Aurora Store
Aurora Store is an open-source Google Play front-end built around privacy - so finding 1 verified tracker (Meta SDK) in 4 scans across 4 devices is the headline. The SDK category is listed as unknown, which makes it harder to assess the exact surface area, but Meta SDK code is present in the bytecode regardless of category label. Permissions tell a coherent story for an app installer: REQUEST_INSTALL_PACKAGES, REQUEST_DELETE_PACKAGES, QUERY_ALL_PACKAGES, and MANAGE_EXTERNAL_STORAGE all map to core install/update workflows. RECEIVE_BOOT_COMPLETED supports background update checks.
Read from the bytecode.
Aurora Store markets itself as a privacy-respecting alternative to the Play Store, so the presence of Meta SDK code is worth a closer look. Static analysis confirms the code is shipped - it does not confirm whether it is initialized or transmits anything at runtime. The unknown SDK category means there is no clean label (analytics, advertising, login) to anchor the assessment. If you use Aurora Store specifically to reduce Google and Meta exposure, the presence of this SDK is a data point your threat model should weigh. The installer permissions (INSTALL, DELETE, QUERY_ALL_PACKAGES) are functionally necessary and expected for this app type.
This is static analysis of the APK bytecode installed on real devices: it proves which SDK classes and manifest permissions ship in the app, not what the app transmits at runtime. Traffic analysis is a different measurement.
Hidden inside the code.
What it asks for.
Lets the app enumerate every installed package on the device. Expected for a store client that needs to detect installed apps and available updates.
Required to sideload APKs outside of the system installer dialog. Core to Aurora Store's purpose; expected here.
Allows the app to trigger uninstall flows programmatically. Expected for a full-featured store replacement.
Grants broad read/write access to all external storage, beyond what READ/WRITE_EXTERNAL_STORAGE cover. Used here for APK download staging; broader than typical app needs.
Allows the app to bypass Doze mode and run background tasks unrestricted. Useful for background update checks, but grants persistent background execution.
Starts a component automatically after device boot. Expected for an app store handling background update scheduling.
Keep reading.
How to Check If an Android App Is Safe Before Installing
Before you install any Android app, here is how to check if it is safe: permissions, trackers, developer reputation, and...
What is a tracker in an app, and why should you care
A tracker is third-party code the developer bundled in. It reads device IDs, coarse location and your app list, with no ...
Similar risk profiles.
Scan Aurora Store yourself.
Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.