# Security Scorecard: World App - Real Human Network

**App:** World App - Real Human Network
**Package ID:** com.worldcoin
**Version:** 2.9.701
**Developer:** TFH
**Category:** Finance
**Analysis Date:** December 18, 2025

---

## Overall Security Score: 58/100 (D)

### Total Security & Privacy Issues: 20

---

## Executive Summary

World is a real human network mobile app providing proof of humanity via World ID for online authentication, access to mini-apps ecosystem, and digital wallet functionality using USDC with no transaction fees.

**Primary Security Concern:** The app contains a critical WebView vulnerability that allows malicious scripts to access sensitive local files including encrypted settings and database files. Combined with centralized wallet infrastructure and extensive tracking, this presents significant risks for users handling financial assets or concerned about privacy.

---

## Category Scores

| Category | Score | Grade |
|----------|-------|-------|
| **Security** | 55/100 | D |
| **Privacy** | 72/100 | C |
| **Data Security** | 52/100 | D |
| **Network Security** | 88/100 | B |
| **Code Safety** | 60/100 | D |
| **Data Collection** | 70/100 | C |
| **Data Sharing** | 68/100 | C |
| **User Control** | 65/100 | D |

---

## Key Findings

### Critical Security Issues (2)

1. **WebView File Access Vulnerability**
   - Third-party content loaded in age verification can access local device files
   - Could expose encrypted settings, database files, and user data
   - Impact: High risk of data theft if malicious content is loaded

2. **Centralized Wallet Infrastructure**
   - All wallet keys managed exclusively through third-party service (Turnkey)
   - Single point of failure for all user wallets
   - Service compromise or outage could affect wallet access for all users

### High Security Issues (6)

3. **Unencrypted Local Database**
   - Chat messages, contacts, and transaction history stored without encryption
   - Accessible with device root access or malware with elevated privileges

4. **Excessive Third-Party Web Access**
   - Mini-apps can trigger payments, access contacts, and use microphone
   - Risk of malicious mini-apps performing unauthorized actions

5. **Outdated Cryptography Library**
   - Uses 3-year-old Web3j library for blockchain transactions
   - May contain known security vulnerabilities

6. **Overly Permissive File Sharing**
   - App can access entire external storage, not just specific folders
   - Could allow access to user's private documents

7. **Face Authentication Bypass Risk**
   - Security thresholds for face recognition exposed in app code
   - Attackers could create synthetic images to bypass authentication

8. **Unvalidated Camera/File Access**
   - Third-party scripts can trigger file picker or camera without validation
   - No origin checks or explicit user confirmation

### Privacy Concerns (3)

9. **Extensive Tracking Infrastructure**
   - 10+ analytics SDKs with overlapping capabilities
   - Includes Braze, PostHog, AppsFlyer, Statsig, Datadog, Fingerprint.js, Firebase, and more

10. **Device Fingerprinting**
    - Automatic device fingerprinting with no user opt-out
    - Enables persistent tracking that survives app reinstalls

11. **Closed-Source Document Scanner**
    - Third-party passport scanning SDK with privileged access to sensitive ID data
    - No visible independent security audit

---

## Security Strengths

- **Strong Network Security:** Certificate pinning implemented for main API endpoints
- **Hardware-Backed Encryption:** Android Keystore integration with hardware security
- **Privacy-Preserving Authentication:** Zero-knowledge proofs for identity verification
- **End-to-End Encryption:** Chat and backup data encrypted end-to-end
- **Modern Cryptography:** Google Tink library for AES-256 encryption
- **Cloud Backup Protection:** Standard backups disabled to prevent Google Cloud exposure

---

## What This App Collects

Based on declared permissions and code analysis:

- **Personal Information:** Name, email, phone number, passport data
- **Identity Data:** Biometric face scans, World ID credentials
- **Financial Data:** Wallet addresses, transaction history, USDC balances
- **Contact Information:** Phone contacts for social features
- **Location Data:** Approximate and precise location
- **Device Information:** Device ID, phone status, Wi-Fi connections
- **Usage Data:** App interactions, feature usage, analytics events
- **Communication:** Chat messages, mini-app interactions

---

## Third-Party Services

The app shares data with multiple third-party services:

**Financial & Infrastructure:**
- Turnkey (wallet management)
- Uniswap (token swaps)
- Circle (USDC stablecoin)

**Analytics & Tracking:**
- PostHog, Braze, Firebase Analytics, AppsFlyer, Statsig, Datadog, Fingerprint.js

**Identity & Security:**
- Regula Document Reader (passport scanning)
- AiPrise (age verification)

**Communication:**
- XMTP (messaging protocol)
- Zendesk (customer support)

**Platform Services:**
- Google Play Services, ML Kit

---

## Compliance & Standards

### Areas for Improvement

**Data Protection:**
- Local database encryption would better protect user data
- Single points of failure in wallet infrastructure increase risk

**Privacy Controls:**
- Limited opt-out mechanisms for tracking
- Device fingerprinting occurs automatically

**Third-Party Risk:**
- Multiple analytics SDKs increase attack surface
- Closed-source components handle sensitive data without transparency

---

## Who Should Use This App

### Best For:
- Tech-savvy users who understand blockchain and crypto wallets
- Users who value zero-knowledge identity verification
- People comfortable with extensive tracking in exchange for free services
- Users seeking proof-of-humanity for online services

### Avoid If:
- Privacy-focused users uncomfortable with 10+ tracking SDKs
- Users handling large cryptocurrency assets (due to centralized wallet risks)
- Users requiring offline wallet backup options
- Users on rooted/jailbroken devices (due to unencrypted database)

---

## Recommendation: Significant Security Concerns

**Verdict:** Critical WebView vulnerability allows file access to local data, centralized wallet infrastructure, and excessive tracking SDKs. Only recommended for tech-savvy users understanding the risks; unsuitable for privacy-focused users or those holding significant assets.

### Risk Summary:
- **Security Risk:** Moderate to High (WebView vulnerability, wallet centralization)
- **Privacy Risk:** Moderate (extensive tracking, device fingerprinting)
- **Data Protection:** Moderate (unencrypted database, broad file access)

### Recommendations for Users:
1. Use only on non-rooted devices to protect local database
2. Keep small balances in the wallet due to centralized infrastructure
3. Be cautious when using mini-apps from unknown sources
4. Review and minimize granted permissions when possible
5. Keep the app updated to receive security patches

---

## Analysis Metadata

- **Version Analyzed:** 2.9.701
- **Analysis Date:** December 18, 2025
- **Classes Analyzed:** 0
- **Report Type:** Public Security Scorecard

---

*This analysis is based on static code analysis and may not reflect runtime behavior or server-side security measures. Security and privacy practices may change with app updates.*

**Powered by canITrustThat APK Security Analysis**
