Scan results

    GitHub

    Android

    Official GitHub app for Android enables collaboration on the go. Manage issues, review code, merge pull requests, and stay connected with your team directly from your device.

    CITT SCORE
    42
    out of 100
    unTRUSTED

    Quick Verdict

    Best for: Developers comfortable with standard crash reporting

    What It Means For You

    User activity is reported to Firebase, including crash diagnostics and session data. Code, repositories, and account interactions are processed on GitHub servers, and Firebase services collect usage patterns from user sessions. Users have reasonable control over their account data, but third-party reporting runs in the background whenever the app is in use.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (14)

    Data Security

    6 total
    1 Critical
    2 High
    3 Medium

    Code Security

    4 total
    1 Critical
    1 High
    2 Medium

    Privacy

    4 total
    1 Critical
    3 Medium

    Third-Party Services

    Firebase Cloud Messaging, Firebase Sessions, Firebase Installations, Firebase Crashlytics, Apollo GraphQL Client, OkHttp, Retrofit, Coil, AppAuth

    Security Strengths

    • Certificate pinning implemented
    • AndroidKeyStore properly implemented for 2FA keys
    • Well-designed WebView JavaScript bridge with minimal attack surface
    • No third-party analytics SDKs
    • Modern cryptography (EC secp256r1, SHA-256)
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    sensitive data
    developer tools
    source code
    credentials
    privacy violations
    compliance issues

    Package

    com.github.android

    Version

    1.219.1 (Build 10265)

    Analysis Date

    Jan 24, 2026

    Classes Analyzed

    55,461

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 6 findings (1 critical, 2 high, 3 medium)

    Network Security - 0 findings

    Code Safety - 0 findings

    Privacy - 4 findings (1 critical, 3 medium)

    Privacy Concerns

    What Data is Collected

    Firebase services collect crash diagnostics, session identifiers, device information, and usage patterns each time the app is opened and used. Account activity, including repository interactions and code browsing, is processed on GitHub's servers.

    Third-Party Data Sharing

    Session and diagnostic data is shared with Google's Firebase platform, which processes crash reports and usage analytics. Firebase Cloud Messaging routes notification delivery through Google's infrastructure using device registration data.

    Understanding the Scores

    CategoryScore
    Security45/100
    Privacy40/100
    Data Security35/100
    Network Security85/100
    Code Safety50/100
    Data Collection55/100
    Data Sharing60/100
    User Control65/100

    Positive Security Features

    • No specific positive security practices were identified for this app.

    Areas for Improvement

    • Data handling practices could be strengthened to better protect sensitive information stored and processed on the device.
    • The range of data collected by background analytics services could be narrowed to what is strictly needed for core functionality.
    • Providing clearer controls for managing background reporting would give users more visibility into what information leaves the device.

    About This Analysis

    App Details

    FieldValue
    AppGitHub
    Packagecom.github.android
    Version1.219.1 (Build 10265)
    Scan Date2026-01-24

    Right of Reply

    Developer not yet contacted