Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

This page's audience real numbers from our own analytics — open to see them
–Visitors
–Page views
–Clicks to vendors
–Time on page
–Reading now
Clicks to vendors, by tool
  • –
Top countries
  • –
Devices
  • –

– · counted by iTechGuides's own first-party analytics, bots removed, every figure rounded down · how we count

SEBASTiAn

Free#16 of 21 in Mobile Application Security Testing Software

SEBASTiAn: A focused open-source SAST tool for APK and IPA analysis with unified reporting. Ranked #16 of 21 in Mobile Application Security Testing Software by our editors (7.6/10); pricing: Open source; best for open-source teams needing cross-platform SAST.

7.6/10Editor score
SEBASTiAn7.6 Visit SEBASTiAn

At a glance

  • Editor score
    7.6 / 10
  • Pricing
    Open source
  • Best for
    Open-source teams needing cross-platform SAST
  • Paid from
    None
  • Mobile platforms
    Both
  • Facts checked
    20 Sep 2026
SEBASTiAn screenshot
  • Where it wins

    • Analyzes Android APK and iOS IPA files in one workflow
    • Unified JSON reports include findings, locations, and remediation guidance
    • Docker execution and configurable analysis support repeatable workflows
  • Where it doesn't

    • Static-only coverage does not include dynamic analysis
    • Commercial or closed-source use requires a commercial license
    • No verified integrations are described

Our verdict on SEBASTiAn

SEBASTiAn is an open-source, platform-agnostic tool for static security assessment of mobile applications. It analyzes Android APK files and iOS IPA files, making it a fit for teams that need one workflow across both mobile platforms. The project runs on Windows, macOS, and Linux, and can be executed from source or through Docker. Its self-hosted deployment model suits teams that want to keep analysis within their own environment.

The strongest part of SEBASTiAn is its unified reporting model. JSON reports bring detected vulnerabilities, vulnerable code or configuration locations, remediation suggestions, and further-reading resources together in a consistent output. The checks cover mobile configuration, cryptography, permissions, networking, WebView behavior, binary protections, and related security issues. Teams can also exclude Android third-party libraries, set an analysis timeout, use fail-fast mode, and produce vulnerability output in English or Italian. These controls give the tool a focused place in automated or repeatable static analysis workflows.

SEBASTiAn’s scope is deliberately narrower than a full mobile application security program. It provides static analysis, but not dynamic analysis, so teams seeking runtime testing need another capability alongside it. Its open-source licensing also matters: the project is available under AGPL for open-source projects, while commercial or closed-source use requires a commercial license. Choose SEBASTiAn when cross-platform APK and IPA SAST, Docker execution, and structured JSON findings are the priority. Choose a broader mobile security tool when dynamic testing or established integrations are central requirements.

SEBASTiAn pricing

Plans Open sourceFree Free to use — no paid tier required for the core job.
See plans on github.com

SEBASTiAn fact sheet

Free planNot verified
Paid fromNone
Mobile platformsBoth
Static binary analysisYes
Dynamic app analysisNo
Sensitive-data flowNot verified
Deployment modelSelf_hosted
Included appsNot verified
DeploymentSelf-hosted
PlatformsWindows, macOS, Linux
SupportCommunity, Docs
Built forSolo, Small business, Mid-market, Enterprise (editorial estimate)
PricingOpen source
Websitegithub.com
Facts checked20 Sep 2026

Alternatives to SEBASTiAn

See all SEBASTiAn alternatives →

Used SEBASTiAn? Be the first to review it

The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used SEBASTiAn for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.

Write a reviewTwo minutes · verified accounts only · read by an editor before it appears

Reviews come only from verified accounts. Sign in or create an account first — your e-mail is never shown.

Your rating

0 characters · at least 80, up to 3,000

Posted from your verified account. Reviews appear after an editor reads them, usually within two working days.

Featured on iTechGuides

Featured on iTechGuides — SEBASTiAn 7.6/10

SEBASTiAn is listed in our Mobile Application Security Testing Software directory. Add the badge to your site — it links back to this page.

<a href="https://www.itechguides.com/products/sebastian/"><img src="https://www.itechguides.com/best/badge/sebastian.svg" alt="Featured on iTechGuides" width="230" height="46"></a>

Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026

Advertiser disclosure: iTechGuides is reader-supported. Vendors can pay for top positions in our rankings and for a place on other products' pages, and we may earn a commission when you click some links. How we rank.

Last updated · How we research and update