AppXpose AppXpose
← All scans
MEDIUM Risk · Score 42/100

AliExpress

com.alibaba.aliexpresshd

AliExpress is a legitimate e-commerce platform owned by Alibaba Group with extensive data collection typical of major Chinese e-commerce apps. Operates under Chinese data protection frameworks with limited GDPR transparency. Data sharing with thousands of third-party vendors increases privacy exposure.

42
out of 100
5
Trackers Found
0
Dangerous Permissions
10
Risk Factors
0
Known Breaches
Warning

Regulatory & Legal

2022 delayed response to GDPR data subject access requests from EU users. 2023 reports of account takeovers via credential stuffing (Alibaba implemented mandatory 2FA).

Score Breakdown

+12
Trackers and analytics SDKs

Google Analytics, Firebase, AppsFlyer, AdMob, and Alibaba proprietary analytics

+11
Chinese jurisdiction and data governance

Alibaba operates under Chinese law; data may be subject to government access requests

+10
Data collection scope

Payment data, shipping addresses, browsing history, search queries, device identifiers

+8
Cross-border payment processing

International transactions through multiple payment gateways increase exposure

+8
Third-party vendor data sharing

Thousands of sellers access buyer data for fulfillment and marketing

+7
Privacy policy transparency

Lengthy, generic policy; unclear on data retention and third-party recipients

+5
No E2E for communications

Buyer-seller messaging is server-side encrypted only

-8
No dangerous permissions

Zero dangerous permissions - reduces immediate exploitation risk

-6
Developer reputation and scale

Fortune 500 company with security practices, updates, and bug bounty

-5
Regular security updates

Active development with frequent patches

Trackers

5 SDKs detected

Hidden inside the code.

Google Analytics Analytics
Firebase Analytics Analytics
AppsFlyer Attribution
Google AdMob Advertising
Alibaba Analytics Analytics

Scan AliExpress yourself.

Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.