mobsfscan
mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code.
Decision gist · record as of 2026-08-14
Yes. mobsfscan is a mature, actively maintained security scanner with low install friction, no known vulnerabilities, and broad language support for Android and iOS development. The copyleft license (LGPLv3+) is standard for security tools and poses no barrier to internal use. Install it if you develop mobile apps and want automated pattern-based vulnerability detection integrated into your workflow.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later; semgrep and libsast are runtime dependencies that may require system libraries.
- Low install friction with a pure Python wheel and seven runtime dependencies.
- Actively maintained with a recent release (4 days old) and steady repository activity; supports Python 3.10–3.14.
License · maintenance · safety
copyleft license (copyleft) — Licensed under LGPLv3+, a copyleft license requiring derivative works to be distributed under the same terms; acceptable for internal security tooling but constrains commercial redistribution.
last release 2026-08-10 (4 days) · last repo commit 2026-08-10 · 779 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 139,966 downloads/mo, #11,283 on PyPI
Alternatives
Verify before relying
pip install mobsfscan
mobsfscan /path/to/android/or/ios/source
mobsfscan --json --output results.json /path/to/source- Whether semgrep and libsast system dependencies are automatically resolved on all platforms or require manual setup.
- Performance characteristics when scanning large codebases or the effectiveness of multiprocessing strategies (default, billiard, thread).
- Accuracy and false-positive rates compared to other mobile security static analysis tools.
What it is and what it does
mobsfscan is a command-line static analysis tool designed to scan Android and iOS source code for security vulnerabilities and insecure coding patterns. It works by applying pattern-matching rules from the MobSF (Mobile Security Framework) project, powered by semgrep and libsast engines. The tool supports multiple languages—Java, Kotlin, Swift, Objective-C, Android XML, and iOS Info.plist—making it useful for teams developing cross-platform mobile applications.
The tool outputs findings in multiple formats (JSON, SARIF, SonarQube, GitLab SAST, HTML) and integrates with CI/CD pipelines through command-line options. It can be configured to treat warnings as failures, supports multiprocessing for faster scans, and includes detailed rule metadata (CVSS scores, CWE references, OWASP-MOBILE mappings, MASVS links). The package is actively maintained, supports modern Python versions, and has no known security vulnerabilities.
Use it for
- Scan Android Java/Kotlin codebases for insecure WebView implementations, hardcoded credentials, and certificate validation bypasses.
- Integrate into CI/CD pipelines to automatically detect mobile security issues before code merges using JSON or SARIF output formats.
- Audit iOS Swift/Objective-C projects for common security misconfigurations and insecure API usage patterns.
- Generate compliance reports in SonarQube or GitLab SAST formats for security teams and auditors.
- Enforce security standards across teams by running mobsfscan as a pre-commit or build-time check with configurable exit codes.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
mobsfscan is a mature, actively maintained security scanner with low install friction, no known vulnerabilities, and broad language support for Android and iOS development. The copyleft license (LGPLv3+) is standard for security tools and poses no barrier to internal use. Install it if you develop mobile apps and want automated pattern-based vulnerability detection integrated into your workflow.
Install
mobsfscan on PyPI
Before you install
Low install friction with a pure Python wheel and seven runtime dependencies. Actively maintained with a recent release (4 days old) and steady repository activity; supports Python 3.10–3.14.
Requires Python 3.10 or later; semgrep and libsast are runtime dependencies that may require system libraries.
License in practice
Licensed under LGPLv3+, a copyleft license requiring derivative works to be distributed under the same terms; acceptable for internal security tooling but constrains commercial redistribution.
Quickstart
pip install mobsfscan
mobsfscan /path/to/android/or/ios/source
mobsfscan --json --output results.json /path/to/source
Verify before relying
- Whether semgrep and libsast system dependencies are automatically resolved on all platforms or require manual setup.
- Performance characteristics when scanning large codebases or the effectiveness of multiprocessing strategies (default, billiard, thread).
- Accuracy and false-positive rates compared to other mobile security static analysis tools.
Package facts
| License | copyleft license copyleft |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 7 packagescoloramalibsastsemgrepsarif-omjschema-to-pythontabulatexmltodict |
| Maintenance | Actively maintained 4 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 139,966 / month, #11,283 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: GNU Lesser General Public License v3 or later (LGPLv3+)Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14 |
Evidence: mobsfscan-1.0.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “android ios static analysis security”
- mobsfscanmobsfscan is a static analysis tool that detects insecure code…
- apkInspectorParses APK files according to the zip specification, extracts…
- androguardAndroguard is a Python tool for analyzing, disassembling, and…
Give your agent the search over MCP, or paste the wish link into any chat.
More Quality Assurance packages
Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.
Install it if you want to measure test completeness or enforce coverage thresholds in your project.
Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.
Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.
Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.
pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.
Install it if your test suite takes long enough that parallelization would save meaningful time.
Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.
Install it if you work with CloudFormation templates.
See also njsscan · libsast · semgrep · androguard · skylos · kingfisher-bin · ai-edge-litert · trufflehog3 · mnn · codeshield