eMAG онлайн пазаруване Security & Privacy Scorecard
Android
Browsing and purchase activity is shared with advertising networks including Facebook, TikTok, Criteo, and RTB House for ad targeting. AppsFlyer tracks app usage and links it to ad campaigns across platforms. Data reaches nine third-party services in total.
Best for
Online shoppers comfortable with targeted advertising
Avoid if
You want to limit ad tracking across platforms
Findings
- 1 critical
- 4 high
- 8 medium
- 4 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Authentication Tokens Stored in Plaintext
- User Data in Unencrypted SQLite Databases
- Weak WebView URL Validation Enabling Phishing
Top privacy issues
- Extensive Cross-App User Profiling via Advertising ID
- User ID and Customer ID Sent to Firebase in Plaintext
- Advertising ID Persists Across Logout
Full analysis
eMAG.bg
Version: 4.38.3 (Build 307)
Scan Date: January 26, 2026
What This Means for You
Browsing and purchase activity is shared with advertising networks including Facebook, TikTok, Criteo, and RTB House for ad targeting. AppsFlyer tracks app usage and links it to ad campaigns across platforms. Data reaches nine third-party services in total.
Recommendation: Use With Caution
Best For: Online shoppers comfortable with targeted advertising
Avoid If: You want to limit ad tracking across platforms
Key Findings
Data Security - 3 findings (1 critical, 1 high, 1 medium)
Network Security - 7 findings (1 high, 5 medium, 1 low)
Code Safety - 0 findings
Privacy - 4 findings (1 high, 1 medium, 2 low)
Privacy Concerns
What Data is Collected
The app collects device identifiers, in-app browsing behavior, purchase history, and interaction patterns to build a profile of user shopping activity and preferences.
Third-Party Data Sharing
User data is shared with nine third-party services:
- Firebase Analytics - App usage and event tracking
- Facebook SDK - Behavioral data for ad targeting on Facebook and partner networks
- AppsFlyer - Attribution tracking that links in-app actions to ad campaigns across platforms
- Criteo - Retargeting and personalized advertising
- TikTok Business SDK - Behavioral data for ad targeting on TikTok
- RTB House - Real-time bidding and ad personalization
- Google Mobile Ads - Ad delivery and targeting
- Salesforce Service Cloud - Customer service and support data
- Parse SDK - Backend data processing
Understanding the Scores
| Category | Score |
|---|---|
| Security | 45/100 |
| Privacy | 55/100 |
| Data Security | 35/100 |
| Network Security | 60/100 |
| Code Safety | 65/100 |
| Data Collection | 50/100 |
| Data Sharing | 45/100 |
| User Control | 75/100 |
Positive Security Features
- None identified in this version.
Areas for Improvement
- Data stored on the device by the app may not be fully protected if the device is accessed by someone else.
- Some network communications use configurations that reduce the protection of data traveling between the device and the app's servers.
- Behavioral data is shared with four separate advertising and retargeting services, giving multiple companies ongoing insight into user shopping habits.
About This Analysis
This scorecard is based on automated static analysis of the app's code and configuration. Results reflect the app as distributed at the time of the scan.
App Details
- App Name: eMAG.bg
- Package ID: bg.emag.android
- Version: 4.38.3 (Build 307)
- Platform: Android
- Scan Date: January 26, 2026
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 50/100 |