Scan results

    Skimmer Pro

    Android

    Pool service software for managing routes, work orders, customer data, invoicing, and service reports. Works online or offline with cloud sync. Includes route optimization, real-time technician tracking, chemical dosage tracking, and automated service emails.

    CITT SCORE
    48
    out of 100
    unTRUSTED

    Quick Verdict

    Best for: Pool service pros comfortable with standard analytics

    What It Means For You

    Usage patterns and behavior are tracked by Pendo Analytics and shared with Sentry for error reporting. A critical finding was identified, meaning account data may not be fully protected. Google Sign-In links user activity to their Google account.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (19)

    Data Security

    4 total
    1 Critical
    2 Medium
    1 Low

    Code Security

    8 total
    2 High
    3 Medium
    3 Low

    Privacy

    5 total
    3 High
    2 Medium

    Third-Party Risk

    1 total
    1 Medium

    Permission Usage

    1 total
    1 Low

    Third-Party Services

    Pendo Analytics, Sentry Error Tracking, Google Maps, Google Sign-In, Azure Mobile Services, Telerik UI, Shiny Bluetooth LE

    Security Strengths

    • Modern encryption infrastructure available (Google Tink, AndroidX Security Crypto)
    • Current SDK versions (Sentry 8.24.0, Google Play Services 18.2.0)
    • Certificate Transparency validation for Pendo analytics
    • HTTPS enforced by default (Android 9+)
    • No SSL certificate bypass vulnerabilities detected
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    business
    location
    camera
    bluetooth
    sensitive data
    analytics
    cloud sync
    offline storage

    Package

    com.getskimmer.skimmerphone

    Version

    12.8.2 (Build 27529)

    Analysis Date

    Feb 7, 2026

    Classes Analyzed

    11,615

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 4 findings (1 critical, 2 medium, 1 low)

    Network Security - 0 findings

    Code Safety - 0 findings

    Privacy - 5 findings (3 high, 2 medium)

    Privacy Concerns

    What Data is Collected

    In-app activity and feature usage are collected by Pendo Analytics, which builds a profile of how users interact with the app over time. Error and crash data, which may include device details and app state at the time of a problem, are sent to Sentry. Location access is required for Google Maps features. Signing in with Google ties app identity to the user's broader Google account. Bluetooth device information is handled locally by Shiny Bluetooth LE when connecting to compatible hardware.

    Third-Party Data Sharing

    Usage data is shared with Pendo Analytics and error data with Sentry. Google receives location requests and account information through Maps and Sign-In. Azure Mobile Services processes data on the backend. Multiple parties receive data generated by everyday use of the app, and the controls available to users over that sharing are limited.

    Understanding the Scores

    CategoryScore
    Overall Security45/100
    Overall Privacy50/100
    Data Security70/100
    Network Security80/100
    Code Safety40/100
    Data Collection55/100
    Data Sharing50/100
    User Control60/100

    Positive Security Features

    • Network communications between the app and its servers score relatively well, suggesting data moving between the device and the backend receives a reasonable level of protection in transit.
    • Account login is handled through Google Sign-In, an externally managed identity provider, which means password management is delegated to a widely-used and maintained system rather than built in-house.

    Areas for Improvement

    • A critical issue in how account data is stored or handled puts it at greater risk than it should be. Stronger protections are needed to keep user information secure at rest.
    • The app's code safety practices scored low, meaning user data may not be well-protected at the code level against unauthorized access by other software on the device.
    • Data flows to several third-party services with limited controls offered to users over what is shared and with whom. Clearer opt-out options would give users more confidence in how their information is used.

    About This Analysis

    This scorecard is based on automated static analysis of the app's code and configuration. Scores reflect the security and privacy practices observed at the time of the scan.

    App Details

    • App: Skimmer Pro
    • Package: com.getskimmer.skimmerphone
    • Version: 12.8.2 (Build 27529)
    • Scan Date: 2026-02-07
    • Platform: Android

    Right of Reply

    Developer not yet contacted