# Security & Privacy Scorecard

## com.wizzair.WizzAirApp

## What This Means for You

Your usage data and device activity may be shared with the app developer and any services it integrates with. Review the category summary below to decide if it fits your needs.

## Recommendation: Trustworthy

This app generally follows good security and privacy practices.

**Best For:** Wizz Air passengers booking flights who accept standard travel-app analytics data sharing

**Avoid If:** Privacy-conscious users or those concerned about third-party payment SDK security (car rental flow)

## Key Findings

**Data Security** - 2 findings (1 medium, 1 low)

**Network Security** - 2 findings (1 medium, 1 low)

**Code Safety** - 0 findings

**Privacy** - 2 findings (2 info)

## Privacy Concerns

### What Data is Collected

Review the app's store listing and in-app privacy notices for a full data collection disclosure.

### Third-Party Data Sharing

**The following third parties may receive your data:**
- TalsecRuntime
- MobileShieldKit
- Firebase Analytics
- Firebase Crashlytics
- Firebase Remote Config
- Firebase App Check
- Firebase Performance Monitoring
- Airship (Urban Airship)
- Coralogix RUM
- Google Ads On-Device Conversion
- Google App Measurement
- Apple AdServices
- CarTrawlerSDK
- CTPayment
- Revolut Pay
- Booking.com BookingInApp
- Inseat
- DittoSwift
- DocumentReader (Regula)
- Sherpa SDK
- Alamofire
- Realm
- FMDB

## Understanding the Scores

**Security:** 90/100
**Privacy:** 87/100

### Security Breakdown

- **Data Security:** 88/100 - how the app handles data at rest
- **Network Security:** 88/100 - how the app handles data in transit
- **Code Safety:** 94/100 - overall code hygiene signals

### Privacy Breakdown

- **Data Collection:** 90/100 - scope of data collected
- **Data Sharing:** 92/100 - third-party data sharing behavior
- **User Control:** 93/100 - controls the app offers you

## Positive Security Features

- Certificate pinning on primary API (be.mobile.wizzair.com) via NSPinnedDomains SPKI-SHA256
- App Attest (DCAppAttestService) in production mode for device integrity verification
- TalsecRuntime 6.13.4 RASP with 9 threat categories including jailbreak, debugger, and screenshot detection
- Biometric-bound Keychain items using SecAccessControlCreateWithFlags and LAContext
- Realm database encryption infrastructure wired to RLMRealmConfiguration.encryptionKey
- ATT consent correctly implemented via ATTrackingManager before any IDFA access
- ATS globally enforced — no NSAllowsArbitraryLoads in main Info.plist
- FirebaseAutomaticScreenReportingEnabled set to false — screen names not auto-reported
- No JS bridge exposed in main binary WKWebBrowserViewController

## Areas for Improvement

- Review the category summary above for where the app could strengthen its practices.
- Keep the app updated so you receive the latest security improvements from the developer.

---

## About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on mobile applications to help users make informed decisions about app security and privacy.

### App Details

**Developer:** Unknown developer
**Version:** 8.3.2 (Build 1807)
**Analysis Date:** 2026-04-17
**Package:** com.wizzair.WizzAirApp
