WASViking Mobile Security Assessment review
Deep static MASVS coverage for teams building repeatable mobile security evidence.
Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026
WASViking Mobile Security Assessment analyzes Android APK and AAB packages alongside iOS IPA packages before release. It is designed for security and engineering teams that need repeatable static assessment, compliance-oriented evidence, and findings that can feed a broader cloud-based application security workflow. Coverage maps to OWASP MASVS and MASTG, with checks spanning configuration, transport security, cryptography, storage, platform exposure, binary hardening, third-party components, and embedded secrets.
Its strongest differentiator is the breadth of its static assessment. More than 200 checks are distributed across MASVS groups, while third-party component inventory and CycloneDX SBOM generation support software composition visibility. Release-to-release finding comparison helps teams track changes over time, and SARIF and JSON outputs provide formats suited to CI/CD pipelines. The published plan structure also extends beyond scanning: Pro adds a Sentinel internal scanning agent, CI/CD security automation, and Slack, Microsoft Teams, and webhook integrations; Business adds compliance mapping, signed compliance evidence, and a dedicated customer success manager; Enterprise adds private and on-premises deployment, custom volume and unlimited scanning, and a dedicated support team.
WASViking fits organizations focused on static mobile application security across both major mobile platforms, especially where MASVS-aligned evidence and pipeline outputs matter. Starter supports up to five targets and continuous vulnerability scanning, while Jira is listed among the integrations. Mobile Security Assessment is available as an add-on across the Starter, Pro, Business, and Enterprise plans, and pricing is handled through contact sales. Teams needing dynamic analysis should choose a product with that capability, since this offering centers on static package assessment rather than runtime testing.
WASViking Mobile Security Assessment pros and cons
- Where it wins
- More than 200 checks across OWASP MASVS groups
- Android and iOS package analysis with CycloneDX SBOMs
- SARIF, JSON, integrations and release comparison for CI/CD
- Where it doesn't
- Static analysis only; dynamic analysis is not included
- Mobile Security Assessment is an add-on across all plans
- Pricing requires contacting sales
WASViking Mobile Security Assessment fact sheet, pricing and score →
Advertiser disclosure: iTechGuides is reader-supported. Vendors can pay for top positions in our rankings and for a place on other products' pages, and we may earn a commission when you click some links. How we rank.
Last updated · How we research and update