This app did not meet one of the trust checks in this assessment.
The five trust checks
What It Means For You
The code sends credentials to OpenSubtitles, and authentication tokens to OpenSubtitles. Another 3 data points are sent out to other third parties. Four high severity findings related to Data Security and Network Security are worth reading before this build handles anything a user would want kept to themselves.
What It Means For You
The code sends credentials to OpenSubtitles, and authentication tokens to OpenSubtitles. Another 3 data points are sent out to other third parties. Four high severity findings related to Data Security and Network Security are worth reading before this build handles anything a user would want kept to themselves.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
105 totalNetwork Security
42 totalCode Security
147 totalPrivacy
46 totalThird-Party Risk
18 totalPermission Usage
12 totalVersion diff is on the Developer plan. See developer plans.
Package
org.videolan.vlc
Analysis Date
Sep 10, 2026
Feedback helps us improve our analysis
The code sends credentials to OpenSubtitles; authentication tokens to OpenSubtitles; media files to OpenSubtitles; and network identifiers to libVLC MediaBrowser (VideoLAN, in-process native). Another 1 data point is sent out to other third parties.
Other findings record data the code reads on the device and data arriving from a server.
The code sends data out of the device to third-party recipients. Some of those flows are recorded on paths that lack a consent step.
Four high severity findings related to Code Security, Data Security and Privacy are worth reading before this build handles anything a user would want kept to themselves.
Four findings need attention. Three are about how data is stored on the device, one about how the app connects to servers. The detailed report states each of these in full.
Of the 339 findings that describe something this build contains, 43 describe code inside bundled libraries that the call graph shows this build leaves unused. They keep their recorded severity and are named in full in the detailed report; the score was computed over the other 296.
The largest group is bouncycastle (43).
Set aside by library:
Of 186 planned analysis tasks, 1 was asked for and did not come back. This page covers the rest.
CITT examined 761 files, traced 106 data flows and recorded 373 findings.
On whether the user was asked first, across the 106 flows recorded, not only the outbound ones: 68 have an unsettled consent state either way; 31 run on paths recorded without a consent step; 7 run after a recorded consent grant.
This assessment was produced by CITT (Can I Trust That), an independent analysis service. Each statement above comes from one recorded claim, given here as a summary of what was found rather than as the evidence for it.
Developer not yet contacted