Scan results

    Mój Orange

    Android

    Official Orange Polska account management app. Manage your account, pay invoices, add service packages, control Wi-Fi, receive offers, and top-up prepaid phones.

    unTRUSTED

    This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.

    The five trust checks

    CITT SCORE
    73
    out of 100
    unTRUSTED

    Quick Verdict

    Best for: Orange Poland subscribers managing their plan

    What It Means For You

    App usage and behavioral data is shared with AppsFlyer, Firebase Analytics, Synerise, QuantumMetric, and Google Tag Manager for analytics, CRM, and marketing purposes. Session interactions within the app are recorded by QuantumMetric for behavioral analysis. Some network activity may travel with less protection than expected on public Wi-Fi.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (10)

    Data Security

    3 total
    3 Info

    Network Security

    2 total
    2 Medium

    Code Security

    2 total
    1 High
    1 Low

    Privacy

    1 total
    1 Medium

    Third-Party Risk

    2 total
    2 Medium

    Third-Party Services

    AppsFlyer, Firebase Analytics, Firebase Crashlytics, Firebase Remote Config, Firebase Messaging, Synerise, QuantumMetric, Google Tag Manager, Google Play Services Auth, Closer SDK, OkHttp3, Retrofit2, BouncyCastle, WebRTC KMP, Lottie, ANRWatchDog

    Security Strengths

    • Closer SDK uses Google Tink AES256-GCM with Android Keystore for secure local storage
    • Synerise SDK encrypts auth tokens with AES-256 GCM backed by Android Keystore
    • App-level backup disabled (android:allowBackup=false)
    • Synerise CRM API uses certificate pinning
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    telecom
    session recording
    gdpr

    Package

    pl.orange.mojeorange

    Version

    5.144.0.15921 (versionCode 65921)

    Analysis Date

    Jun 13, 2026

    Classes Analyzed

    3,400

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Acceptable

    If you're an Orange Poland customer, this app is necessary for managing your account, paying invoices, and controlling your services. A design issue in the app's web-integrated login pages could allow compromised web content to capture your account password, and five analytics services receive your behavioral data. Session recordings may also include sensitive billing and payment screen activity.

    Key Findings

    Data Security - 3 findings (3 info)

    Network Security - 2 findings (2 medium)

    Code Safety - 3 findings (1 high, 1 medium, 1 low)

    Privacy - 2 findings (2 medium)

    Privacy Concerns

    What Data is Collected

    • Personal information: Account name, phone number, and billing details sent to Orange servers for account management.
    • Device information: Device advertising ID and Android ID shared with AppsFlyer, Synerise, and Firebase Analytics for attribution and behavioral analytics.
    • Usage data: In-app interactions and session recordings shared with QuantumMetric, Synerise, Firebase Analytics, and Google Tag Manager. Google Tag Manager may also inject additional tracking behavior without requiring an app update.
    • Location data: Precise location is accessed on your device to support service-related features. Depending on how analytics services are configured, it may be transmitted to analytics partners.

    Third-Party Data Sharing

    The following third parties may receive your data:

    • AppsFlyer - Install attribution and in-app purchase event tracking
    • Firebase Analytics - App usage event reporting and behavioral analytics
    • Synerise - CRM and behavioral analytics, including device type, network type, push notification consent, and app launch events
    • QuantumMetric - Session replay and screen interaction recording
    • Google Tag Manager - Dynamic behavior configuration that may add tracking without requiring an app update

    Understanding the Scores

    Security: 76/100
    Privacy: 72/100

    Security Breakdown

    • Data Security: 100/100 - Sensitive data stored on your device is well protected. Local storage uses hardware-backed encryption aligned with Android security best practices.
    • Network Security: 80/100 - Most communication with Orange servers is protected. A network configuration exception permits unencrypted connections to two primary API server addresses, though static analysis alone cannot confirm whether any active code path currently uses this exception.
    • Code Safety: 76/100 - The app's overall structure is reasonably solid. A login bridge accessible from web page content and an exposed debugging mechanism present risks that would benefit from remediation.

    Privacy Breakdown

    • Data Collection: 78/100 - Device identifiers and behavioral data are shared with five analytics services. Each service receives a portion of your in-app activity, contributing to a broad combined data profile.
    • Data Sharing: 74/100 - Your usage behavior and device identifiers flow to multiple third parties including install attribution, session recording, and CRM analytics providers.
    • User Control: 82/100 - The app supports data deletion on request and encrypts data in transit. Individual opt-out controls for specific third-party analytics services are less visible to users.

    Positive Security Features

    • Sensitive data stored locally on your device is protected with hardware-backed encryption, following strong Android security practices.
    • App backups via developer tools are disabled, preventing unauthorized extraction of app data from the device.
    • The Synerise marketing platform connection uses an additional layer of server identity verification beyond standard encrypted connections.
    • Data is encrypted during transmission between the app and Orange servers.

    Areas for Improvement

    GDPR / CCPA Compliance

    The app's privacy practices could be strengthened by:

    1. Session Recording Transparency
      The screen interaction recording service may capture payment and billing screens. Documenting which screens are excluded from session recordings and making that information accessible to users would strengthen privacy compliance for a telecom app serving 10M+ customers.

    2. Per-Service Analytics Consent
      Five separate analytics services receive behavioral data. Providing users with individual opt-out controls for each service would help meet the requirement for a separate lawful basis per third-party data transfer.

    Security Enhancements

    1. Network Configuration Hardening
      Removing the configuration exception that permits unencrypted connections to the two primary API server addresses would eliminate the theoretical risk of unprotected data transmission to those endpoints.

    2. Web Login Bridge Protection
      Adding origin validation to the web-to-native login mechanism would prevent compromised or malicious web content from triggering the native login flow and capturing account passwords.

    Technical Context

    App Type: Telecom account management - high sensitivity (billing, authentication, personal data)
    Classes Analyzed: 3,400
    Third-Party Services: 16
    Context Tags: financial, sensitive_data, telecom, session_recording, gdpr


    About This Analysis

    This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.

    App Details

    Developer: Orange Polska
    Version: 5.144.0.15921 (versionCode 65921)
    Analysis Date: 2026-06-13
    Package: pl.orange.mojeorange

    Analysis Limitations

    • Static analysis only (code review without running the app)
    • Based on APK version 5.144.0.15921 analyzed on 2026-06-13
    • May not reflect server-side security controls
    • Cannot detect all runtime behaviors

    Right of Reply

    Developer not yet contacted