The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
OWASP/mastg 的健康指数为 100 分中的 94 分,处于「卓越」区间。 其得分最高的类别是Community & Adoption(96/100),最低的是Security(63/100)。 最近一次更新在今天。 近期的大部分工作由 3 位贡献者完成。
指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均,再依据公开记录的分布进行校准,使各等级具有百分位含义;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 34(存在风险)的上限。
每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。
加权总体分 80 经校准后在公布的指数量表上为 94(记录校准 2026-08-02)。
项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?
| 36/36 | 推送新近度 — 最近一次推送于 0 天前 |
| 33.9/36 | 提交节奏 — 52 周中有 49 周有提交 |
| 18/18 | 提交量 — 最近一年 905 次提交 |
| 10/10 | OpenSSF Scorecard:Maintained — 30 commit(s) and 19 issue activity found in the last 90 days -- score normalized to 10 |
| commits_last_year | 905 |
| human_commit_share | 0.96 |
| days_since_last_push | 0 |
| active_weeks_last_year | 49 |
| 27/27 | 有发布版本 — 已发布 20 个发布版本 |
| 36/36 | 发布时效 — 最近一次发布版本于 34 天前 |
| 12.6/27 | 发布节奏 — 约每 200 天发布一次 |
| 0/10 | OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases. |
| releases_count | 20 |
| latest_release_tag | v2.0.0 |
| releases_from_tags | 否 |
| days_since_latest_release | 34 |
| mean_days_between_releases | 200 |
项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?
| 60/60 | 星标 — 13,094 个星标 |
| 25/25 | 复刻 — 2,779 个复刻 |
| 14.5/15 | 关注者 — 412 位关注者 |
| forks | 2,779 |
| stars | 13,094 |
| watchers | 412 |
| growth_state | unverified |
| growth_factor_pct | 100 |
| growth_unverified_reason | no_history |
| 22.5/22.5 | README |
| 22.5/22.5 | 许可证 — 可识别的许可证(CC-BY-SA-4.0) |
| 18/18 | CONTRIBUTING 指南 |
| 13.5/13.5 | 行为准则 |
| 0/7.2 | 议题模板 |
| 6.3/6.3 | PR 模板 |
| has_readme | 是 |
| has_license | 是 |
| readme_badges | 4 |
| has_contributing | 是 |
| has_issue_template | 否 |
| has_code_of_conduct | 是 |
| readme_badge_services | github.com, shields.io |
| has_pull_request_template | 是 |
项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?
| 36/54 | 巴士系数 — 3 位贡献者贡献了半数提交 |
| 16.3/22.5 | 提交分布 — 头号贡献者编写了 28% 的提交 |
| 13.5/13.5 | 贡献者广度 — 98 位贡献者 |
| 10/10 | OpenSSF Scorecard:Contributors — project has 13 contributing companies or organizations |
| bus_factor | 3 |
| contributors_sampled | 98 |
| top_contributor_share | 0.277 |
| 35.5/42 | 议题解决 — 84% 的议题已关闭 |
| 26.4/30 | PR 接受 — 已裁定的 PR 中 2,071/2,349 已合并 |
| 0/13 | Newcomer PR acceptance — 30 天内没有首次贡献者的 PR 得到裁决 |
| 7.5/15 | OpenSSF Scorecard:Code-Review — Found 11/22 approved changesets -- score normalized to 5 |
| merged_prs | 2,071 |
| open_issues | 188 |
| closed_issues | 1,028 |
| prs_merged_7d | 1 |
| prs_decided_7d | 1 |
| prs_merged_30d | 4 |
| prs_decided_30d | 4 |
| issue_closed_ratio | 0.845 |
| closed_unmerged_prs | 278 |
| first_time_authors_30d | 0 |
| first_time_prs_merged_30d | 0 |
| first_time_prs_decided_30d | 0 |
| 30/30 | 所有权背书 — 组织持有 |
| 0/20 | 已验证域名 — 未读取该组织的域名验证状态 |
| 25/25 | 所有者影响力 — OWASP 有 11,853 位关注者 |
| 25/25 | 既往记录 — 1,401 个公开仓库,账户约 16 年 |
| followers | 11,853 |
| owner_type | Organization |
| is_verified | — |
| owner_login | OWASP |
| public_repos | 1,401 |
| account_age_days | 6,100 |
基础的工程与文档实践是否到位?
| 24/24 | CI 工作流 — 16 个工作流 |
| 24/24 | 存在测试 |
| 0/16 | Linter 配置 |
| 0/9.6 | Pre-commit 钩子 |
| 0/6.4 | .editorconfig |
| 20/20 | OpenSSF Scorecard:CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10 |
| has_ci | 是 |
| has_tests | 是 |
| has_editorconfig | 否 |
| has_linter_config | 否 |
| has_precommit_config | 否 |
| 30/30 | README |
| 0/25 | 文档目录 |
| 15/15 | 文档 / 主页站点 — http://mas.owasp.org/ |
| 10/10 | 仓库描述 |
| 10/10 | 主题标签 — 19 个主题标签 |
| 0/10 | Wiki |
| topics | mobile-app, pentesting, android-application, ios-app, runtime-analysis, network-analysis, static-analysis, reverse-engineering, dynamic-analysis, mobile-security, android, ios, hacking, reverse-enginnering, mstg, testing-cryptography, compliancy-checklist, mast, mastg |
| has_wiki | 否 |
| homepage | http://mas.owasp.org/ |
| docs_site | http://mas.owasp.org/ |
| has_readme | 是 |
| has_docs_dir | 否 |
| has_description | 是 |
可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?
| 0/7.5 | Binary-Artifacts — binaries present in source code |
| 0/7.5 | Branch-Protection — 无数据 |
| 2.5/2.5 | CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10 |
| 0/2.5 | CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected |
| 3.8/7.5 | Code-Review — Found 11/22 approved changesets -- score normalized to 5 |
| 2.5/2.5 | Contributors — project has 13 contributing companies or organizations |
| 10/10 | Dangerous-Workflow — no dangerous workflow patterns detected |
| 7.5/7.5 | Dependency-Update-Tool — update tool detected |
| 0/5 | Fuzzing — project is not fuzzed |
| 2.5/2.5 | 许可证 — license file detected |
| 7.5/7.5 | Maintained — 30 commit(s) and 19 issue activity found in the last 90 days -- score normalized to 10 |
| 0/5 | Packaging — 无数据 |
| 0/5 | Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0 |
| 3.5/5 | SAST — SAST tool detected but not run on all commits |
| 5/5 | Security-Policy — security policy file detected |
| 0/7.5 | Signed-Releases — Project has not signed or included provenance with any releases. |
| 0/7.5 | Token-Permissions — detected GitHub workflow tokens with excessive permissions |
| 5.2/7.5 | Vulnerabilities — 3 existing vulnerabilities detected |
| source | openssf_scorecard |
| checks_evaluated | 16 |
| scorecard_version | v5.5.0 |
| checks_inconclusive | 2 |
| scorecard_aggregate | 5.4 |
| 35/35 | 直接依赖不含已知公告 — 没有直接依赖携带已知公告 |
| 0/25 | 间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分 |
| 0/40 | 没有长期未处理的公告 — 没有公告带有发布日期 |
| source | osv |
| advisories | 0 |
| affected_packages | 0 |
| assessed_packages | 8 |
| unassessed_packages | 5 |
| affected_by_severity | none |
| direct_affected_packages | 0 |
该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?权重刻意设小(4%):代理工具链是一项真实的维护信号,但完全不具备的仓库仍可达到 100/100。
| 45/45 | 代理指令 — .github/instructions/index.md, .github/instructions/markdown.instructions.md, .github/instructions/mastg-apps.instructions.md, .github/instructions/mastg-best-practice.instructions.md, .github/instructions/mastg-demo.instructions.md, .github/instructions/mastg-frida-scripts.instructions.md, .github/instructions/mastg-frooky-hooks.instructions.md, .github/instructions/mastg-knowledge.instructions.md, .github/instructions/mastg-mitmproxy-scripts.instructions.md, .github/instructions/mastg-r2-scripts.instructions.md, .github/instructions/mastg-rules.instructions.md, .github/instructions/mastg-techniques.instructions.md, .github/instructions/mastg-test.instructions.md, .github/instructions/mastg-tools.instructions.md, .github/instructions/porting-mastg-v1-tests-to-v2.instructions.md |
| 0/15 | 机器可读文档(llms.txt) |
| 40/40 | 可读的提交历史 — 96 次人类提交中有 94 次说明了意图(结构化标题或解释性正文) |
| has_llms_txt | 否 |
| llms_txt_url | — |
| legible_history_share | 0.979 |
| agent_instruction_files | .github/instructions/index.md, .github/instructions/markdown.instructions.md, .github/instructions/mastg-apps.instructions.md, .github/instructions/mastg-best-practice.instructions.md, .github/instructions/mastg-demo.instructions.md, .github/instructions/mastg-frida-scripts.instructions.md, .github/instructions/mastg-frooky-hooks.instructions.md, .github/instructions/mastg-knowledge.instructions.md, .github/instructions/mastg-mitmproxy-scripts.instructions.md, .github/instructions/mastg-r2-scripts.instructions.md, .github/instructions/mastg-rules.instructions.md, .github/instructions/mastg-techniques.instructions.md, .github/instructions/mastg-test.instructions.md, .github/instructions/mastg-tools.instructions.md, .github/instructions/porting-mastg-v1-tests-to-v2.instructions.md |
| agent_instruction_max_bytes | 33,844 |
| 12.6/18 | 一条命令的引导启动 — demos/android/MASVS-CODE/MASTG-DEMO-0050/build.gradle.kts(工具链约定,无任务运行器) |
| 22/22 | 自动化测试 |
| 0/11 | Lint / 格式化配置 |
| 0/11 | 静态类型检查 |
| 0/10 | 可复现环境 |
| 10/10 | 已体现的代理实践 — 最近 100 次提交中有 35 次由代理编写或署名代理 |
| 8/8 | 自动化维护 — 最近 100 次提交中有 4 次为自动依赖更新 |
| 0/10 | OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0 |
| has_nix | 否 |
| has_tests | 是 |
| lockfiles | — |
| has_dockerfile | 否 |
| typed_language | 否 |
| bootstrap_files | — |
| has_devcontainer | 否 |
| has_linter_config | 否 |
| typecheck_configs | — |
| agent_commit_share | 0.35 |
| toolchain_manifests | demos/android/MASVS-CODE/MASTG-DEMO-0050/build.gradle.kts |
| dependency_bot_commit_share | 0.04 |
| 0/45 | 可类型检查的代码 — Python,未配置类型检查 |
| 55/55 | 可控的文件大小 — 采样的 220 个源文件中有 0 个超过 60KB |
| primary_language | Python |
| largest_source_bytes | 20,255 |
| source_files_sampled | 220 |
| oversized_source_files | 0 |
| 0/40 | API 模式(OpenAPI/GraphQL/proto) — 不适用于此类软件 |
| 0/20 | MCP 服务器 — 不适用于此类软件 |
| 40/40 | 可运行示例 — demos, samples |
| example_dirs | demos, samples |
| has_mcp_signal | 否 |
| api_schema_files | — |
| interfaces_expected_of | — |
每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。
仅显示最近的历史——该仓库超出采集窗口,因此未采集最早的历史记录。
每个点涵盖 4 天。
来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。
| 0 | Binary-Artifacts | binaries present in source code |
| 不适用 | Branch-Protection | internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md |
| 10 | CI-Tests | 30 out of 30 merged PRs checked by a CI test -- score normalized to 10 |
| 0 | CII-Best-Practices | no effort to earn an OpenSSF best practices badge detected |
| 5 | Code-Review | Found 11/22 approved changesets -- score normalized to 5 |
| 10 | Contributors | project has 13 contributing companies or organizations |
| 10 | Dangerous-Workflow | no dangerous workflow patterns detected |
| 10 | Dependency-Update-Tool | update tool detected |
| 0 | Fuzzing | project is not fuzzed |
| 10 | License | license file detected |
| 10 | Maintained | 30 commit(s) and 19 issue activity found in the last 90 days -- score normalized to 10 |
| 不适用 | Packaging | packaging workflow not detected |
| 0 | Pinned-Dependencies | dependency not pinned by hash detected -- score normalized to 0 |
| 7 | SAST | SAST tool detected but not run on all commits |
| 10 | Security-Policy | security policy file detected |
| 0 | Signed-Releases | Project has not signed or included provenance with any releases. |
| 0 | Token-Permissions | detected GitHub workflow tokens with excessive permissions |
| 7 | Vulnerabilities | 3 existing vulnerabilities detected |
来自 GitHub 依赖图的完整解析依赖集合:0 个直接依赖与 13 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。
| 注册表 | 软件包 | 版本 | 关系 |
|---|---|---|---|
| PyPI | bs4 | 0.0.2 | 间接 |
| PyPI | frida | — | 间接 |
| PyPI | frida-tools | — | 间接 |
| PyPI | frooky | — | 间接 |
| PyPI | lxml | 6.1.0 | 间接 |
| PyPI | openpyxl | 3.1.5 | 间接 |
| PyPI | pandas | 2.3.0 | 间接 |
| PyPI | pillow | 12.3.0 | 间接 |
| PyPI | pyyaml | 6.0.2 | 间接 |
| PyPI | r2pipe | — | 间接 |
| PyPI | requests | 2.33.0 | 间接 |
| PyPI | semgrep | — | 间接 |
| PyPI | tabulate | 0.9.0 | 间接 |
该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 8 个包,其中也包含从不交付的开发与测试版本固定:0 个存在已知公告,0 个为直接依赖。 有 5 个无法评估——没有已解析的版本、生态系统不受支持,或不在所列包清单之内。
没有已知公告影响已评估的依赖。
公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。
发现这份报告有不准确之处,或有想法要分享?错误的测量、未识别的工具、建议、疑问——都欢迎提出。每条消息都会被阅读并得到回复。