Skip to main content
Home/All Tools/Android Development/AndroidManifest.xml Security & Permission Linter
How to Use & Guide ↓

AndroidManifest.xml Security & Permission Linter

Cleartext HTTP Traffic Allowed

usesCleartextTraffic="true" permits insecure HTTP connections. Enforce HTTPS or configure network_security_config.xml.

Application Data Backup Enabled

allowBackup="true" lets adb backup extract sensitive private sqlite databases or preferences unless disabled or secured.

Deprecated Broad Storage Permissions

Scoped Storage is mandatory on Android 11+ (API 30+). Use MediaStore or Photo Picker instead of broad external storage.

Dangerous Location Permission Declared

Requires runtime permission prompt (ActivityCompat.requestPermissions) and Google Play privacy justification.

Multiple Exported Components Detected

Ensure services, broadcast receivers, or activities with exported="true" have permission checks or are protected.

AndroidManifest.xml Security & Permission Linter

Essential
4.91•340K Users•100% Client-Side Privacy
Unlimited Free

Audit AndroidManifest.xml for exported activities, cleartext HTTP traffic vulnerabilities, dangerous permissions, and Google Play compliance warnings.

Exported component securityCleartext traffic checkScoped storage auditingRuntime permissions check

How to Use AndroidManifest.xml Security & Permission Linter

Follow these simple steps to process your files securely in browser memory.

1Step 1 of 3

Paste AndroidManifest.xml

Paste manifest XML content or upload project manifest file.

Pro Tip: Compare debug vs release manifests to verify hardening.
2Step 2 of 3

Run Automated Security Audit

Scans for usesCleartextTraffic, unexported activities, and dangerous permissions.

Pro Tip: android:exported="true" without permission guards is a major security vulnerability.
3Step 3 of 3

Apply Hardening Snippets

Copy recommended fixes and secure your app before store submission.

Pro Tip: Ensure android:allowBackup="false" unless encrypted backup is configured.

Who Is AndroidManifest.xml Security & Permission Linter Built For?

Designed for professionals seeking fast, private, and unlimited client-side execution.

Primary Target Audience
🎯Android Security Engineers & Mobile Devs
Also Widely Used By
QA TestersApp Store Compliance Officers
Typical Real-World Use Cases
  • Cleartext traffic vulnerability checks
  • Exported component intent hijacking audits
  • Google Play dangerous permissions scan

OWASP MASVS Checks

Flags high-risk attack surfaces instantly.

Store Rejection Prevention

Catch policy violations before Google Play review.

Actionable XML Fixes

Clear code snippets to secure every flagged component.

Frequently Asked Questions about AndroidManifest.xml Security & Permission Linter

Cleartext traffic, vulnerable exported components, dangerous permissions, and backup leakage.
Top Search Queries for AndroidManifest.xml Security & Permission Linter:
androidmanifest xml security validator lintercheck android cleartext traffic vulnerabilityandroid exported activity intent vulnerability scannergoogle play dangerous permissions audit manifestmobile app security testing manifest online