Ross ROSS = Recommend OSS · open-source software intelligence for agents

MobSF/Mobile-Security-Framework-MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. observed · 2026-08-28

github.com/MobSF/Mobile-Security-Framework-MobSF · homepage · JavaScript · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

94/100

  • Activity 99
  • Release rhythm 85
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 64
  • age_days: 4232
  • days_rel: 23
  • days_push: 8
  • n_releases_24m: 10

Full methodology

Adoption not part of the score

21650 stars · 3755 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

MobSF is an automated all-in-one mobile application security testing framework for Android, iOS, and Windows Mobile apps. It performs static and dynamic analysis of APK, IPA, and APPX binaries or source code, with REST APIs and CLI tools for DevSecOps/CI-CD integration.

Use cases

  • scan an android apk for security vulnerabilities
  • static analysis of an ios ipa binary
  • dynamic analysis and runtime instrumentation of mobile apps
  • mobile app malware analysis
  • integrate mobile security scanning into ci/cd pipeline
  • check mobile app against owasp masvs
  • analyze mobile app privacy issues
  • penetration test an android application

When to choose

  • you need automated static and dynamic analysis of android, ios, or windows mobile apps in one tool
  • you want to integrate mobile app security scanning into a devsecops or ci/cd pipeline via rest api
  • you need malware or privacy analysis of mobile binaries like apk, ipa, or appx

When to avoid

  • you need to scan web applications or server-side code rather than mobile apps
  • you require deep manual reverse engineering rather than automated assessment
  • you need a lightweight single-purpose scanner rather than a full framework with emulator setup

Facets

framework · maturity active

penetration-testing vulnerability-scanning security testing api-framework cli web-scraping security penetration-testing mobile-development reverse-engineering privacy windows python self-hosted cli mobile-security android ios apk-analysis ipa-analysis static-analysis dynamic-analysis malware-analysis owasp-masvs devsecops rest-api appsec devops linux macos docker web-server

2 sources

Member repositories

RepositoryRoleHealth v2
MobSF/Mobile-Security-Framework-MobSFmain94

For agents

markdown · JSON · MCP: product_card(name="MobSF/Mobile-Security-Framework-MobSF")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem