Scan results

    VLC for Android

    Android

    TRUSTish

    This app did not meet one of the trust checks in this assessment.

    The five trust checks

    CITT SCORE
    75
    out of 100
    TRUSTish

    What It Means For You

    The code sends credentials to OpenSubtitles, and authentication tokens to OpenSubtitles. Another 3 data points are sent out to other third parties. Four high severity findings related to Data Security and Network Security are worth reading before this build handles anything a user would want kept to themselves.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (370)

    Data Security

    105 total
    3 High
    31 Medium
    71 Low

    Network Security

    42 total
    1 High
    13 Medium
    28 Low

    Code Security

    147 total
    31 Medium
    116 Low

    Privacy

    46 total
    5 Medium
    41 Low

    Third-Party Risk

    18 total
    18 Low

    Permission Usage

    12 total
    1 Medium
    11 Low
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Package

    org.videolan.vlc

    Analysis Date

    Sep 10, 2026

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    What This App Collects

    The code sends credentials to OpenSubtitles; authentication tokens to OpenSubtitles; media files to OpenSubtitles; and network identifiers to libVLC MediaBrowser (VideoLAN, in-process native). Another 1 data point is sent out to other third parties.

    Other findings record data the code reads on the device and data arriving from a server.

    Can This Be Trusted

    The code sends data out of the device to third-party recipients. Some of those flows are recorded on paths that lack a consent step.

    Four high severity findings related to Code Security, Data Security and Privacy are worth reading before this build handles anything a user would want kept to themselves.

    What Needs Attention

    Four findings need attention. Three are about how data is stored on the device, one about how the app connects to servers. The detailed report states each of these in full.

    Scores

    • Overall: 75/100
    • Security: 68/100. Held down by how data is stored on the device and by how the app is put together.
    • Privacy: 91/100. Held down by the amount collected and by how little of it is recorded as consented to.
    • Data Security: 76/100
    • Network Security: 82/100
    • Code Safety: 78/100
    • Data Collection: 92/100
    • Data Sharing: 97/100
    • User Control: 91/100
    • Permission Usage: 96/100

    What the Score Set Aside

    Of the 339 findings that describe something this build contains, 43 describe code inside bundled libraries that the call graph shows this build leaves unused. They keep their recorded severity and are named in full in the detailed report; the score was computed over the other 296.

    The largest group is bouncycastle (43).

    Set aside by library:

    • bouncycastle (43)

    How This Was Checked

    Of 186 planned analysis tasks, 1 was asked for and did not come back. This page covers the rest.

    CITT examined 761 files, traced 106 data flows and recorded 373 findings.

    On whether the user was asked first, across the 106 flows recorded, not only the outbound ones: 68 have an unsettled consent state either way; 31 run on paths recorded without a consent step; 7 run after a recorded consent grant.

    About This Analysis

    This assessment was produced by CITT (Can I Trust That), an independent analysis service. Each statement above comes from one recorded claim, given here as a summary of what was found rather than as the evidence for it.

    Right of Reply

    Developer not yet contacted