World App - Real Human Network Security & Privacy Scorecard
Android
Best for
Tech-savvy users who understand the risks and value zero-knowledge identity verification
Avoid if
Privacy-focused users uncomfortable with extensive tracking or users handling large crypto assets
Findings
- 2 critical
- 6 high
- 12 medium
- 1 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- File Access Enabled in NFC Age Verification WebView
- Turnkey Single Point of Failure for Wallet Access
- Unencrypted SQLite Database with Sensitive Data
Top privacy issues
- Excessive Analytics SDKs - Privacy Concern
- Fingerprint.js Device Fingerprinting Without Opt-Out
- Regula Document Reader SDK - Closed-Source with Privileged Access
Full analysis
App: World App - Real Human Network
Package ID: com.worldcoin
Version: 2.9.701
Developer: TFH
Category: Finance
Analysis Date: December 18, 2025
Overall Security Score: 58/100 (D)
Total Security & Privacy Issues: 20
Executive Summary
World is a real human network mobile app providing proof of humanity via World ID for online authentication, access to mini-apps ecosystem, and digital wallet functionality using USDC with no transaction fees.
Primary Security Concern: The app contains a critical WebView vulnerability that allows malicious scripts to access sensitive local files including encrypted settings and database files. Combined with centralized wallet infrastructure and extensive tracking, this presents significant risks for users handling financial assets or concerned about privacy.
Category Scores
| Category | Score | Grade |
|---|---|---|
| Security | 55/100 | D |
| Privacy | 72/100 | C |
| Data Security | 52/100 | D |
| Network Security | 88/100 | B |
| Code Safety | 60/100 | D |
| Data Collection | 70/100 | C |
| Data Sharing | 68/100 | C |
| User Control | 65/100 | D |
Key Findings
Critical Security Issues (2)
WebView File Access Vulnerability
- Third-party content loaded in age verification can access local device files
- Could expose encrypted settings, database files, and user data
- Impact: High risk of data theft if malicious content is loaded
Centralized Wallet Infrastructure
- All wallet keys managed exclusively through third-party service (Turnkey)
- Single point of failure for all user wallets
- Service compromise or outage could affect wallet access for all users
High Security Issues (6)
Unencrypted Local Database
- Chat messages, contacts, and transaction history stored without encryption
- Accessible with device root access or malware with elevated privileges
Excessive Third-Party Web Access
- Mini-apps can trigger payments, access contacts, and use microphone
- Risk of malicious mini-apps performing unauthorized actions
Outdated Cryptography Library
- Uses 3-year-old Web3j library for blockchain transactions
- May contain known security vulnerabilities
Overly Permissive File Sharing
- App can access entire external storage, not just specific folders
- Could allow access to user's private documents
Face Authentication Bypass Risk
- Security thresholds for face recognition exposed in app code
- Attackers could create synthetic images to bypass authentication
Unvalidated Camera/File Access
- Third-party scripts can trigger file picker or camera without validation
- No origin checks or explicit user confirmation
Privacy Concerns (3)
Extensive Tracking Infrastructure
- 10+ analytics SDKs with overlapping capabilities
- Includes Braze, PostHog, AppsFlyer, Statsig, Datadog, Fingerprint.js, Firebase, and more
Device Fingerprinting
- Automatic device fingerprinting with no user opt-out
- Enables persistent tracking that survives app reinstalls
Closed-Source Document Scanner
- Third-party passport scanning SDK with privileged access to sensitive ID data
- No visible independent security audit
Security Strengths
- Strong Network Security: Certificate pinning implemented for main API endpoints
- Hardware-Backed Encryption: Android Keystore integration with hardware security
- Privacy-Preserving Authentication: Zero-knowledge proofs for identity verification
- End-to-End Encryption: Chat and backup data encrypted end-to-end
- Modern Cryptography: Google Tink library for AES-256 encryption
- Cloud Backup Protection: Standard backups disabled to prevent Google Cloud exposure
What This App Collects
Based on declared permissions and code analysis:
- Personal Information: Name, email, phone number, passport data
- Identity Data: Biometric face scans, World ID credentials
- Financial Data: Wallet addresses, transaction history, USDC balances
- Contact Information: Phone contacts for social features
- Location Data: Approximate and precise location
- Device Information: Device ID, phone status, Wi-Fi connections
- Usage Data: App interactions, feature usage, analytics events
- Communication: Chat messages, mini-app interactions
Third-Party Services
The app shares data with multiple third-party services:
Financial & Infrastructure:
- Turnkey (wallet management)
- Uniswap (token swaps)
- Circle (USDC stablecoin)
Analytics & Tracking:
- PostHog, Braze, Firebase Analytics, AppsFlyer, Statsig, Datadog, Fingerprint.js
Identity & Security:
- Regula Document Reader (passport scanning)
- AiPrise (age verification)
Communication:
- XMTP (messaging protocol)
- Zendesk (customer support)
Platform Services:
- Google Play Services, ML Kit
Compliance & Standards
Areas for Improvement
Data Protection:
- Local database encryption would better protect user data
- Single points of failure in wallet infrastructure increase risk
Privacy Controls:
- Limited opt-out mechanisms for tracking
- Device fingerprinting occurs automatically
Third-Party Risk:
- Multiple analytics SDKs increase attack surface
- Closed-source components handle sensitive data without transparency
Who Should Use This App
Best For:
- Tech-savvy users who understand blockchain and crypto wallets
- Users who value zero-knowledge identity verification
- People comfortable with extensive tracking in exchange for free services
- Users seeking proof-of-humanity for online services
Avoid If:
- Privacy-focused users uncomfortable with 10+ tracking SDKs
- Users handling large cryptocurrency assets (due to centralized wallet risks)
- Users requiring offline wallet backup options
- Users on rooted/jailbroken devices (due to unencrypted database)
Recommendation: Significant Security Concerns
Verdict: Critical WebView vulnerability allows file access to local data, centralized wallet infrastructure, and excessive tracking SDKs. Only recommended for tech-savvy users understanding the risks; unsuitable for privacy-focused users or those holding significant assets.
Risk Summary:
- Security Risk: Moderate to High (WebView vulnerability, wallet centralization)
- Privacy Risk: Moderate (extensive tracking, device fingerprinting)
- Data Protection: Moderate (unencrypted database, broad file access)
Recommendations for Users:
- Use only on non-rooted devices to protect local database
- Keep small balances in the wallet due to centralized infrastructure
- Be cautious when using mini-apps from unknown sources
- Review and minimize granted permissions when possible
- Keep the app updated to receive security patches
Analysis Metadata
- Version Analyzed: 2.9.701
- Analysis Date: December 18, 2025
- Classes Analyzed: 0
- Report Type: Public Security Scorecard
This analysis is based on static code analysis and may not reflect runtime behavior or server-side security measures. Security and privacy practices may change with app updates.
Powered by canITrustThat APK Security Analysis
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #4 (current) | 58/100 | |
| #3 | 42/100 | |
| #2 | 44/100 | |
| #1 | 42/100 |