TodoPago Security & Privacy Scorecard
Android
Payment activity and device identifiers are shared with multiple analytics and identity verification services. Firebase tracks app behavior, while Kount and Metamap process identity and transaction data for fraud detection. Financial interactions are handled with weaker-than-expected data protections in place.
Best for
TodoPago users aware of broad data sharing
Avoid if
You store sensitive financial data on shared devices
Findings
- 0 critical
- 0 high
- 6 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Hardcoded AES Encryption Keys and Initialization Vector
- Cleartext HTTP Traffic Allowed for Production Payment APIs
- Full HTTP Request/Response Logging Enabled in Production
Top privacy issues
- Pre-Consent Behavioral Tracking and Biometric Collection
- Third-Party Data Sharing Without Explicit Disclosure (Kount)
- Excessive Location Precision (Street-Level Tracking)
Full analysis
TodoPago
What This Means for You
Payment activity and device identifiers are shared with multiple analytics and identity verification services. Firebase tracks app behavior, while Kount and Metamap process identity and transaction data for fraud detection. Financial interactions are handled with weaker-than-expected data protections in place.
Recommendation: Use With Caution
Best For: TodoPago users aware of broad data sharing
Avoid If: You store sensitive financial data on shared devices
Key Findings
Data Security - 9 findings (5 critical, 3 high, 1 medium)
Network Security - 2 findings (2 critical)
Code Safety - 0 findings
Privacy - 6 findings (1 critical, 2 high, 2 medium, 1 low)
Privacy Concerns
What Data is Collected
TodoPago collects device identifiers, payment transaction data, and behavioral activity within the app. User identity details are processed through third-party services for fraud detection and onboarding verification purposes.
Third-Party Data Sharing
User data is shared with the following third-party services:
- Firebase (Analytics, Crashlytics, Messaging) - Behavioral tracking, crash reporting, and push notifications
- Kount Analytics - Fraud detection and transaction risk scoring
- Metamap SDK - Identity verification processing
- Incode Welcome SDK - Onboarding and identity checks
- Huawei HMS - Device platform integration
- Google Play Services - Core platform services
- Card.io - Payment card scanning
Understanding the Scores
| Category | Score |
|---|---|
| Security | 25/100 |
| Privacy | 30/100 |
| Data Security | 20/100 |
| Network Security | 25/100 |
| Code Safety | 35/100 |
| Data Collection | 40/100 |
| Data Sharing | 45/100 |
| User Control | 35/100 |
Positive Security Features
- This version of the app does not demonstrate standout security practices based on what was observed.
Areas for Improvement
- Stronger protections should be applied to how payment and identity data is stored and transmitted within the app.
- The range of third-party services that access user financial and identity data should be reduced to limit unnecessary exposure.
- Users should be given clearer controls over what data is collected and which external parties receive it.
About This Analysis
This scorecard is based on static analysis of the app's code and configuration. Scores reflect the security and privacy posture observed at the time of the scan.
App Details
- App Name: TodoPago
- Package ID: com.mobilcash.todomovil
- Version: 3.4 (Build 66)
- Scan Date: 2026-02-16
- Platform: Android
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #3 (current) | 28/100 |