OMNI.reporte Security & Privacy Scorecard

Android

45
Overall trust score
Unsafe
35
Security
55
Privacy

Activity and crash data are sent to Firebase and Microsoft Azure services. Location may be accessed via Google Maps. Data storage protections are limited, meaning user data may not be fully protected.

Best for

Reporting news with standard cloud analytics

Avoid if

You share sensitive location or personal details

Findings

  • 2 critical
  • 7 high
  • 5 medium
  • 2 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • Azure Blob Storage Account Key Hardcoded in APK
  • Apache Tika XML External Entity (XXE) Injection
  • Google API Keys Hardcoded and Potentially Unrestricted

Top privacy issues

  • Inaccurate Privacy Disclosure - Third-Party Data Sharing
  • Analytics Enabled Without User Consent
  • Missing FLAG_SECURE (Screenshot Protection)

Full analysis

OMNI.reporte

What This Means for You

Activity and crash data are sent to Firebase and Microsoft Azure services. Location may be accessed via Google Maps. Data storage protections are limited, meaning user data may not be fully protected.

Recommendation: Use With Caution

Best For: Reporting news with standard cloud analytics
Avoid If: You share sensitive location or personal details

Key Findings

Data Security - 6 findings (1 critical, 3 high, 1 medium, 1 low)

Network Security - 3 findings (1 critical, 1 high, 1 medium)

Code Safety - 0 findings

Privacy - 3 findings (1 high, 2 medium)

Privacy Concerns

What Data is Collected

  • Crash reports and diagnostic information (via Firebase Crashlytics)
  • App session activity and usage patterns (via Firebase Sessions and Firebase Data Transport)
  • Performance telemetry and application events (via Azure Application Insights)
  • Location data (via Google Maps SDK)
  • File and document content (via Azure Blob Storage and Apache Tika)

Third-Party Data Sharing

Data is shared with the following external services:

  • Firebase (Google) - receives crash reports, session activity, and app usage data
  • Microsoft Azure - receives performance data; files may be stored in Azure Blob Storage
  • Google Maps - accesses location to support mapping features
  • Apache Tika - processes documents users interact with inside the app

Understanding the Scores

Category Score
Security 35/100
Privacy 55/100
Data Security 30/100
Network Security 40/100
Code Safety 35/100
Data Collection 70/100
Data Sharing 50/100
User Control 60/100

Positive Security Features

  • No specific positive security practices were identified for this version of the app.

Areas for Improvement

  • Data storage protections are limited, meaning user data stored by the app may not be fully protected.
  • Network communications lack sufficient safeguards, meaning data sent between the app and its servers travels with less protection than expected.
  • Privacy transparency could be improved so users have a clearer picture of what is collected and meaningful options to limit it.

About This Analysis

This scorecard reflects a static analysis of the app's code and configuration. It evaluates data handling practices, network communication patterns, third-party integrations, and storage behavior.

App Details

  • App: OMNI.reporte
  • Package ID: com.primerimpacto.reportepi
  • Version: 4.35.2
  • Scan Date: 2026-02-04
  • Developer: Not specified

Versions & scan history

ScanDateOverall score
#2 (current) 45/100