# Security & Privacy Scorecard

## com.media720.offlinegames

## What This Means for You

Your usage data and device activity may be shared with the app developer and any services it integrates with. Review the category summary below to decide if it fits your needs.

## Recommendation: Trustworthy

This app generally follows good security and privacy practices.

**Best For:** Casual gamers comfortable with standard ad-supported free apps who accept multi-party ad targeting

**Avoid If:** Privacy-conscious users concerned about data sharing with Yandex Russian analytics infrastructure or multiple ad networks

## Key Findings

**Data Security** - 2 findings (2 info)

**Network Security** - 2 findings (1 medium, 1 info)

**Code Safety** - 0 findings

**Privacy** - 2 findings (2 low)

## Privacy Concerns

### What Data is Collected

Review the app's store listing and in-app privacy notices for a full data collection disclosure.

### Third-Party Data Sharing

**The following third parties may receive your data:**
- AppLovin MAX
- Facebook Audience Network
- FBSDKCoreKit
- Google AdMob
- InMobi SDK
- Vungle / Liftoff
- Unity Ads
- MTGSDK (Mintegral)
- IronSource / LevelPlay
- AppMetrica (Yandex)
- Firebase Crashlytics
- Firebase Messaging
- Firebase Remote Config
- KSCrash
- AdAttributionKit
- SKAdNetwork
- GCDWebServer
- Open Measurement SDK (OMSDK)

## Understanding the Scores

**Security:** 93/100
**Privacy:** 88/100

### Security Breakdown

- **Data Security:** 100/100 - how the app handles data at rest
- **Network Security:** 88/100 - how the app handles data in transit
- **Code Safety:** 100/100 - overall code hygiene signals

### Privacy Breakdown

- **Data Collection:** 95/100 - scope of data collected
- **Data Sharing:** 88/100 - third-party data sharing behavior
- **User Control:** 94/100 - controls the app offers you

## Positive Security Features

- Keychain configured with kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly — prevents iCloud sync, device-scoped only
- WKWebView bridge loads only locally bundled game content — no remote URL injection surface
- ATT prompt properly integrated before IDFA access
- No server-side secrets or private keys found anywhere in binary or plists
- VulnFanatic found zero vulnerability patterns across all 40 analyzed framework binaries
- GCDWebServer correctly bound to localhost only — no network exposure
- No camera, microphone, contacts, health, or clipboard permissions requested

## Areas for Improvement

- Review the category summary above for where the app could strengthen its practices.
- Keep the app updated so you receive the latest security improvements from the developer.

---

## About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on mobile applications to help users make informed decisions about app security and privacy.

### App Details

**Developer:** Unknown developer
**Version:** 1.55 (build 15502)
**Analysis Date:** 2026-04-14
**Package:** com.media720.offlinegames
