TodoPago Security & Privacy Scorecard

Android

28
Overall trust score
Don't Trust
25
Security
30
Privacy

Payment activity and device identifiers are shared with multiple analytics and identity verification services. Firebase tracks app behavior, while Kount and Metamap process identity and transaction data for fraud detection. Financial interactions are handled with weaker-than-expected data protections in place.

Best for

TodoPago users aware of broad data sharing

Avoid if

You store sensitive financial data on shared devices

Findings

  • 0 critical
  • 0 high
  • 6 medium
  • 0 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • Hardcoded AES Encryption Keys and Initialization Vector
  • Cleartext HTTP Traffic Allowed for Production Payment APIs
  • Full HTTP Request/Response Logging Enabled in Production

Top privacy issues

  • Pre-Consent Behavioral Tracking and Biometric Collection
  • Third-Party Data Sharing Without Explicit Disclosure (Kount)
  • Excessive Location Precision (Street-Level Tracking)

Full analysis

TodoPago

What This Means for You

Payment activity and device identifiers are shared with multiple analytics and identity verification services. Firebase tracks app behavior, while Kount and Metamap process identity and transaction data for fraud detection. Financial interactions are handled with weaker-than-expected data protections in place.

Recommendation: Use With Caution

Best For: TodoPago users aware of broad data sharing
Avoid If: You store sensitive financial data on shared devices

Key Findings

Data Security - 9 findings (5 critical, 3 high, 1 medium)

Network Security - 2 findings (2 critical)

Code Safety - 0 findings

Privacy - 6 findings (1 critical, 2 high, 2 medium, 1 low)

Privacy Concerns

What Data is Collected

TodoPago collects device identifiers, payment transaction data, and behavioral activity within the app. User identity details are processed through third-party services for fraud detection and onboarding verification purposes.

Third-Party Data Sharing

User data is shared with the following third-party services:

  • Firebase (Analytics, Crashlytics, Messaging) - Behavioral tracking, crash reporting, and push notifications
  • Kount Analytics - Fraud detection and transaction risk scoring
  • Metamap SDK - Identity verification processing
  • Incode Welcome SDK - Onboarding and identity checks
  • Huawei HMS - Device platform integration
  • Google Play Services - Core platform services
  • Card.io - Payment card scanning

Understanding the Scores

Category Score
Security 25/100
Privacy 30/100
Data Security 20/100
Network Security 25/100
Code Safety 35/100
Data Collection 40/100
Data Sharing 45/100
User Control 35/100

Positive Security Features

  • This version of the app does not demonstrate standout security practices based on what was observed.

Areas for Improvement

  • Stronger protections should be applied to how payment and identity data is stored and transmitted within the app.
  • The range of third-party services that access user financial and identity data should be reduced to limit unnecessary exposure.
  • Users should be given clearer controls over what data is collected and which external parties receive it.

About This Analysis

This scorecard is based on static analysis of the app's code and configuration. Scores reflect the security and privacy posture observed at the time of the scan.

App Details

  • App Name: TodoPago
  • Package ID: com.mobilcash.todomovil
  • Version: 3.4 (Build 66)
  • Scan Date: 2026-02-16
  • Platform: Android

Versions & scan history

ScanDateOverall score
#3 (current) 28/100