Scan results

    com.wizzair.WizzAirApp

    iOS

    Budget European airline app for flight bookings, seat selection, and passenger management. Integrates car rental via CarTrawler and multiple payment methods including Revolut Pay.

    CITT SCORE
    88
    out of 100
    TRUSTED

    Quick Verdict

    Best for: General use with standard privacy expectations

    What It Means For You

    Usage data and device activity may be shared with the app developer and any integrated services. Review the category summary below for details.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (11)

    Data Security

    2 total
    1 Medium
    1 Low

    Network Security

    2 total
    1 Medium
    1 Low

    Code Security

    2 total
    2 Low

    Privacy

    2 total
    2 Info

    Third-Party Risk

    3 total
    1 Medium
    2 Info

    Third-Party Services

    TalsecRuntime, MobileShieldKit, Firebase Analytics, Firebase Crashlytics, Firebase Remote Config, Firebase App Check, Firebase Performance Monitoring, Airship (Urban Airship), Coralogix RUM, Google Ads On-Device Conversion, Google App Measurement, Apple AdServices, CarTrawlerSDK, CTPayment, Revolut Pay, Booking.com BookingInApp, Inseat, DittoSwift, DocumentReader (Regula), Sherpa SDK, Alamofire, Realm, FMDB

    Security Strengths

    • Certificate pinning on primary API (be.mobile.wizzair.com) via NSPinnedDomains SPKI-SHA256
    • App Attest (DCAppAttestService) in production mode for device integrity verification
    • TalsecRuntime 6.13.4 RASP with 9 threat categories including jailbreak, debugger, and screenshot detection
    • Biometric-bound Keychain items using SecAccessControlCreateWithFlags and LAContext
    • Realm database encryption infrastructure wired to RLMRealmConfiguration.encryptionKey
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    travel
    sensitive data
    location
    ads

    Package

    com.wizzair.WizzAirApp

    Version

    8.3.2 (Build 1807)

    Analysis Date

    Apr 17, 2026

    Classes Analyzed

    325

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on App Store

    Recommendation: Trustworthy

    This app generally follows good security and privacy practices.

    Key Findings

    Data Security - 2 findings (1 medium, 1 low)

    Network Security - 2 findings (1 medium, 1 low)

    Code Safety - 0 findings

    Privacy - 2 findings (2 info)

    Privacy Concerns

    What Data is Collected

    Review the app's store listing and in-app privacy notices for a full data collection disclosure.

    Third-Party Data Sharing

    The following third parties may receive your data:

    • TalsecRuntime
    • MobileShieldKit
    • Firebase Analytics
    • Firebase Crashlytics
    • Firebase Remote Config
    • Firebase App Check
    • Firebase Performance Monitoring
    • Airship (Urban Airship)
    • Coralogix RUM
    • Google Ads On-Device Conversion
    • Google App Measurement
    • Apple AdServices
    • CarTrawlerSDK
    • CTPayment
    • Revolut Pay
    • Booking.com BookingInApp
    • Inseat
    • DittoSwift
    • DocumentReader (Regula)
    • Sherpa SDK
    • Alamofire
    • Realm
    • FMDB

    Understanding the Scores

    Security: 90/100
    Privacy: 87/100

    Security Breakdown

    • Data Security: 88/100 - how the app handles data at rest
    • Network Security: 88/100 - how the app handles data in transit
    • Code Safety: 94/100 - overall code hygiene signals

    Privacy Breakdown

    • Data Collection: 90/100 - scope of data collected
    • Data Sharing: 92/100 - third-party data sharing behavior
    • User Control: 93/100 - controls the app offers you

    Positive Security Features

    • Certificate pinning on primary API (be.mobile.wizzair.com) via NSPinnedDomains SPKI-SHA256
    • App Attest (DCAppAttestService) in production mode for device integrity verification
    • TalsecRuntime 6.13.4 RASP with 9 threat categories including jailbreak, debugger, and screenshot detection
    • Biometric-bound Keychain items using SecAccessControlCreateWithFlags and LAContext
    • Realm database encryption infrastructure wired to RLMRealmConfiguration.encryptionKey
    • ATT consent correctly implemented via ATTrackingManager before any IDFA access
    • ATS globally enforced — no NSAllowsArbitraryLoads in main Info.plist
    • FirebaseAutomaticScreenReportingEnabled set to false — screen names not auto-reported
    • No JS bridge exposed in main binary WKWebBrowserViewController

    Areas for Improvement

    • Review the category summary above for where the app could strengthen its practices.
    • Keep the app updated so you receive the latest security improvements from the developer.

    About This Analysis

    This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on mobile applications to help users make informed decisions about app security and privacy.

    App Details

    Developer: Unknown developer
    Version: 8.3.2 (Build 1807)
    Analysis Date: 2026-04-17
    Package: com.wizzair.WizzAirApp

    Right of Reply

    Developer not yet contacted