{"categories":[{"label":"Quality Assurance","url":"https://skillfed.io/packages/category/software-development-quality-assurance/3"}],"enrichment":{"capability":"mobsfscan is a static analysis tool that detects insecure code patterns in Android and iOS source code, supporting Java, Kotlin, Swift, Objective-C, and Android XML files.","skillfed_tags":["mobile-security","static-analysis","ci-cd-integration"],"use_cases":["Scan Android Java/Kotlin codebases for insecure WebView implementations, hardcoded credentials, and certificate validation bypasses.","Integrate into CI/CD pipelines to automatically detect mobile security issues before code merges using JSON or SARIF output formats.","Audit iOS Swift/Objective-C projects for common security misconfigurations and insecure API usage patterns.","Generate compliance reports in SonarQube or GitLab SAST formats for security teams and auditors.","Enforce security standards across teams by running mobsfscan as a pre-commit or build-time check with configurable exit codes."],"what_it_does":"mobsfscan is a command-line static analysis tool designed to scan Android and iOS source code for security vulnerabilities and insecure coding patterns. It works by applying pattern-matching rules from the MobSF (Mobile Security Framework) project, powered by semgrep and libsast engines. The tool supports multiple languages\u2014Java, Kotlin, Swift, Objective-C, Android XML, and iOS Info.plist\u2014making it useful for teams developing cross-platform mobile applications.\n\nThe tool outputs findings in multiple formats (JSON, SARIF, SonarQube, GitLab SAST, HTML) and integrates with CI/CD pipelines through command-line options. It can be configured to treat warnings as failures, supports multiprocessing for faster scans, and includes detailed rule metadata (CVSS scores, CWE references, OWASP-MOBILE mappings, MASVS links). The package is actively maintained, supports modern Python versions, and has no known security vulnerabilities.","worth_installing":"Yes. mobsfscan is a mature, actively maintained security scanner with low install friction, no known vulnerabilities, and broad language support for Android and iOS development. The copyleft license (LGPLv3+) is standard for security tools and poses no barrier to internal use. Install it if you develop mobile apps and want automated pattern-based vulnerability detection integrated into your workflow."},"id":"mobsfscan","links":{"html":"https://skillfed.io/packages/mobsfscan","md":"https://skillfed.io/packages/mobsfscan.md","pypi":"https://pypi.org/project/mobsfscan/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-08-10","license_spdx":null,"license_treatment":"copyleft","name":"mobsfscan","python_support":"supports_current","summary":"mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code."},"popularity":{"monthly_downloads":139966,"position":11283,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"1.0.0"}
