OMNI.reporte Security & Privacy Scorecard
Android
Activity and crash data are sent to Firebase and Microsoft Azure services. Location may be accessed via Google Maps. Data storage protections are limited, meaning user data may not be fully protected.
Best for
Reporting news with standard cloud analytics
Avoid if
You share sensitive location or personal details
Findings
- 2 critical
- 7 high
- 5 medium
- 2 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Azure Blob Storage Account Key Hardcoded in APK
- Apache Tika XML External Entity (XXE) Injection
- Google API Keys Hardcoded and Potentially Unrestricted
Top privacy issues
- Inaccurate Privacy Disclosure - Third-Party Data Sharing
- Analytics Enabled Without User Consent
- Missing FLAG_SECURE (Screenshot Protection)
Full analysis
OMNI.reporte
What This Means for You
Activity and crash data are sent to Firebase and Microsoft Azure services. Location may be accessed via Google Maps. Data storage protections are limited, meaning user data may not be fully protected.
Recommendation: Use With Caution
Best For: Reporting news with standard cloud analytics
Avoid If: You share sensitive location or personal details
Key Findings
Data Security - 6 findings (1 critical, 3 high, 1 medium, 1 low)
Network Security - 3 findings (1 critical, 1 high, 1 medium)
Code Safety - 0 findings
Privacy - 3 findings (1 high, 2 medium)
Privacy Concerns
What Data is Collected
- Crash reports and diagnostic information (via Firebase Crashlytics)
- App session activity and usage patterns (via Firebase Sessions and Firebase Data Transport)
- Performance telemetry and application events (via Azure Application Insights)
- Location data (via Google Maps SDK)
- File and document content (via Azure Blob Storage and Apache Tika)
Third-Party Data Sharing
Data is shared with the following external services:
- Firebase (Google) - receives crash reports, session activity, and app usage data
- Microsoft Azure - receives performance data; files may be stored in Azure Blob Storage
- Google Maps - accesses location to support mapping features
- Apache Tika - processes documents users interact with inside the app
Understanding the Scores
| Category | Score |
|---|---|
| Security | 35/100 |
| Privacy | 55/100 |
| Data Security | 30/100 |
| Network Security | 40/100 |
| Code Safety | 35/100 |
| Data Collection | 70/100 |
| Data Sharing | 50/100 |
| User Control | 60/100 |
Positive Security Features
- No specific positive security practices were identified for this version of the app.
Areas for Improvement
- Data storage protections are limited, meaning user data stored by the app may not be fully protected.
- Network communications lack sufficient safeguards, meaning data sent between the app and its servers travels with less protection than expected.
- Privacy transparency could be improved so users have a clearer picture of what is collected and meaningful options to limit it.
About This Analysis
This scorecard reflects a static analysis of the app's code and configuration. It evaluates data handling practices, network communication patterns, third-party integrations, and storage behavior.
App Details
- App: OMNI.reporte
- Package ID: com.primerimpacto.reportepi
- Version: 4.35.2
- Scan Date: 2026-02-04
- Developer: Not specified
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #2 (current) | 45/100 |