androguard
Androguard is a full python tool to play with Android files.
Decision gist · record as of 2026-08-14
Yes, if you need to analyze Android applications programmatically. The package is actively maintained, has low install friction, permissive licensing, and is battle-tested in production security tools. Be aware that version 4.1.4 represents a substantial rewrite from earlier releases, so existing code may need updates. Documentation is incomplete but improving.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later; earlier Python versions are not supported.
- Low friction installation with a pure-Python wheel.
- Active maintenance with recent releases; the project underwent substantial changes in version 4.0.0 and later, so some older workflows may need adjustment.
License · maintenance · safety
Apache Licence, Version 2.0 (permissive) — Licensed under Apache License 2.0 (permissive). You can use, modify, and distribute the software freely as long as you include a copy of the license and state significant changes.
last release 2026-06-01 (74 days) · last repo commit 2026-08-13 · 6,195 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 2,158,671 downloads/mo, #3,243 on PyPI
Alternatives
Verify before relying
pip install androguard
from androguard.apk import APK
apk = APK('path/to/app.apk')
print(apk.get_package())- Whether the decompiler output is suitable for production reverse-engineering workflows or primarily for analysis.
- Current state of documentation accuracy given the note that it is 'in progress of updating'.
- Stability of the Frida integration for dynamic analysis across different Android versions.
What it is and what it does
Androguard is a comprehensive Python framework for static and dynamic analysis of Android applications. It can parse and extract information from APK files, DEX/ODEX bytecode, Android binary XML, and resource files. The package includes a basic decompiler for DEX bytecode, disassembly capabilities, and integration with Frida for dynamic analysis. It also supports saving analysis sessions to SQLite databases.
The tool is widely used in mobile security research, malware analysis, and app auditing. It serves as a foundation for higher-level security frameworks and is actively maintained, though versions 4.0.0 and later introduced breaking changes from the 3.3.5 release. The package has 14 runtime dependencies including cryptography, lxml, networkx, and IPython, providing a rich ecosystem for programmatic Android app inspection.
Use it for
- Analyze APK files to extract package names, permissions, activities, and other metadata for security audits.
- Disassemble and decompile DEX bytecode to review application logic and identify potential vulnerabilities.
- Integrate Android app analysis into automated security scanning pipelines or malware detection systems.
- Perform dynamic analysis using Frida integration to monitor app behavior at runtime.
- Build custom Android security tools or frameworks that need programmatic access to app internals.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to analyze Android applications programmatically.
The package is actively maintained, has low install friction, permissive licensing, and is battle-tested in production security tools. Be aware that version 4.1.4 represents a substantial rewrite from earlier releases, so existing code may need updates. Documentation is incomplete but improving.
Install
androguard on PyPI
Before you install
Low friction installation with a pure-Python wheel. Active maintenance with recent releases; the project underwent substantial changes in version 4.0.0 and later, so some older workflows may need adjustment.
Requires Python 3.9 or later; earlier Python versions are not supported.
License in practice
Licensed under Apache License 2.0 (permissive). You can use, modify, and distribute the software freely as long as you include a copy of the license and state significant changes.
Quickstart
pip install androguard
from androguard.apk import APK
apk = APK('path/to/app.apk')
print(apk.get_package())
Verify before relying
- Whether the decompiler output is suitable for production reverse-engineering workflows or primarily for analysis.
- Current state of documentation accuracy given the note that it is 'in progress of updating'.
- Stability of the Frida integration for dynamic analysis across different Android versions.
Package facts
| License | Apache Licence, Version 2.0 permissive |
| Python support | Supports the current Python release !=2.7.*,!=3.0.*,!=3.1.*,!=3.2.*,!=3.3.*,!=3.4.*,!=3.5.*,!=3.6.*,!=3.7.*,!=3.8.*,>=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 14 packagesapkInspectorasn1cryptoclickcoloramacryptographydatasetipythonlogurulxmlmutf8networkxpydotpygmentspyyaml |
| Maintenance | Actively maintained 74 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 2,158,671 / month, #3,243 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: Other/Proprietary LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14 |
Evidence: androguard-4.1.4-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “dex decompiler”
- androguardAndroguard is a Python tool for analyzing, disassembling, and…
- apkutils2Parses Android APK files to extract and display metadata including…
- hyperliquid-python-sdkPython SDK for trading on the Hyperliquid decentralized exchange API,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also pyaxmlparser · apkInspector · apkutils2 · mobsfscan · mozdevice · google-play-scraper · device-detector · pure-python-adb · adbutils · uiautomator2