ntfy icon

io.heckel.ntfy_63.apk

ntfy

8.89 MB

Analyzed: 2026-08-07 17:38 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
97/100
Threat scan clean Modern target SDK
Privacy Permissions & network
97/100
High-risk permissions HTTP URLs found AllowBackup enabled Low data access
97/100
Excellent
Overall trust

Facts

Threat scan 0/75 flagged, 0 suspicious
Permissions 12 requested
Network strings 25 URLs (1 HTTP, 24 HTTPS)
Target SDK 36
Certificate Valid until 2049-04-18 (23 years, suspicious)

Warnings

Found 1 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS, android.permission.RECEIVE_BOOT_COMPLETED
AllowBackup is enabled.
Package Name io.heckel.ntfy
Version Code 63
Version Name 1.25.2
Application Name io.heckel.ntfy.app.Application
Debuggable No
Allow Backup Yes
Min SDK Android 26 (Oreo)
Target SDK Android 36 (Unknown)
Supported ABIs
arm64-v8a armeabi-v7a x86 x86_64

Certificate & Signer

Valid From 2021-12-01 17:41:20
Valid To 2049-04-18 17:41:20
Serial Number e1d910a
Thumbprint 5605c385e42929980845a51a390b373aeec4a180
Issuer: C UK
Issuer: CN FDroid
Issuer: DN C:UK, CN:FDroid, L:ORG, O:fdroid.org, ST:ORG, OU:FDroid
Issuer: L ORG
Issuer: O fdroid.org
Issuer: OU FDroid
Issuer: ST ORG
Subject: C UK
Subject: CN FDroid
Subject: DN C:UK, CN:FDroid, L:ORG, O:fdroid.org, ST:ORG, OU:FDroid
Subject: L ORG
Subject: O fdroid.org
Subject: OU FDroid
Subject: ST ORG

Security Scan

0 /75
✓ Clean
Scanned by 75 security vendors
Last scan: 2026-08-05 12:01 UTC
Malicious
0
Suspicious
0
Harmless
0
Undetected
67
Timeout
0
Failure
1

Scan Providers

75 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.806
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.30.1.10706
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260805-00
Avira undetected
No result reported
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav undetected
No result reported
Engine 8.2.40(8338)
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.3.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet undetected
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.279
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.48.0
GData undetected
No result reported
Engine GD:27.45524AVA:64.31705
Google undetected
No result reported
Engine 1785927644
Gridinsoft undetected
No result reported
Engine 1.0.251.174
Ikarus failure
No result reported
Engine 6.5.4.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.70.60362
K7GW undetected
No result reported
Engine 14.70.60365
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.260
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.15679
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.26070
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne undetected
No result reported
Engine 7.7.0.1
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.6.2.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-08-05.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.14.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1264
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38862
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5658
ZoneAlarm undetected
No result reported
Engine 6.26-117392786
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 2b05b4b:2b05b4b:80714cb:80714cb
tehtris type-unsupported
No result reported

File Signatures

SHA-256 b4baa6f668bd57ad5df3b4e0e769165dcf25c5ee19fdb04f78077ee819616f2a
MD5 5a7689608485fae050e8aad5c55f6200
SHA-1 6b75d08b66ce1a21cfc4f4df49caaedb04056ba0
SSDEEP 196608:jxsum4jg8QLckQwquBLPDTI34C1qstsy8Ft:tyckQ4LPnLOqLf
TLSH T18196F19BB75CDA2BC4771072CD5A6233A25E4E168E4287836948371C38B72D4CF79BD8
VHASH 52e1509854c75b8c51eda0d97fa77841
PERMHASH 84989c3a6dfd195ed5d9ed590ba9eaa0ef265e299272bfa1ba2baee8315c4b32

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (40%), Java Archive (20%), VYM Mind Map (18.5%), Sweet Home 3D Design (generic) (15.5%), ZIP compressed archive (5.9%) TrID file type guesses with probabilities.
dhash 0000001e1e0d0c08 Perceptual hash used to compare visual similarity of files.
raw md5 3f3bf6d1cf2db1fcc01b9fe662561e7c Raw MD5 hash of the file contents.
extensions xml (741), png (153), version (74), kotlin_builtins (8), txt (6), so (4), properties (3), dex (2), json (2), bin (1), CoroutineExceptionHandler (1), list (1), MainDispatcherFactory (1), prof (1), profm (1), textproto (1) File extensions found inside the APK and how many of each.
file types XML (741), PNG (153), unknown (101), ELF (4), Java Bytecode (1) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1981-01-01 01:01:02 UTC Earliest timestamp found among files inside the archive.
num children 1079 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 17 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (4)

io.heckel.ntfy.ui.DetailActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE
io.heckel.ntfy.ui.MainActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
Categories
android.intent.category.LAUNCHER
io.heckel.ntfy.ui.ShareActivity
Actions
Send Activity Action: Deliver some data to someone else. android.intent.action.SEND
Categories
android.intent.category.DEFAULT
io.heckel.ntfy.up.LinkActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT

Service Intents (1)

io.heckel.ntfy.firebase.FirebaseService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT

Receiver Intents (7)

Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
Actions
Install performance profile Installs a profile that helps optimize app performance. androidx.profileinstaller.action.INSTALL_PROFILE
Skip profile install Skips profile installation for this build. androidx.profileinstaller.action.SKIP_FILE
Save performance profile Saves a profile generated during app usage. androidx.profileinstaller.action.SAVE_PROFILE
Benchmark operation Runs a profile installer benchmark operation. androidx.profileinstaller.action.BENCHMARK_OPERATION
Work rescheduler Reschedules background work after reboot or app update. androidx.work.impl.background.systemalarm.RescheduleReceiver
Actions
Boot Completed Broadcast Action: This is broadcast once, after the system has finished android.intent.action.BOOT_COMPLETED
androidx.work.impl.diagnostics.DiagnosticsReceiver
Actions
androidx.work.diagnostics.REQUEST_DIAGNOSTICS androidx.work.diagnostics.REQUEST_DIAGNOSTICS
io.heckel.ntfy.msg.BroadcastService$BroadcastReceiver
Actions
io.heckel.ntfy.SEND_MESSAGE io.heckel.ntfy.SEND_MESSAGE
io.heckel.ntfy.service.SubscriberService$BootStartReceiver
Actions
Boot Completed Broadcast Action: This is broadcast once, after the system has finished android.intent.action.BOOT_COMPLETED
android.app.action.SCHEDULE_EXACT_ALARM_PERMISSION_STATE_CHANGED android.app.action.SCHEDULE_EXACT_ALARM_PERMISSION_STATE_CHANGED
io.heckel.ntfy.service.SubscriberService$ConnectionAlertBroadcastReceiver
Actions
io.heckel.ntfy.CONNECTION_ALERT_DISMISS io.heckel.ntfy.CONNECTION_ALERT_DISMISS
io.heckel.ntfy.CONNECTION_ALERT_SNOOZE_SHORT io.heckel.ntfy.CONNECTION_ALERT_SNOOZE_SHORT
io.heckel.ntfy.CONNECTION_ALERT_SNOOZE_LONG io.heckel.ntfy.CONNECTION_ALERT_SNOOZE_LONG
io.heckel.ntfy.CONNECTION_ALERT_NEVER io.heckel.ntfy.CONNECTION_ALERT_NEVER
io.heckel.ntfy.up.BroadcastReceiver
Actions
org.unifiedpush.android.distributor.REGISTER org.unifiedpush.android.distributor.REGISTER
org.unifiedpush.android.distributor.UNREGISTER org.unifiedpush.android.distributor.UNREGISTER
org.unifiedpush.android.distributor.feature.BYTES_MESSAGE org.unifiedpush.android.distributor.feature.BYTES_MESSAGE

Native Libraries (1)

libpl_droidsonroids_gif libpl_droidsonroids_gif.so

Requested Permissions (12)

have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
android.permission.FOREGROUND_SERVICE_SPECIAL_USE Custom app or vendor permission (not publicly documented). android.permission.FOREGROUND_SERVICE_SPECIAL_USE
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
control vibration Allows the app to control the vibrator. android.permission.VIBRATE
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
android.permission.SCHEDULE_EXACT_ALARM Custom app or vendor permission (not publicly documented). android.permission.SCHEDULE_EXACT_ALARM
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS Custom app or vendor permission (not publicly documented). android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. io.heckel.ntfy.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (7)

io.heckel.ntfy.ui.MainActivity
io.heckel.ntfy.ui.DetailActivity
io.heckel.ntfy.ui.SettingsActivity
io.heckel.ntfy.ui.DetailSettingsActivity
io.heckel.ntfy.ui.ShareActivity
io.heckel.ntfy.msg.NotificationService$ViewActionWithClearActivity
io.heckel.ntfy.up.LinkActivity

Services (5)

io.heckel.ntfy.service.SubscriberService
io.heckel.ntfy.firebase.FirebaseService
androidx.work.impl.background.systemjob.SystemJobService
androidx.work.impl.foreground.SystemForegroundService
androidx.room.MultiInstanceInvalidationService

Broadcast Receivers (11)

io.heckel.ntfy.service.SubscriberService$BootStartReceiver io.heckel.ntfy.service.SubscriberService$BootStartReceiver
io.heckel.ntfy.service.SubscriberService$AutoRestartReceiver io.heckel.ntfy.service.SubscriberService$AutoRestartReceiver
io.heckel.ntfy.service.SubscriberService$ConnectionAlertBroadcastReceiver io.heckel.ntfy.service.SubscriberService$ConnectionAlertBroadcastReceiver
io.heckel.ntfy.msg.BroadcastService$BroadcastReceiver io.heckel.ntfy.msg.BroadcastService$BroadcastReceiver
io.heckel.ntfy.up.BroadcastReceiver io.heckel.ntfy.up.BroadcastReceiver
io.heckel.ntfy.msg.NotificationService$UserActionBroadcastReceiver io.heckel.ntfy.msg.NotificationService$UserActionBroadcastReceiver
io.heckel.ntfy.msg.NotificationService$DeleteBroadcastReceiver io.heckel.ntfy.msg.NotificationService$DeleteBroadcastReceiver
androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
Work rescheduler Reschedules background work after reboot or app update. androidx.work.impl.background.systemalarm.RescheduleReceiver
androidx.work.impl.diagnostics.DiagnosticsReceiver androidx.work.impl.diagnostics.DiagnosticsReceiver
Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver

Content Providers (3)

androidx.core.content.FileProvider
androidx.startup.InitializationProvider
com.squareup.picasso.PicassoProvider

Submission Details

Submitted At 2026-08-07
First Submission 2026-08-07
Last Submission 2026-08-07
Stored Until 2026-09-06