World App - Real Human Network Security & Privacy Scorecard

Android

58
Overall trust score
Use With Caution
55
Security
72
Privacy

Best for

Tech-savvy users who understand the risks and value zero-knowledge identity verification

Avoid if

Privacy-focused users uncomfortable with extensive tracking or users handling large crypto assets

Findings

  • 2 critical
  • 6 high
  • 12 medium
  • 1 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • File Access Enabled in NFC Age Verification WebView
  • Turnkey Single Point of Failure for Wallet Access
  • Unencrypted SQLite Database with Sensitive Data

Top privacy issues

  • Excessive Analytics SDKs - Privacy Concern
  • Fingerprint.js Device Fingerprinting Without Opt-Out
  • Regula Document Reader SDK - Closed-Source with Privileged Access

Full analysis

App: World App - Real Human Network
Package ID: com.worldcoin
Version: 2.9.701
Developer: TFH
Category: Finance
Analysis Date: December 18, 2025


Overall Security Score: 58/100 (D)

Total Security & Privacy Issues: 20


Executive Summary

World is a real human network mobile app providing proof of humanity via World ID for online authentication, access to mini-apps ecosystem, and digital wallet functionality using USDC with no transaction fees.

Primary Security Concern: The app contains a critical WebView vulnerability that allows malicious scripts to access sensitive local files including encrypted settings and database files. Combined with centralized wallet infrastructure and extensive tracking, this presents significant risks for users handling financial assets or concerned about privacy.


Category Scores

Category Score Grade
Security 55/100 D
Privacy 72/100 C
Data Security 52/100 D
Network Security 88/100 B
Code Safety 60/100 D
Data Collection 70/100 C
Data Sharing 68/100 C
User Control 65/100 D

Key Findings

Critical Security Issues (2)

  1. WebView File Access Vulnerability

    • Third-party content loaded in age verification can access local device files
    • Could expose encrypted settings, database files, and user data
    • Impact: High risk of data theft if malicious content is loaded
  2. Centralized Wallet Infrastructure

    • All wallet keys managed exclusively through third-party service (Turnkey)
    • Single point of failure for all user wallets
    • Service compromise or outage could affect wallet access for all users

High Security Issues (6)

  1. Unencrypted Local Database

    • Chat messages, contacts, and transaction history stored without encryption
    • Accessible with device root access or malware with elevated privileges
  2. Excessive Third-Party Web Access

    • Mini-apps can trigger payments, access contacts, and use microphone
    • Risk of malicious mini-apps performing unauthorized actions
  3. Outdated Cryptography Library

    • Uses 3-year-old Web3j library for blockchain transactions
    • May contain known security vulnerabilities
  4. Overly Permissive File Sharing

    • App can access entire external storage, not just specific folders
    • Could allow access to user's private documents
  5. Face Authentication Bypass Risk

    • Security thresholds for face recognition exposed in app code
    • Attackers could create synthetic images to bypass authentication
  6. Unvalidated Camera/File Access

    • Third-party scripts can trigger file picker or camera without validation
    • No origin checks or explicit user confirmation

Privacy Concerns (3)

  1. Extensive Tracking Infrastructure

    • 10+ analytics SDKs with overlapping capabilities
    • Includes Braze, PostHog, AppsFlyer, Statsig, Datadog, Fingerprint.js, Firebase, and more
  2. Device Fingerprinting

    • Automatic device fingerprinting with no user opt-out
    • Enables persistent tracking that survives app reinstalls
  3. Closed-Source Document Scanner

    • Third-party passport scanning SDK with privileged access to sensitive ID data
    • No visible independent security audit

Security Strengths

  • Strong Network Security: Certificate pinning implemented for main API endpoints
  • Hardware-Backed Encryption: Android Keystore integration with hardware security
  • Privacy-Preserving Authentication: Zero-knowledge proofs for identity verification
  • End-to-End Encryption: Chat and backup data encrypted end-to-end
  • Modern Cryptography: Google Tink library for AES-256 encryption
  • Cloud Backup Protection: Standard backups disabled to prevent Google Cloud exposure

What This App Collects

Based on declared permissions and code analysis:

  • Personal Information: Name, email, phone number, passport data
  • Identity Data: Biometric face scans, World ID credentials
  • Financial Data: Wallet addresses, transaction history, USDC balances
  • Contact Information: Phone contacts for social features
  • Location Data: Approximate and precise location
  • Device Information: Device ID, phone status, Wi-Fi connections
  • Usage Data: App interactions, feature usage, analytics events
  • Communication: Chat messages, mini-app interactions

Third-Party Services

The app shares data with multiple third-party services:

Financial & Infrastructure:

  • Turnkey (wallet management)
  • Uniswap (token swaps)
  • Circle (USDC stablecoin)

Analytics & Tracking:

  • PostHog, Braze, Firebase Analytics, AppsFlyer, Statsig, Datadog, Fingerprint.js

Identity & Security:

  • Regula Document Reader (passport scanning)
  • AiPrise (age verification)

Communication:

  • XMTP (messaging protocol)
  • Zendesk (customer support)

Platform Services:

  • Google Play Services, ML Kit

Compliance & Standards

Areas for Improvement

Data Protection:

  • Local database encryption would better protect user data
  • Single points of failure in wallet infrastructure increase risk

Privacy Controls:

  • Limited opt-out mechanisms for tracking
  • Device fingerprinting occurs automatically

Third-Party Risk:

  • Multiple analytics SDKs increase attack surface
  • Closed-source components handle sensitive data without transparency

Who Should Use This App

Best For:

  • Tech-savvy users who understand blockchain and crypto wallets
  • Users who value zero-knowledge identity verification
  • People comfortable with extensive tracking in exchange for free services
  • Users seeking proof-of-humanity for online services

Avoid If:

  • Privacy-focused users uncomfortable with 10+ tracking SDKs
  • Users handling large cryptocurrency assets (due to centralized wallet risks)
  • Users requiring offline wallet backup options
  • Users on rooted/jailbroken devices (due to unencrypted database)

Recommendation: Significant Security Concerns

Verdict: Critical WebView vulnerability allows file access to local data, centralized wallet infrastructure, and excessive tracking SDKs. Only recommended for tech-savvy users understanding the risks; unsuitable for privacy-focused users or those holding significant assets.

Risk Summary:

  • Security Risk: Moderate to High (WebView vulnerability, wallet centralization)
  • Privacy Risk: Moderate (extensive tracking, device fingerprinting)
  • Data Protection: Moderate (unencrypted database, broad file access)

Recommendations for Users:

  1. Use only on non-rooted devices to protect local database
  2. Keep small balances in the wallet due to centralized infrastructure
  3. Be cautious when using mini-apps from unknown sources
  4. Review and minimize granted permissions when possible
  5. Keep the app updated to receive security patches

Analysis Metadata

  • Version Analyzed: 2.9.701
  • Analysis Date: December 18, 2025
  • Classes Analyzed: 0
  • Report Type: Public Security Scorecard

This analysis is based on static code analysis and may not reflect runtime behavior or server-side security measures. Security and privacy practices may change with app updates.

Powered by canITrustThat APK Security Analysis

Versions & scan history

ScanDateOverall score
#4 (current) 58/100
#3 42/100
#2 44/100
#1 42/100