Skip to content

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.

active 2023-08-192026-08-10 (UTC)

Complete coverage26,585 / 26,585 hourly files (100%) · 2 absent upstream2023-08-152026-08-26 (UTC)
Events
545
Pushes
38
Pull requests
45
Issues
30
Stars
257
Forks
41

Activity over time

Daily event counts in the loaded window

Line chart, 1088 days from 2023-08-19 to 2026-08-10. Pushes: 38 total, peak 5 in a day. Pull requests: 45 total, peak 6 in a day. Issues: 30 total, peak 3 in a day. Comments: 66 total, peak 7 in a day. Stars: 257 total, peak 4 in a day.

  • Pushes
  • Pull requests
  • Issues
  • Comments
  • Stars

Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.

Top contributors

Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity

Recent activity

Latest issues, pull requests and releases

  • Issue#68ajinabraham2026-08-10 05:31
    Imported: semgrep android rules
  • Pull request#117ajinabraham2026-03-12 21:46
  • Pull request#113OhMyApp2026-01-26 22:57
  • Issue comment#111jvictors-tp2025-11-20 17:36
    ios_hardcoded_secret produces too many false positives
  • Issue#110auroragorisavellini2025-07-18 15:02
    SDK
  • Issue comment#88vasconcedu2025-03-25 07:48
    False negatives: hardcoded secrets
  • Issue comment#105yanz-safe2025-03-10 04:41
    Ensure multiple suppressions work as expected
  • Issue#107yanz-safe2025-02-03 07:01
    `mobsf-ignore` comment does not work in .swift files
  • Pull request#106ajinabraham2025-01-31 23:23
  • Pull request#106ajinabraham2025-01-31 23:23
  • Issue comment#104ajinabraham2025-01-24 01:02
    Multiple suppressions on the same rule_id only removes one instance
  • Pull request#105mattmook2025-01-03 14:35
  • Issue#104mattmook2025-01-03 14:25
    Multiple suppressions on the same rule_id only removes one instance
  • Pull request#100ajinabraham2024-11-16 03:58
  • Issue comment#99ajinabraham2024-11-15 01:46
    Scanning with 0.4.2 fails on Azure Pipelines due to dependency failure
  • Issue comment#98ajinabraham2024-11-15 01:46
    I scan the others as normal But this folder will have error
  • Issue comment#99vpuonti2024-11-14 20:35
    Scanning with 0.4.2 fails on Azure Pipelines due to dependency failure
  • Issue comment#99ajinabraham2024-11-14 20:23
    Scanning with 0.4.2 fails on Azure Pipelines due to dependency failure
  • Issue comment#99vpuonti2024-11-14 20:19
    Scanning with 0.4.2 fails on Azure Pipelines due to dependency failure
  • Pull request#103ajinabraham2024-11-14 20:17
  • Pull request#103ajinabraham2024-11-14 20:07
  • Releaseajinabraham2024-11-14 17:31
    0.4.4
  • Pull request#102ajinabraham2024-11-14 17:27
  • Pull request#102ajinabraham2024-11-14 17:21
  • Releaseajinabraham2024-11-14 09:00
    0.4.3

Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 257 stars here means stars gained during the window, not the repo's star count.