Scan results

    Mercado Libre: Compras online

    Android

    Leading Latin American e-commerce platform offering online shopping, selling, and payments. Browse 100M+ products across categories including electronics, fashion, groceries, and home goods with fast shipping options.

    CITT SCORE
    60
    out of 100
    TRUSTish

    Quick Verdict

    Best for: Everyday shoppers comfortable with ad tracking

    Not For: You keep financial or identity data strictly private

    What It Means For You

    Browsing, search, and purchase activity is shared with Facebook, Google, and Adjust to build ad profiles and target users across other apps. Behavioral and biometric data from user interactions may be collected by FaceTec and Behaviosec. Data is also sent to Datadog and Bugsnag for monitoring purposes.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (11)

    Data Security

    3 total
    2 High
    1 Medium

    Network Security

    1 total
    1 Medium

    Code Security

    4 total
    1 Critical
    2 Medium
    1 Low

    Privacy

    2 total
    2 High

    Third-Party Risk

    1 total
    1 Medium

    Third-Party Services

    Datadog RUM, Bugsnag, Adjust, Facebook SDK, Google Analytics, Firebase, FaceTec, Behaviosec, Bitmovin Player, Glide, Lottie, Fresco, OkHttp, Retrofit, Qualtrics, Timber, Koin, LeakCanary, Mercado Pago SDK

    Security Strengths

    • Play Integrity API for device attestation and tamper detection
    • AES-256-GCM encryption with hardware-backed Android KeyStore
    • Proper SSL certificate validation throughout
    • HTTPS enforcement (usesCleartextTraffic disabled)
    • No SQL injection vulnerabilities (Room Database with parameterized queries)
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    e-commerce
    sensitive data
    location
    camera
    biometric
    ads
    analytics
    payment processing

    Package

    com.mercadolibre

    Version

    10.504.0 (Build 1816182097)

    Analysis Date

    Feb 4, 2026

    Classes Analyzed

    68,895

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 3 findings (2 high, 1 medium)

    Network Security - 1 finding (1 medium)

    Code Safety - 0 findings

    Privacy - 2 findings (2 high)

    Privacy Concerns

    What Data is Collected

    The app collects shopping behavior, search queries, purchase history, device identifiers, and location data. Biometric signals and behavioral patterns from user in-app interactions are also gathered for identity verification and fraud detection purposes. Survey responses may be collected through Qualtrics.

    Third-Party Data Sharing

    User activity data is shared with multiple external companies:

    • Facebook SDK - receives behavioral data to build advertising profiles used to target users on other platforms
    • Google Analytics and Firebase - receive usage and event data for analytics and advertising measurement
    • Adjust - receives device and session data for cross-app advertising attribution
    • FaceTec - receives biometric interaction data for identity verification
    • Behaviosec - receives behavioral patterns to detect fraud
    • Datadog - receives performance and session data for operational monitoring
    • Bugsnag - receives crash reports and diagnostic data
    • Qualtrics - receives survey and feedback responses

    Understanding the Scores

    CategoryScore
    Security65/100
    Privacy55/100
    Data Security60/100
    Network Security85/100
    Code Safety70/100
    Data Collection50/100
    Data Sharing60/100
    User Control55/100

    Positive Security Features

    • No notable positive security practices were identified in this version of the app.

    Areas for Improvement

    • User activity and biometric data is shared with multiple advertising and analytics companies, with limited transparency about how long that data is kept or how it is used beyond the session.
    • The scope of data collection is broad relative to the app's core function, and there are few controls available to limit behavioral profiling or opt out of cross-app tracking.
    • Data handling for payment and identity-related features does not fully meet the standards expected for apps that store sensitive financial information.

    About This Analysis

    This scorecard is based on static code analysis of the app and reflects observed practices at the time of the scan. Results describe practices present in the analyzed build and may not capture all behaviors that occur during live use.

    App Details

    • Package ID: com.mercadolibre
    • Version: 10.504.0 (Build 1816182097)
    • Scan Date: February 4, 2026

    Right of Reply

    Developer not yet contacted