Safety checks · free tool

Is an APK file safe? What actually decides it

No file is safe or unsafe because it is an APK. Twelve checks show where a particular file stands, and the checklist counts them for you.

Tool · runs in your browserNothing is uploaded

Answer each check for the file in front of you. Nothing you tick is stored or sent anywhere.

3 of 12 checks passed · 3 found a problem · 6 still open Jump to the result

Where the link came from. You reached the download from a page whose address you typed yourself, or from a link you can account for.

How to check this
  • Think back to where you first saw the link.
  • An ad, a comment, a group chat, a forwarded message, a video description or a message from a stranger does not count.
  • If you cannot remember, leave this open and go back to the page you started from.

Read more: Link checker

How to check this
  • Press and hold the link and copy it instead of tapping it.
  • A link that ends in .apk, or a short link, hides the page you would want to read first.
  • Paste the copied link into the link checker and read the warnings.

Read more: APK download links

The file

Why you want it. You want the app for a reason of your own. Nobody told you a file is needed to log in, claim a bonus or unlock something.

How to check this
  • Ask yourself who first said you needed a file.
  • Installing a file does not fix a login problem.
  • If the only reason is that someone said so, the honest answer is a problem.

Read more: Login guide

What the file is called. Neither the file name nor the page that offers it uses the words mod, hack, unlimited, premium unlocked, predictor or cheat.

How to check this
  • Read the exact file name and the words on the page that offers it.
  • Those words promise something a file on your phone cannot deliver, because a file cannot change what an online service keeps on its own servers.
  • Files sold on those words usually do something else.

Read more: Mod APK risks

Who published it. A publisher’s name is given, and the same name appears on a second page that you reached by typing the address yourself.

How to check this
  • Look for a publisher or developer name on the page the file came from.
  • Look for the same name on another page you reach on your own, such as a store listing.
  • A name that appears in one place only proves nothing, because whoever uploaded the file typed it.

Read more: Checking an app file

The file’s fingerprint. The publisher gives a SHA-256 fingerprint on a second page, and your file matches it.

How to check this
  • A fingerprint is a 64-character value worked out from every byte of the file.
  • Find one on a page you reached on your own, not beside the download link.
  • Work out your file’s fingerprint with the file fingerprint checker and compare the two.

Read more: File fingerprint checker

What it asks for

Permissions. None of the permissions it asks for is one a game has no use for: reading texts, accessibility service, device administrator, notification access or display over other apps.

How to check this
  • A store listing or the publisher’s page may list the permissions. Check it if it does.
  • A file from outside a store has no listing, so the pop-ups and the Settings screens are your only preview. In that case leave this open.
  • Refuse any request for your texts or for accessibility each time it appears.

Read more: Permissions to refuse

Payments. Nobody has asked you to pay, to send money to a person’s UPI ID or to share card or bank details, in order to get this file or unlock it.

How to check this
  • Check the page and any chat with whoever sent the file.
  • A fee, a deposit or a “verification payment” for a file is a trick, and so is a request to send money to a person’s UPI ID.
  • If the app later asks for card, bank or UPI details on screens of its own, stop and remove it.

Read more: After a scam

Play Protect. Play Protect is switched on, and it has not warned about this file.

How to check this
  • In the Play Store, tap your profile picture, then Play Protect, and check that scanning is on.
  • A warning is a stop sign, not something to tap past.
  • Do not switch Play Protect off to make a file install.

Read more: Checking an app file

Around the app

How it updates. You know how new versions arrive: through a store listing or the page you got the file from, not through links sent in chats.

How to check this
  • Ask where new versions come from.
  • An app that tells you to download and install another file, or a chat that sends “update files”, keeps asking you to leave the door open.
  • A web page saved to your home screen has no updates to manage.

Read more: Old and latest versions

Reviews. The reviews you can find are on a store listing or a page you reached yourself, and none describes lost money, locked accounts or surprise requests. This is the weakest check.

How to check this
  • Ratings and download counts on the page that offers the file are typed by whoever uploaded it.
  • Look for reviews on a store listing or a site you reached on your own.
  • Treat this as the weakest check, because reviews can be bought or copied.

Read more: Checking an app file

A way back. You have a screenshot of the page the file came from, and you know how to remove the app.

How to check this
  • Take a screenshot of the page and its address before you install.
  • To remove an app, touch and hold its icon and choose Uninstall, or open Settings, then Apps.
  • If you ever need to report a problem, the screenshot is your record.

Read more: Checking an app file

3 of 12checks passed
3checks found a problem
6checks still open
1problem is a reason to walk away

3 of 12 checks passed, 3 checks found a problem, 6 still open. 1 problem below is a reason to walk away from this file (“Where the link came from”). Do not install it. If you still want the app, start again from a source you can account for and run the checks again.

What to do about the 9 checks that are not passed
CheckWhere it standsWhat to do
Where the link came fromA problemOpen nothing from that link and start again from an address you type yourself.
What the link points toA problemDo not tap it.
ReviewsA problemTake reviews that describe lost money, locked accounts or surprise requests seriously, and go back to the stronger checks above them.
Who published itNot checkedSearch for the publisher’s name from a page you type yourself, not from the page the file came from.
The file’s fingerprintNot checkedLeave it open if no fingerprint is given and lean on the other checks.
PermissionsNot checkedRead what each permission lets an app do now, so you know which requests to refuse when they appear.
Play ProtectNot checkedOpen the Play Store, tap your profile picture, then Play Protect, and make sure scanning is on.
How it updatesNot checkedFind out where updates come from before you rely on the app.
A way backNot checkedTake a screenshot of the page and its address, and find out how to remove the app.

Whether an APK is safe is the wrong question to put to a file type. A file from a publisher’s own page and a file from a chat group are both APKs, but they are not equal. In the example above a download-site file passes 3 of 12 checks, and 1 problem is enough to walk away, whatever the star rating says.

The checklist runs in your browser and keeps nothing. Tick what you know, and leave the rest as not checked.

Common questions

Why can nobody call an APK file safe?

An APK is only a container. The same type of file holds a publisher’s own app and a copy someone has rebuilt, and nothing in the name, the size or the rating shows which. What you can check is the link it came from, the publisher, the fingerprint and the permissions.

What makes an APK riskier than an app from a store?

A store gives each app one listing, a publisher name and a permissions list before you install. A file from outside a store has none of that, and anyone can rebuild it. The risk sits in those gaps, and the checks fill them one by one.

Is an APK safe if a friend sent it?

Not by that alone. A friend’s chat account can be hacked and a forwarded file has been through other hands. Ask your friend another way whether they sent it, then run the same checks you would run on any file.

Does the checklist send my answers anywhere?

No. It runs in your browser and your answers stay on the page. The copy-link button writes them into the link after the # sign, which a website never receives.

Does every check passing mean the file is fine?

It lowers the risk and nothing more. Nobody can see inside a file from outside, and a fingerprint, a clean list of permissions and good reviews can all be made to look right. That is why the tool reports checks done and checks open, never a safe file.

The full tool