Plugin Architecture Implementation for Mobile Apps
A retailer recently approached us: their enterprise app needed to support dozens of modules — inventory management, CRM, analytics. Each module was updated by different teams at different times, but the monolithic architecture required monthly full-app releases even when changing a single module. As a result, time-to-market for new features was 4–6 weeks, and every update risked breaking other modules. The client needed to isolate development and accelerate delivery.
We proposed a plugin architecture: we extracted the core (authentication, navigation, common UI) and turned modules into independent plugins. Now teams update their plugins without waiting for a full release. The project assessment took 2 days — you can get a similar turnkey solution. Average savings on releases in such projects is €10,000–€25,000 per year.
Plugin architecture is a step beyond modular architecture. In modular architecture, all modules are known at compile time and are built into a single binary. Plugin architecture assumes parts of the app can be added, replaced, or updated independently of the main application — sometimes at runtime. This cuts time-to-market for new modules by 3–5x compared to monolithic updates.
Plugin architecture is justified for platform apps with partner extensions, super apps where mini-programs are plugins, enterprise MDM systems where client companies add their own modules. For standard apps without external extensions, it's overkill — it complicates development and debugging.
How It Works on Android
On Android, dynamic code loading is a reality via DexClassLoader. A plugin is an APK or DEX file loaded at runtime:
val pluginApkPath = File(context.filesDir, "plugin-v2.apk").absolutePath
val classLoader = DexClassLoader(
pluginApkPath,
context.codeCacheDir.absolutePath,
null,
context.classLoader
)
val pluginClass = classLoader.loadClass("com.plugin.FeatureImpl")
val plugin = pluginClass.getDeclaredConstructor().newInstance() as PluginContract
plugin.initialize(pluginContext)
PluginContract is an interface that the plugin implements. The main app knows only the interface, not the implementation. The plugin is downloaded from a server, verified by digital signature (JarVerifier or custom SHA-256 verification), placed in filesDir, and loaded.
Google Play Integrity API — to verify the downloaded plugin wasn't tampered with. IntegrityManager.requestIntegrityToken() before loading the plugin confirms the request's integrity.
Limitation: The App Store (iOS) prohibits dynamic loading of executable code — guideline 2.5.2. On iOS, plugin architecture means either compile-time plugins (all known at build time, connected via protocols) or interpreted content (JavaScript via JavaScriptCore, Lua, WebAssembly) — this is not native code and doesn't violate rules.
Why Plugin Architecture Is More Profitable Than a Monolith
Plugin architecture reduces time-to-market for new modules by 3–5x compared to monolithic updates. For example, in our retailer case, the time from a new module request to activation dropped from 4 weeks to 3 days. Additionally, plugin architecture isolates errors: a bug in one plugin doesn't crash the entire app. ROI for such architecture is 6–12 months for an average enterprise project. Savings on releases — from €15,000 per year for a team of 5 developers.
How to Ensure Plugin Security
Security is key in dynamic code loading. On Android, we apply:
- Digital signature verification of each plugin (SHA-256 + JarVerifier).
- Integrity check via Google Play Integrity API before loading.
- Loading only from protected storage (
filesDir).
On iOS, interpreted plugins (JS, WASM) run in a sandbox (JavaScriptCore or WKWebView), limiting access to native API. We also use static code analysis of plugins before adding them to the marketplace.
iOS: Plugins via Protocols and JavaScriptCore
On iOS, a "plugin" in the sense of dynamically loaded code is impossible without jailbreak. But plugin architecture can be implemented via:
-
Protocol-based compile-time plugins. Each plugin is a Swift Package implementing PluginProtocol. The app compiles with all plugins but activates the needed ones via config. Plugins are isolated through modules, access to host API only via protocol.
-
JavaScriptCore as runtime. The plugin is a JavaScript file downloaded from a server and executed via JSContext. The host registers native functions as JS objects: context["nativeAPI"] = nativeAPI as AnyObject. Execution speed is acceptable for business logic, unacceptable for rendering. This is how mini-programs work in WeChat and some super apps.
-
WebAssembly. Since iOS 14+, WKWebView executes WASM via the JavaScript engine. The plugin is compiled into WASM (from C++, Rust, AssemblyScript) and runs in an isolated environment. Interaction with native code is via WASM imports/exports.
Plugin Versioning and Compatibility
The hardest part of plugin architecture is not code loading but compatibility management. App v2.5 must run a plugin written for v2.0 API and not crash on a v2.6 plugin that expects a non-existent API.
The solution is explicit contract versioning. PluginContract has minHostVersion and targetHostVersion. When loading a plugin, the host checks compatibility before initialize(). Deprecated API versions are marked @Deprecated and supported for two major versions.
Case study. Enterprise super app for retail: main app — authentication, navigation, common UI. Plugins — StockPlugin (inventory), CRMPlugin (customer management), AnalyticsPlugin (dashboards). Each plugin is developed by a separate team, loaded via MDM on first launch by employees. Android: DexClassLoader with signature verification. iOS: compile-time plugins via local SPM packages, activation via feature flags. Plugin update — without updating the main app in Google Play (via own distribution server for corporate devices).
Comparison: Compile-time vs Runtime Plugin Architecture
| Parameter |
Compile-time plugins |
Runtime plugins (Android) |
| Loading |
At compile time |
At runtime via DexClassLoader |
| Update flexibility |
Requires app release |
Without updating main app |
| Security |
High (code in binary) |
Requires signature verification |
| Performance |
No overhead |
Overhead for class loading |
| iOS support |
Fully (Apple allows) |
Impossible (violates guideline) |
What's Included
- Architectural documentation (diagrams, contract descriptions, plugin API).
- Core code for iOS and Android (loading, versioning, security support).
- Example plugin (template) to start development.
- CI/CD pipelines for building and verifying plugins.
- Documentation for plugin developers (integration guide).
- 3-month support after delivery.
Timelines
| System Type |
Estimated Timelines |
| Compile-time plugin system (iOS + Android) |
8–14 weeks |
| Runtime plugin system (Android) + JS plugins (iOS) |
4–7 months |
| Full platform with plugin marketplace |
8–14 months |
We have implemented plugin architecture for 7 enterprise clients over 5+ years. Our specialists are certified for Android and iOS (Google Associate Android Developer, Apple Certified iOS Developer). We guarantee plugin compatibility over 2 major app versions.
Want to evaluate plugin architecture for your project? Request a consultation — we'll prepare a turnkey proposal in 2–3 days. Contact us to discuss your requirements.
DexClassLoader API documentation
Mobile App Architecture
The app is built in a single ViewController with 2000 lines. Network calls, business logic, UI updates—all in one place. Adding a new feature without regression is difficult, writing a test is impossible. This isn’t “bad code”—it’s a lack of architecture. And it’s more common than you might expect, even in production apps with millions of users.
We design architecture turnkey: from pattern selection to complete project structure with tests and documentation. In 7–10 days you get clean, modular code ready for scaling.
Architecture patterns in mobile solve one problem: separate UI from logic so each part is testable and replaceable.
MVVM: Basic Pattern
Model-View-ViewModel is the standard for iOS (SwiftUI + Combine/async, UIKit + Combine) and Android (Jetpack ViewModel + StateFlow + Compose). The ViewModel holds UI state and business logic. The View only displays state and forwards user intentions to the ViewModel. The Model represents data and its source.
Key rule: ViewModel knows nothing about UIKit or Android View classes. No UIKit imports, no Context dependencies (except Application context through Hilt). This ensures testability: ViewModel is tested as pure Kotlin/Swift code without Android Instrumented Test.
MVVM covers 70% of needs. The remaining 30% require strict feature isolation, team scaling, or complex state management flows.
Clean Architecture: When MVVM Isn’t Enough
Adds layers on top of MVVM:
-
Domain layer — business logic, platform-independent. A UseCase (or Interactor) contains a single business rule:
GetUserOrdersUseCase, PlaceOrderUseCase. Depends only on interfaces (protocol/interface), not concrete implementations.
-
Data layer — repository implementations.
OrderRepositoryImpl implements OrderRepository from domain. Knows about Retrofit, Room, UserDefaults. The ViewModel doesn’t know where data comes from—network or cache.
-
Presentation layer — ViewModel + View. Knows about Domain, not Data.
Dependency rule: dependencies point inward only. Domain depends on nothing. Data and Presentation depend on Domain.
Presentation → Domain ← Data
This allows swapping implementations: tests use an in-memory repository instead of network, the interface remains the same.
Practical caveat: Clean Architecture adds files and layers. For small apps, this is overhead. It’s justified starting from ~15 features and teams of 3+ developers.
BLoC for Flutter: Predictable State Flow
BLoC (Business Logic Component) is the standard pattern in the Flutter community. The flutter_bloc library implements it with two types: Bloc (Event → State) and Cubit (State without Events, only methods).
Bloc processes Event and emits a new State via on<EventType> handlers. State is immutable—a new object for each change. BlocBuilder re-renders only the part of the tree where state changed.
// Event
abstract class CartEvent {}
class AddItemToCart extends CartEvent {
final String productId;
AddItemToCart(this.productId);
}
// State
abstract class CartState {}
class CartLoaded extends CartState {
final List<CartItem> items;
CartLoaded(this.items);
}
// Bloc
class CartBloc extends Bloc<CartEvent, CartState> {
CartBloc(this._cartRepository) : super(CartLoaded([])) {
on<AddItemToCart>(_onAddItem);
}
Future<void> _onAddItem(AddItemToCart event, Emitter<CartState> emit) async {
final current = state as CartLoaded;
final updated = await _cartRepository.addItem(event.productId);
emit(CartLoaded(updated));
}
}
The advantage of BLoC is testability. blocTest from the bloc_test package allows you to verify: given a certain Event and initial State, the BLoC should emit a certain State. No UI, no mocks for the Flutter framework.
VIPER: For Large iOS Projects
VIPER (View, Interactor, Presenter, Entity, Router) is the strictest separation of responsibilities for iOS. Each component has a protocol and concrete implementation.
-
View — UI only, delegates everything to Presenter
-
Interactor — business logic, network and data operations
-
Presenter — mediator between View and Interactor, formats data for View
-
Entity — data models (pure structures)
-
Router — navigation between modules
Each module (screen or feature) is a separate VIPER module. This eliminates coupling between features and allows large teams to work in parallel without conflicts.
The cost: many files, many protocols. Boilerplate is generated via Sourcery or custom Xcode templates. VIPER is justified for apps with 10+ developers and 50+ screens.
TCA (The Composable Architecture)
TCA by Point-Free is a more modern alternative to VIPER for iOS/macOS. Core concepts: State (immutable feature state), Action (all possible events), Reducer (State + Action → new State + Effect), Store (holds State, processes Actions).
Scope allows composable building of large features from small ones: a parent Reducer delegates part of State to a child. Each feature is tested in isolation via TestStore with precise control over Effects.
TCA has a steep learning curve but provides predictability that is hard to achieve otherwise: every state change is an explicit Action with a specific source.
Which Pattern to Choose for Your Project?
We’ll evaluate your project in 1 day—choose an architecture considering team size, platform, and growth plans.
| Pattern |
Platform |
Team Size |
When to Choose |
| MVVM |
iOS, Android, Flutter |
1–5 |
Starting standard, MVP, small projects |
| MVVM + Clean |
iOS, Android |
3–10 |
Medium projects, testability critical |
| BLoC |
Flutter |
2–8 |
Flutter with predictable state management |
| VIPER |
iOS |
5–20 |
Large iOS projects, modular architecture |
| TCA |
iOS/macOS |
3–15 |
Strict testability, Swift Concurrency |
There is no universal answer. Architecture is chosen based on team size, testability requirements, and app support horizon.
What Components Are Included in Our Architecture Work?
-
Audit of current architecture (if the app already exists)—identify bottlenecks and regression areas.
-
Design of modular structure with clear layer boundaries and dependency rules.
-
Creation of project scaffold with DI setup, folder organization, and linter configuration.
-
Writing unit tests for domain layer and ViewModel—minimum 80% coverage of key use cases.
-
Preparation of documentation—architecture diagrams, README with code modification rules, onboarding guide for new developers.
-
Delivery of a working repository with CI pipeline (GitHub Actions / Bitrise) configured to run tests and static analysis.
All this is included in the design cost. Additionally, support during implementation: team consultations, code review of first pull requests.
How Does Lack of Architecture Affect Development Speed?
Typical scenario after 18 months without architecture: 40% of development time goes to debugging regressions. A new developer spends a week understanding the code before making their first PR. Tests aren’t written “because it’s hard to mock.” Adding a new feature requires understanding half the codebase.
Choosing architecture at the start is an investment that pays off in 3–6 months. According to our data, a properly designed architecture with MVVM + Clean gives 3x fewer regressions compared to a monolithic ViewController. And the cost of implementation is recouped in 2–3 sprints.
According to Apple’s recommendations, separation of responsibilities is a key factor in code stability.
Why Trust Our Team with Architecture?
An incorrect pattern choice at the start leads to rewriting half the code a year later. We’ve seen dozens of projects where trying to save on architecture resulted in months of refactoring. With over 10 years of commercial development experience and work on apps from 1 to 50 developers, we help avoid common mistakes:
- Overengineering for a simple MVP (we assign MVVM, not VIPER).
- Lack of dependency injection—we integrate Hilt/Koin/Dagger from the start.
- Ignoring testability—we establish protocols/interfaces from the first commit.
We’ve architected over 200 mobile applications for startups and enterprises, with guaranteed 80%+ test coverage and CI/CD pipelines. Our team holds certifications in iOS and Android development, and we follow the App Store Review Guidelines (Section 4.2/5.1) to ensure smooth store approvals.
Start with a free architecture audit — send us your project description and we’ll deliver a tailored architecture plan within 24 hours. Reach out via Telegram or email to get started.