Android Manifest Analyzer
Analyze AndroidManifest.xml from any APK to extract package information, permissions, app components, and detect security issues. Paste decoded XML content, select an example, or upload a file. Private, fast, and no signup required.
Analyze AndroidManifest.xml to extract package info, permissions, app components, and detect security issues. Paste the decoded XML content extracted from any APK file. All processing happens locally in your browser.
Paste the decoded AndroidManifest.xml content from any APK to analyze its permissions, components, and security posture. The tool extracts package info, SDK versions, all declared permissions with protection levels, app components (activities, services, receivers, providers), and flags security issues. All processing happens locally in your browser.
Why Use Our Android Manifest Analyzer?
Complete Manifest Parsing
Parse the full AndroidManifest.xml structure: package name, version info, SDK versions, application attributes, and all component declarations. Extract every activity, service, broadcast receiver, content provider, and intent filter with their full attributes from the XML manifest.
Dangerous Permission Detection
Automatically classify all declared permissions by Android protection level: normal, dangerous, signature, system, and development. Flag dangerous permission combinations that could enable data theft, surveillance, or device compromise with clear severity ratings.
Component Security Analysis
Flag security issues in component declarations: exported components without permission guards, debug mode enabled in production, allowBackup enabled, exposed content providers, unprotected broadcast receivers, and intent filters that could enable malicious app interaction.
Threat Categorization & Severity Ratings
Every finding is categorized and severity-rated: critical (data exfiltration, code execution), high (surveillance, privilege escalation), medium (privacy exposure, device manipulation), and informational (best practice suggestions). Filter results by severity to focus on the most important issues.
Common Use Cases for Android Manifest Analyzer
Mobile App Security Auditing
Security auditors use the manifest analyzer to quickly review app permission requests and component exposure. A single scan reveals whether an app requests more permissions than it needs, exposes components without protection, or enables dangerous flags like backup or debugging in production releases.
Malware & Spyware Analysis
Analyze suspicious APKs by examining their manifest for malicious indicators: dangerous permission combinations (RECORD_AUDIO + CAMERA + INTERNET), hidden activities, exported services for C2 communication, debug flags, and backup configurations that could exfiltrate app data.
App Development Best Practices
Developers can use the analyzer to validate their manifest against security best practices before release. Check for proper permission usage, correct component export settings, intent filter security, content provider URI permissions, and recommended network security configurations.
Privacy Compliance Review
Privacy officers and compliance teams review manifests to verify GDPR, CCPA, and Play Store policy compliance. Identify data-accessing permissions, background location requests, SMS/call log access, and health data permissions that require special disclosure or user consent.
App Store Submission Review
Before submitting to Google Play, developers use the analyzer to catch policy-violating permissions (SMS/Call Log for newer apps), verify proper backup configuration, check debuggable flags, and ensure all exported components have appropriate permission guards - avoiding submission rejections.
Open Source App Audit
Review open source Android apps before installing or contributing. The manifest analyzer gives a quick overview of what permissions the app requires, what components it exposes, and whether there are any suspicious or overreaching declarations that warrant closer code inspection.
Understanding the Android Manifest
What is AndroidManifest.xml?
The AndroidManifest.xml is a required file in every Android application (APK). It declares essential information about the app to the Android operating system: the package name (unique app identifier), version code and name (used for updates), the minimum and target SDK versions(which Android versions the app supports), and all app components - activities, services, broadcast receivers, and content providers. It also lists everypermission the app requires and defines hardware and software features the app needs. The manifest is written in XML and can be extracted from any APK using tools like apktool, aapt, or by simply unzipping the APK and converting the binary AndroidManifest.xml to readable text.
How Android Permissions Work
- Declaration in Manifest - Permissions are declared with
<uses-permission android:name="android.permission.PERMISSION_NAME" />. For Android 6.0+, dangerous permissions also require runtime requests. - Permission Protection Levels - Normal: automatically granted (INTERNET, ACCESS_NETWORK_STATE). Dangerous: requires user approval at runtime (CAMERA, LOCATION, RECORD_AUDIO). Signature: only granted if the app is signed with the same certificate as the system. System/SignatureOrSystem: reserved for system apps.
- Runtime Permission Model - Since Android 6.0 (API 23), dangerous permissions must be requested at runtime through a system dialog. Users can grant or deny individual permission groups, and can revoke them at any time through Settings.
- Permission Groups & Auto-Grant - Permissions are organized into groups (STORAGE, LOCATION, SMS, etc.). Granting one permission in a group auto-grants all others in the same group. Users can see exactly which group each permission belongs to.
Manifest Security Signals & Red Flags
- Dangerous Permission Combinations: CAMERA + RECORD_AUDIO suggests surveillance/spying. ACCESS_FINE_LOCATION + INTERNET + SEND_SMS suggests tracking with SMS exfiltration. READ_CONTACTS + GET_ACCOUNTS + INTERNET suggests contact harvesting.
- Exported Components: An
android:exported="true"activity, service, or receiver without a required permission means any app on the device can launch it. This is a common security vulnerability in third-party SDKs and custom ROM components. - Backup Flag:
android:allowBackup="true"(the default) allows users to back up app data via ADB, which could expose sensitive data. Explicitly setting it to false prevents data exfiltration via backup. - Debuggable Flag:
android:debuggable="true"should never appear in release builds. It allows debugging tools to attach to the app process, exposing data and bypassing security controls. - Custom Permissions: Apps defining their own permissions with
<permission>tags should use the signature protection level to prevent other apps from gaining unauthorized access to their components.
Privacy & Security
This tool runs entirely in your browser using client-side JavaScript. Your manifest XML content and analysis results are never uploaded to any server, stored in any database, or transmitted over the network. All XML parsing, permission classification, component analysis, and security flagging executes locally on your device. There are no API calls, analytics tracking, cookies, or data collection of any kind. This makes it completely safe for analyzing proprietary apps, pre-release builds, or sensitive security audit findings.
Frequently Asked Questions About Android Manifest Analyzer
AndroidManifest.xml is the central configuration file in every Android APK. It declares the app package name, required permissions, app components (activities, services, receivers, providers), SDK versions, and hardware requirements. Analyzing it reveals what an app can do (permissions), what it exposes (exported components), and potential security or privacy issues before installation.
You can extract the manifest using several methods: use apktool (apktool d app.apk) to decode the binary XML to readable text, use aapt (aapt dump xmltree app.apk AndroidManifest.xml) to dump the tree, or simply use an online APK decompiler. Once extracted, paste the decoded XML content into the text area above for analysis.
Normal permissions (like INTERNET or VIBRATE) are automatically granted by Android because they pose minimal privacy risk. Dangerous permissions (like CAMERA, LOCATION, RECORD_AUDIO, READ_CONTACTS) require explicit user approval at runtime on Android 6.0+ because they access private user data or sensitive device capabilities. The analyzer flags all dangerous permissions and highlights risky combinations.
An exported component with android:exported="true" means any app on the device can launch it without permission. If an exported activity displays sensitive data, an exported content provider exposes private databases, or an exported receiver listens for system broadcasts without permission filtering, malicious apps can exploit these to access data or trigger actions without user knowledge.
The android:allowBackup flag (default true on most Android versions) determines whether the app data can be backed up via ADB. If enabled, anyone with USB debugging access can extract the app's private data, including databases, shared preferences, and cached files. Setting it to false is recommended for apps handling sensitive data like banking, health records, or authentication tokens.
Yes. The manifest is a required part of every APK file and is readable after decoding. You can analyze manifests from any app: installed apps (extract via ADB with aapt or apktool), APK files downloaded from any source, open source projects, or your own apps during development. The analysis is completely local and private.
Absolutely. The Android Manifest Analyzer runs entirely in your browser. Your manifest XML and analysis results are never uploaded to any server, stored in any database, or transmitted over the network. All XML parsing, permission classification, component extraction, and security flagging executes locally on your device with no API calls, analytics, or data collection.
Yes - 100% free with no signup, no account, and no usage limits. Analyze as many app manifests as you need, as many times as you want. There are no premium tiers, hidden charges, or rate limits. The tool runs entirely in your browser - your data never leaves your device.