:00, sha 21a2748e1dae)
  - site_page: https://mas.owasp.org/MASWE/MASVS-CODE/MASWE-0045 (fetched 2026-08-29T08:08:54.644152+00:00, sha 4f468f1dcb5a)
  - site_page: https://mas.owasp.org/MASTG/tests/android/MASVS-CODE/MASTG-TEST-0044 (fetched 2026-08-29T08:08:54.645822+00:00, sha 2a39fcc6e4d3)
  - site_page: https://mas.owasp.org/MASVS/02-Frontispiece (fetched 2026-08-29T08:08:54.642326+00:00, sha 7093923b48e4)
- Data as of 2026-08-30T08:39:29.467469+00:00.
