Google Play Store
Google Play Store is the default Android app distribution channel, so its bytecode carries more system-level capability than almost anything else on the device. 6 scans across 5 devices find 2 verified trackers: Google AdMob (Ads) and Google Maps (Location). AdMob in the store that sells apps is a detail worth noting - it is present in the bytecode whether or not ad placements are visible to every user. Google Maps is consistent with in-app location features such as region-based content. The permission list is long and reflects the app's privileged system role.
Read from the bytecode.
Static analysis shows code present in the package - not confirmed runtime behavior. That said: INSTALL_PACKAGES and DELETE_PACKAGES are extraordinary permissions that no third-party app can hold; they reflect Play Store's unique system role. READ_SMS and SEND_SMS are harder to explain for an app store and are worth knowing about. ACCESS_ADSERVICES_AD_ID paired with AdMob code means the infrastructure for ad-ID-based targeting is in the binary. Whether Google activates it for every user is a runtime question this scan cannot answer.
This is static analysis of the APK bytecode installed on real devices: it proves which SDK classes and manifest permissions ship in the app, not what the app transmits at runtime. Traffic analysis is a different measurement.
Hidden inside the code.
What it asks for.
Allows installing APKs silently - a system-level capability reserved for app stores and device management tools. Expected here, but powerful.
Allows uninstalling apps without user confirmation dialogs. System-role permission consistent with an app store, but notable in scope.
Access to all SMS messages on the device. Not an obvious requirement for an app store; no clear feature mapping is apparent from the category.
Can send SMS messages. Combined with READ_SMS and SEND_SMS_NO_CONFIRMATION, this is a notable set of messaging capabilities for an app distribution platform.
Declares access to the Android advertising ID. Paired with the AdMob SDK found in the bytecode, this is the standard setup for ad-ID-based targeting infrastructure.
Grants visibility into every installed app on the device. Expected for an app store managing installs and updates, but grants a broad inventory of user software.
Keep reading.
How to Check If an Android App Is Safe Before Installing
Before you install any Android app, here is how to check if it is safe: permissions, trackers, developer reputation, and...
What is a tracker in an app, and why should you care
A tracker is third-party code the developer bundled in. It reads device IDs, coarse location and your app list, with no ...
Similar risk profiles.
Scan Google Play Store yourself.
Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.