Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

MobSF

Free#13 of 26 in SAST ToolsStatic Application Security Testing Sast

Open-source mobile application security testing framework

6.2/10Editor score
MobSF6.2 Visit MobSF

At a glance

  • Editor score
    6.2 / 10
  • Pricing
    Free plan
  • Best for
    Mobile application security teams
  • Free plan
    Yes
  • Paid from
    None
  • Pull request scans
    Yes
  • Facts checked
    15 Sep 2026
  • Where it wins

    • Static analysis covers Android, iOS, Windows packages, and source code.
    • Dynamic analysis includes Android, iOS, runtime data, and network traffic.
    • REST API, CLI, Docker, reports, and CI/CD examples support automation.
  • Where it doesn't

    • Dynamic analysis is focused on Android and iOS applications.
    • No AI features are included.
    • Support and training are separate packages, not software subscription tiers.

Our verdict on MobSF

MobSF is an open-source security research platform for teams assessing Android, iOS, and Windows applications. It combines static analysis of source code and binaries with dynamic analysis for Android and iOS, making it suitable for mobile application security teams, penetration testers, malware analysts, and privacy-focused review workflows. Source scanning covers Java, Kotlin, Android XML, Info.plist, Swift, and Objective-C. The platform also supports runtime inspection, network traffic analysis, REST API and CLI workflows, and pull request scans.

MobSF fits development and security pipelines through GitHub Actions, GitLab CI/CD, Travis CI, CircleCI, and Bitrise examples. Docker-based deployment supports self-hosted operation across web, Windows, macOS, and Linux environments, while API access supports automated workflows. Reports can be produced in JSON, SARIF, GitLab SAST, SonarQube, and HTML formats, with rule severity overrides and finding suppression for workflow control. SonarQube, SonarCloud, and Docker are also listed among its integrations. Teams seeking a security tool that spans source code, app packages, dynamic mobile analysis, and CI outputs will find the scope well aligned.

MobSF itself is available as open-source software with a free plan. OpenSecurity also publishes separate annual packages: Professional Support adds live troubleshooting, priority email or Slack support, e-learning for 5 accounts, one minor feature request, and priority bug fixes; Enterprise Support adds e-learning for 15 accounts and two major feature requests; Training includes live onsite or online training, CTF challenges, CI/CD setup assistance, e-learning for 50 accounts, and expert email consultation. Choose MobSF for broad mobile security coverage and self-hosted automation. Teams needing dynamic analysis for Windows applications, AI features, or a narrower commercial subscription model should consider alternatives.

MobSF pricing

Plans Free planFree Free to use — no paid tier required for the core job.
See plans on github.com

All 3 MobSF plans and prices →

MobSF fact sheet

Free planYes
Paid fromNone
Analysis targetssource code, binaries
Languages supportedNot verified
Pull request scansYes
IDE supportNot verified
CI/CD integrationYes
Custom security rulesNot verified
Automated fixesNot verified
DeploymentCloud, Desktop, Self-hosted
PlatformsWeb, Windows, macOS, Linux
Integrations8 integrations: GitHub Actions, GitLab CI/CD, SonarQube, SonarCloud, Travis CI, CircleCI …
PricingFree plan (source)
Websitegithub.com
Facts checked15 Sep 2026

MobSF integrations

MobSF lists 8 integrations on its own site.

  • GitHub Actions
  • GitLab CI/CD
  • SonarQube
  • SonarCloud
  • Travis CI
  • CircleCI
  • Bitrise
  • Docker

Alternatives to MobSF

See all MobSF alternatives →

Also listed in

Used MobSF? Be the first to review it

The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used MobSF for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.

Write a reviewTwo minutes · verified accounts only · read by an editor before it appears

Reviews come only from verified accounts. Sign in or create an account first — your e-mail is never shown.

Your rating

0 characters · at least 80, up to 3,000

Posted from your verified account. Reviews appear after an editor reads them, usually within two working days.

Featured on iTechGuides

Featured on iTechGuides — MobSF 6.2/10

MobSF is listed in our SAST Tools directory. Add the badge to your site — it links back to this page.

<a href="https://www.itechguides.com/products/mobsf/"><img src="https://www.itechguides.com/best/badge/mobsf.svg" alt="Featured on iTechGuides" width="230" height="46"></a>

Reviewed by iTechGuides Editors · Editorial team · Updated Sep 2026

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. It never changes a score or a verdict. How we rank.