mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.
active 2023-08-19 → 2026-08-10 (UTC)
Activity over time
Daily event counts in the loaded window
Line chart, 1088 days from 2023-08-19 to 2026-08-10. Pushes: 38 total, peak 5 in a day. Pull requests: 45 total, peak 6 in a day. Issues: 30 total, peak 3 in a day. Comments: 66 total, peak 7 in a day. Stars: 257 total, peak 4 in a day.
- Pushes
- Pull requests
- Issues
- Comments
- Stars
Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.
Top contributors
Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity
| Contributor | Contributions | Pushes | PRs | Comments |
|---|---|---|---|---|
| ajinabraham | 129 | 38 | 39 | 32 |
| github-advanced-security[bot] | 10 | 0 | 0 | 7 |
| ls-valentinas-bakaitis | 5 | 0 | 1 | 4 |
| yanz-safe | 5 | 0 | 1 | 2 |
| vpuonti | 3 | 0 | 0 | 2 |
| olaf-a | 3 | 0 | 0 | 2 |
| valentinas | 3 | 0 | 0 | 2 |
| nitinNayar | 3 | 0 | 1 | 1 |
| Heckfer | 2 | 0 | 0 | 1 |
| madlymad | 2 | 0 | 0 | 1 |
| mattmook | 2 | 0 | 1 | 0 |
| maen08 | 2 | 0 | 1 | 1 |
| vasconcedu | 2 | 0 | 0 | 1 |
| sebasrevuelta | 2 | 0 | 0 | 1 |
| emersonramos | 1 | 0 | 0 | 0 |
| joost-klitsie | 1 | 0 | 0 | 1 |
| auroragorisavellini | 1 | 0 | 0 | 0 |
| YuriBanyuwang1 | 1 | 0 | 0 | 0 |
| jvictors-tp | 1 | 0 | 0 | 1 |
| abhinavsejpal-mns | 1 | 0 | 0 | 1 |
Recent activity
Latest issues, pull requests and releases
- Issue#68ajinabraham2026-08-10 05:31Imported: semgrep android rules
- Pull request#117ajinabraham2026-03-12 21:46
- Pull request#113OhMyApp2026-01-26 22:57
- Issue comment#111jvictors-tp2025-11-20 17:36ios_hardcoded_secret produces too many false positives
- Issue#110auroragorisavellini2025-07-18 15:02SDK
- Issue comment#88vasconcedu2025-03-25 07:48False negatives: hardcoded secrets
- Issue comment#105yanz-safe2025-03-10 04:41Ensure multiple suppressions work as expected
- Issue#107yanz-safe2025-02-03 07:01`mobsf-ignore` comment does not work in .swift files
- Pull request#106ajinabraham2025-01-31 23:23
- Pull request#106ajinabraham2025-01-31 23:23
- Issue comment#104ajinabraham2025-01-24 01:02Multiple suppressions on the same rule_id only removes one instance
- Pull request#105mattmook2025-01-03 14:35
- Issue#104mattmook2025-01-03 14:25Multiple suppressions on the same rule_id only removes one instance
- Pull request#100ajinabraham2024-11-16 03:58
- Issue comment#99ajinabraham2024-11-15 01:46Scanning with 0.4.2 fails on Azure Pipelines due to dependency failure
- Issue comment#98ajinabraham2024-11-15 01:46I scan the others as normal But this folder will have error
- Issue comment#99vpuonti2024-11-14 20:35Scanning with 0.4.2 fails on Azure Pipelines due to dependency failure
- Issue comment#99ajinabraham2024-11-14 20:23Scanning with 0.4.2 fails on Azure Pipelines due to dependency failure
- Issue comment#99vpuonti2024-11-14 20:19Scanning with 0.4.2 fails on Azure Pipelines due to dependency failure
- Pull request#103ajinabraham2024-11-14 20:17
- Pull request#103ajinabraham2024-11-14 20:07
- Releaseajinabraham2024-11-14 17:310.4.4
- Pull request#102ajinabraham2024-11-14 17:27
- Pull request#102ajinabraham2024-11-14 17:21
- Releaseajinabraham2024-11-14 09:000.4.3
Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 257 stars here means stars gained during the window, not the repo's star count.