# MobSF/Mobile-Security-Framework-MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

Repository: https://github.com/MobSF/Mobile-Security-Framework-MobSF
Canonical: https://ross.abutalabs.com/products/mobile-security-framework-mobsf
Homepage: https://opensecurity.in
Language: JavaScript
License: GPL-3.0
License Family: copyleft
Topics: static-analysis, dynamic-analysis, mobsf, android-security, mobile-security, windows-mobile-security, ios-security, api-testing, web-security, malware-analysis, runtime-security, devsecops, apk, rest, cwe, owasp, mstg, masvs, mastg
Last push: 2026-08-26T02:15:16+00:00

## Health v2 (maintenance only)
Score: 94/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 85, longevity 100
- inputs: {"age_days": 4232, "days_push": 8, "days_rel": 23, "gap_med": 64, "n_releases_24m": 10}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 21650, forks 3755 (observed 2026-08-28T04:11:31.904761+00:00)

## What it is
MobSF is an automated all-in-one mobile application security testing framework for Android, iOS, and Windows Mobile apps. It performs static and dynamic analysis of APK, IPA, and APPX binaries or source code, with REST APIs and CLI tools for DevSecOps/CI-CD integration.

## Use cases
- scan an android apk for security vulnerabilities
- static analysis of an ios ipa binary
- dynamic analysis and runtime instrumentation of mobile apps
- mobile app malware analysis
- integrate mobile security scanning into ci/cd pipeline
- check mobile app against owasp masvs
- analyze mobile app privacy issues
- penetration test an android application

## When to choose
- you need automated static and dynamic analysis of android, ios, or windows mobile apps in one tool
- you want to integrate mobile app security scanning into a devsecops or ci/cd pipeline via rest api
- you need malware or privacy analysis of mobile binaries like apk, ipa, or appx

## When to avoid
- you need to scan web applications or server-side code rather than mobile apps
- you require deep manual reverse engineering rather than automated assessment
- you need a lightweight single-purpose scanner rather than a full framework with emulator setup

## Facets
- artifact type: framework
- maturity: active
- function: penetration-testing, vulnerability-scanning, security, testing, api-framework, cli, web-scraping
- domain: security, penetration-testing, mobile-development, reverse-engineering, privacy
- platform: windows, python, self-hosted, cli
- tags: mobile-security, android, ios, apk-analysis, ipa-analysis, static-analysis, dynamic-analysis, malware-analysis, owasp-masvs, devsecops, rest-api, appsec, devops, linux, macos, docker, web-server

## Member repositories
- MobSF/Mobile-Security-Framework-MobSF (main) score 94

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:31.904761+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T16:57:50.929067+00:00, confidence not recorded.
  - readme: https://github.com/MobSF/Mobile-Security-Framework-MobSF (fetched 2026-08-28T04:11:31.904761+00:00, sha fe16c70aa3f6)
  - homepage: https://opensecurity.in (fetched 2026-08-29T07:56:46.401226+00:00, sha b84e5455dcbd)
- Data as of 2026-08-30T08:39:29.467469+00:00.
