Pluxee Pay TN icon

Pluxee_Pay_TN.apk

Pluxee Pay TN

31.16 MB

Analyzed: 2026-03-11 13:14 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
97/100
Threat scan clean Modern target SDK
Privacy Permissions & network
37/100
High-risk permissions Possible tracking
54/100
High Risk
Overall trust

Facts

Threat scan 0/76 flagged, 0 suspicious
Permissions 29 requested
Network strings 14 URLs (0 HTTP, 14 HTTPS)
Target SDK 34
Certificate Valid until 2052-01-12 (26 years, suspicious)

Warnings

High-risk permissions detected: android.permission.QUERY_ALL_PACKAGES, android.permission.RECEIVE_BOOT_COMPLETED
Requests 29 permissions (review carefully).
Possible analytics/tracking domains found: app-measurement.com, pagead2.googlesyndication.com
Package Name com.sodexo.client.mpayment
Version Code 42
Version Name 3.3.2
Application Name com.example.paytool_client.MainApplication
Debuggable No
Allow Backup No
Min SDK Android 21 (Lollipop)
Target SDK Android 34 (Android 14)
Supported ABIs
Universal

Certificate & Signer

Valid From 2022-01-12 14:20:56
Valid To 2052-01-12 14:20:56
Serial Number 6e9175a2275b09f85121df21f739765bf7989212
Thumbprint 61c2cfc0a1ac4dccff109fa900336b593af0babb
Issuer: C US
Issuer: CN Android
Issuer: DN C:US, CN:Android, L:Mountain View, O:Google Inc., ST:California, OU:Android
Issuer: L Mountain View
Issuer: O Google Inc.
Issuer: OU Android
Issuer: ST California
Subject: C US
Subject: CN Android
Subject: DN C:US, CN:Android, L:Mountain View, O:Google Inc., ST:California, OU:Android
Subject: L Mountain View
Subject: O Google Inc.
Subject: OU Android
Subject: ST California

Security Scan

0 /76
✓ Clean
Scanned by 76 security vendors
Last scan: 2026-03-11 13:14 UTC
Malicious
0
Suspicious
0
Harmless
0
Undetected
59
Timeout
7
Failure
0

Scan Providers

76 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.757
AVG timeout
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.29.1.10604
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast timeout
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260311-00
Avira undetected
No result reported
Engine 8.3.3.24
Baidu timeout
No result reported
Engine 1.0.0.2
BitDefender timeout
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav undetected
No result reported
Engine 2.0.0.1
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV timeout
No result reported
Engine 1.5.2.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet type-unsupported
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic type-unsupported
No result reported
Engine 4.0.251
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.30.0
GData undetected
No result reported
Engine GD:27.43816AVA:64.30817
Google undetected
No result reported
Engine 1773226851
Gridinsoft undetected
No result reported
Engine 1.0.241.174
Ikarus undetected
No result reported
Engine 6.4.16.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.40.58844
K7GW undetected
No result reported
Engine 14.40.58846
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.211
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.14023
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26010.1
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne type-unsupported
No result reported
Engine 7.5.3.1
Skyhigh timeout
No result reported
Sophos undetected
No result reported
Engine 3.3.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-03-11.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.10.0
TrellixENS timeout
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.5.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1162
Webroot undetected
No result reported
Engine 1.10.0.2
Xcitium undetected
No result reported
Engine 38475
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5560
ZoneAlarm undetected
No result reported
Engine 6.23-113518796
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 5e7248a:5e7248a:113f75a:113f75a
tehtris type-unsupported
No result reported

File Signatures

SHA-256 51a159e68aba86ce9a3c2af4c86f810cad52e64d15af518933551551bff57572
MD5 1ef50b7fc3aadf4e99e4a87d051e5f3d
SHA-1 8af5e4e6c60d1da8b64421a9ec8aa9b293bf7b5a
SSDEEP 393216:dpPyfplBIo+2FbYvyAde2S6ZszeveBrlnJVwn7T9CHKi+qJddY7exQkn:dkfprIofFUaVzevYlnJmT9CMQrY7aF
TLSH T16C670147E7552C36C56E433A08B68340B7316D49BB879B532048F5B8BDB37C26F9CA86
VHASH 4c406ff92edcba155670cfcd7e7265a8
PERMHASH 704e7d6050042290d5a76ed7e014253ebf5fa43654e519ee617ff61f416a71bd

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID SPSS Extension (23.6%), Android Package (21.2%), Dragon Age: Origins game data (15.7%), Opera Widget (11%), Java Archive (10.6%) TrID file type guesses with probabilities.
dhash 0000001c1e0d0410 Perceptual hash used to compare visual similarity of files.
raw md5 722ff1c232e2bbb6f1d7f8289836f88d Raw MD5 hash of the file contents.
extensions xml (324), png (271), svg (212), version (67), proto (26), properties (25), json (19), otf (9), jpg (8), kotlin_builtins (7), ttf (6), gif (4), yaml (3), bin (2), dex (2), js (2), css (1), frag (1), prof (1), profm (1), txt (1), Z (1) File extensions found inside the APK and how many of each.
file types XML (351), unknown (349), PNG (272), JSON (14), JPG (7), GIF (4), DEX (2), Java Bytecode (1) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1981-01-01 01:01:02 UTC Earliest timestamp found among files inside the archive.
num children 1347 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 35 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (1)

com.example.paytool_client.MainActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
FLUTTER_NOTIFICATION_CLICK FLUTTER_NOTIFICATION_CLICK
android.nfc.action.NDEF_DISCOVERED android.nfc.action.NDEF_DISCOVERED
Categories
android.intent.category.LAUNCHER android.intent.category.DEFAULT

Service Intents (3)

com.example.paytool_client.PaymentService
Actions
android.nfc.cardemulation.action.HOST_APDU_SERVICE android.nfc.cardemulation.action.HOST_APDU_SERVICE
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT
io.flutter.plugins.firebase.messaging.FlutterFirebaseMessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT

Receiver Intents (4)

Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
Actions
Install performance profile Installs a profile that helps optimize app performance. androidx.profileinstaller.action.INSTALL_PROFILE
Skip profile install Skips profile installation for this build. androidx.profileinstaller.action.SKIP_FILE
Save performance profile Saves a profile generated during app usage. androidx.profileinstaller.action.SAVE_PROFILE
Benchmark operation Runs a profile installer benchmark operation. androidx.profileinstaller.action.BENCHMARK_OPERATION
com.dexterous.flutterlocalnotifications.ScheduledNotificationBootReceiver
Actions
Boot Completed Broadcast Action: This is broadcast once, after the system has finished android.intent.action.BOOT_COMPLETED
My Package Replaced Broadcast Action: A new version of your application has been installed android.intent.action.MY_PACKAGE_REPLACED
android.intent.action.QUICKBOOT_POWERON android.intent.action.QUICKBOOT_POWERON
com.htc.intent.action.QUICKBOOT_POWERON com.htc.intent.action.QUICKBOOT_POWERON
com.google.firebase.iid.FirebaseInstanceIdReceiver
Actions
com.google.android.c2dm.intent.RECEIVE com.google.android.c2dm.intent.RECEIVE
io.flutter.plugins.firebase.messaging.FlutterFirebaseMessagingReceiver
Actions
com.google.android.c2dm.intent.RECEIVE com.google.android.c2dm.intent.RECEIVE

Requested Permissions (29)

take pictures and videos This app can take pictures and record videos using the camera while the app is in use. android.permission.CAMERA
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
read your contacts Allows the app to read data about your contacts stored on your tablet. Apps will also have access to the accounts on your tablet that have created contacts. This may include accounts created by apps you have installed. This permission allows apps to save your contact data, and malicious apps may share contact data without your knowledge. android.permission.READ_CONTACTS
modify your contacts Allows the app to modify the data about your contacts stored on your tablet. This permission allows apps to delete contact data. android.permission.WRITE_CONTACTS
find accounts on the device Allows the app to get the list of accounts known by the tablet. This may include any accounts created by applications you have installed. android.permission.GET_ACCOUNTS
have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
control Near Field Communication Allows the app to communicate with Near Field Communication (NFC) tags, cards, and readers. android.permission.NFC
read phone status and identity Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call. android.permission.READ_PHONE_STATE
control vibration Allows the app to control the vibrator. android.permission.VIBRATE
android.permission.QUERY_ALL_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.QUERY_ALL_PACKAGES
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
android.permission.USE_BIOMETRIC Custom app or vendor permission (not publicly documented). android.permission.USE_BIOMETRIC
android.permission.USE_FINGERPRINT Custom app or vendor permission (not publicly documented). android.permission.USE_FINGERPRINT
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
android.permission.USE_FULL_SCREEN_INTENT Custom app or vendor permission (not publicly documented). android.permission.USE_FULL_SCREEN_INTENT
android.permission.SCHEDULE_EXACT_ALARM Custom app or vendor permission (not publicly documented). android.permission.SCHEDULE_EXACT_ALARM
access precise location only in the foreground This app can get your precise location from location services while the app is in use. Location services for your device must be turned on for the app to get location. This may increase battery usage. android.permission.ACCESS_FINE_LOCATION
access approximate location only in the foreground This app can get your approximate location from location services while the app is in use. Location services for your device must be turned on for the app to get location. android.permission.ACCESS_COARSE_LOCATION
Cloud messaging receive Allows the app to receive push messages via Google/Firebase Cloud Messaging. com.google.android.c2dm.permission.RECEIVE
com.google.android.gms.permission.AD_ID Custom app or vendor permission (not publicly documented). com.google.android.gms.permission.AD_ID
AdServices Attribution Required to call AdServices Attribution APIs. android.permission.ACCESS_ADSERVICES_ATTRIBUTION
AdServices Advertising ID Required to call AdServices Advertising ID APIs. android.permission.ACCESS_ADSERVICES_AD_ID
Install Referrer service Allows Google Play to bind to the app's Install Referrer service for install attribution. com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. com.sodexo.client.mpayment.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Uses Features (7)

Camera Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera
Camera Autofocus Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera.autofocus
Camera Flash Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera.flash
Camera Front Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera.front
Nfc Feature for {@link #getSystemAvailableFeatures} and android.hardware.nfc
Screen Landscape Feature for {@link #getSystemAvailableFeatures} and android.hardware.screen.landscape
Wifi Feature for {@link #getSystemAvailableFeatures} and android.hardware.wifi

Activities (6)

com.example.paytool_client.MainActivity
com.djgeo.majascan.g_scanner.QrCodeScannerActivity
com.xamdesign.safe_device.MockLocation.MainActivityvvvv
io.flutter.plugins.urllauncher.WebViewActivity
com.google.android.gms.common.api.GoogleApiActivity
com.journeyapps.barcodescanner.CaptureActivity

Services (10)

com.example.paytool_client.PaymentService
io.flutter.plugins.firebase.messaging.FlutterFirebaseMessagingBackgroundService
io.flutter.plugins.firebase.messaging.FlutterFirebaseMessagingService
com.google.firebase.components.ComponentDiscoveryService
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
com.google.firebase.sessions.SessionLifecycleService
com.google.android.gms.measurement.AppMeasurementService
com.google.android.gms.measurement.AppMeasurementJobService
com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService

Broadcast Receivers (8)

io.flutter.plugins.firebase.messaging.FlutterFirebaseMessagingReceiver io.flutter.plugins.firebase.messaging.FlutterFirebaseMessagingReceiver
com.dexterous.flutterlocalnotifications.ActionBroadcastReceiver com.dexterous.flutterlocalnotifications.ActionBroadcastReceiver
com.dexterous.flutterlocalnotifications.ScheduledNotificationReceiver com.dexterous.flutterlocalnotifications.ScheduledNotificationReceiver
com.dexterous.flutterlocalnotifications.ScheduledNotificationBootReceiver com.dexterous.flutterlocalnotifications.ScheduledNotificationBootReceiver
com.google.firebase.iid.FirebaseInstanceIdReceiver com.google.firebase.iid.FirebaseInstanceIdReceiver
com.google.android.gms.measurement.AppMeasurementReceiver com.google.android.gms.measurement.AppMeasurementReceiver
Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver

Content Providers (4)

io.flutter.plugins.firebase.messaging.FlutterFirebaseMessagingInitProvider
io.flutter.plugins.imagepicker.ImagePickerFileProvider
com.google.firebase.provider.FirebaseInitProvider
androidx.startup.InitializationProvider

Submission Details

Submitted At 2026-03-11
First Submission 2026-03-11
Last Submission 2026-03-11
Stored Until 2026-04-10