com.wizzair.WizzAirApp Security & Privacy Scorecard
iOS
Usage data and device activity may be shared with the app developer and any integrated services. Review the category summary below for details.
Best for
General use with standard privacy expectations
Findings
- 0 critical
- 0 high
- 3 medium
- 4 low
- 4 info
1 issue identified across security and privacy analysis.
Top security issues
- CarTrawler Payment WebView Wildcard postMessage Origin
- Keychain Items Use Deprecated kSecAttrAccessibleAlways Policy
- CarTrawlerSDK Stores Rental Booking and Payment Card Data in Plaintext SQLite
Top privacy issues
- Airship UANativeBridge Exposes Native SDK Actions Without URL Allowlist
- Multi-SDK Analytics Stack with Five Simultaneous Telemetry Systems
- Google Ads SDK Collects IDFA for Cross-App Ad Conversion When ATT Authorized
Full analysis
What This Means for You
Your usage data and device activity may be shared with the app developer and any services it integrates with. Review the category summary below to decide if it fits your needs.
Recommendation: Trustworthy
This app generally follows good security and privacy practices.
Best For: Wizz Air passengers booking flights who accept standard travel-app analytics data sharing
Avoid If: Privacy-conscious users or those concerned about third-party payment SDK security (car rental flow)
Key Findings
Data Security - 2 findings (1 medium, 1 low)
Network Security - 2 findings (1 medium, 1 low)
Code Safety - 0 findings
Privacy - 2 findings (2 info)
Privacy Concerns
What Data is Collected
Review the app's store listing and in-app privacy notices for a full data collection disclosure.
Third-Party Data Sharing
The following third parties may receive your data:
- TalsecRuntime
- MobileShieldKit
- Firebase Analytics
- Firebase Crashlytics
- Firebase Remote Config
- Firebase App Check
- Firebase Performance Monitoring
- Airship (Urban Airship)
- Coralogix RUM
- Google Ads On-Device Conversion
- Google App Measurement
- Apple AdServices
- CarTrawlerSDK
- CTPayment
- Revolut Pay
- Booking.com BookingInApp
- Inseat
- DittoSwift
- DocumentReader (Regula)
- Sherpa SDK
- Alamofire
- Realm
- FMDB
Understanding the Scores
Security: 90/100
Privacy: 87/100
Security Breakdown
- Data Security: 88/100 - how the app handles data at rest
- Network Security: 88/100 - how the app handles data in transit
- Code Safety: 94/100 - overall code hygiene signals
Privacy Breakdown
- Data Collection: 90/100 - scope of data collected
- Data Sharing: 92/100 - third-party data sharing behavior
- User Control: 93/100 - controls the app offers you
Positive Security Features
- Certificate pinning on primary API (be.mobile.wizzair.com) via NSPinnedDomains SPKI-SHA256
- App Attest (DCAppAttestService) in production mode for device integrity verification
- TalsecRuntime 6.13.4 RASP with 9 threat categories including jailbreak, debugger, and screenshot detection
- Biometric-bound Keychain items using SecAccessControlCreateWithFlags and LAContext
- Realm database encryption infrastructure wired to RLMRealmConfiguration.encryptionKey
- ATT consent correctly implemented via ATTrackingManager before any IDFA access
- ATS globally enforced — no NSAllowsArbitraryLoads in main Info.plist
- FirebaseAutomaticScreenReportingEnabled set to false — screen names not auto-reported
- No JS bridge exposed in main binary WKWebBrowserViewController
Areas for Improvement
- Review the category summary above for where the app could strengthen its practices.
- Keep the app updated so you receive the latest security improvements from the developer.
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on mobile applications to help users make informed decisions about app security and privacy.
App Details
Developer: Unknown developer
Version: 8.3.2 (Build 1807)
Analysis Date: 2026-04-17
Package: com.wizzair.WizzAirApp
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #2 (current) | 88/100 |