AppXpose AppXpose
← All scans
MEDIUM Risk · Score 39/100

WhatsApp

com.whatsapp

WhatsApp is a widely-used messaging app with end-to-end encrypted conversations and calls, significantly reducing content-level privacy risks. However, Meta's ownership enables substantial metadata collection (contacts, location, call patterns, device identifiers), and the app requests 10 dangerous permissions with all granted. The combination of metadata harvesting and Meta's ad-targeting ecosystem places it in the MEDIUM risk category - acceptable for most users but with notable privacy trade-offs.

39
out of 100
5
Trackers Found
4
Dangerous Permissions
8
Risk Factors
0
Known Breaches
Score Breakdown

+7
Unexpected Dangerous Permissions

10 dangerous permissions including location, contacts, SMS, phone state

+12
Metadata Collection by Meta

Phone number, contacts, call metadata, location, device IDs, connection patterns

+8
Verified Trackers: 5 SDKs

Firebase Analytics, Meta SDK, FCM, Google Sign-In, Google Maps

-10
End-to-End Encryption (E2EE)

Signal Protocol E2E for all messages, calls, groups, and status updates

+9
Meta Ownership & Data Sharing

Metadata integrated into Meta ad network for cross-platform profiling

-4
Active Development

Frequent security updates, no known unpatched vulnerabilities

+5
Known Privacy Incidents

GDPR fines, investigations in EU, India, UK over metadata practices

+4
Location Sharing Feature

Real-time location sharing with Google Maps integration

Trackers

5 SDKs detected

Hidden inside the code.

Google Firebase Analytics Analytics
Meta SDK Advertising
Firebase Cloud Messaging Push
Google Sign-In Social
Google Maps Location
Permissions

4 flagged

What it asks for.

high
ACCESS_FINE_LOCATION

Precise GPS for location sharing features

medium
READ_PHONE_STATE

Reads phone number and device identifiers

high
RECEIVE_SMS

Can intercept incoming SMS messages

high
SEND_SMS

Can send SMS without user interaction

Evidence

From the scan.

WhatsApp scan  - AI summary and risk breakdown showing E2E encryption offset
AI summary and risk breakdown showing E2E encryption offset
WhatsApp scan  - Extensive data collection: contacts, call metadata, usage patterns
Extensive data collection: contacts, call metadata, usage patterns

Scan WhatsApp yourself.

Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.