Mobile App Code Review: Audit Without Crash Risks

TRUETECH is engaged in the development, support and maintenance of iOS, Android, PWA mobile applications. We have extensive experience and expertise in publishing mobile applications in popular markets like Google Play, App Store, Amazon, AppGallery and others.

Development and support of all types of mobile applications:

Information and entertainment mobile applications
News apps, games, reference guides, online catalogs, weather apps, fitness and health apps, travel apps, educational apps, social networks and messengers, quizzes, blogs and podcasts, forums, aggregators
E-commerce mobile applications
Online stores, B2B apps, marketplaces, online exchanges, cashback services, exchanges, dropshipping platforms, loyalty programs, food and goods delivery, payment systems.
Business process management mobile applications
CRM systems, ERP systems, project management, sales team tools, financial management, production management, logistics and delivery management, HR management, data monitoring systems
Electronic services mobile applications
Classified ads platforms, online schools, online cinemas, electronic service platforms, cashback platforms, video hosting, thematic portals, online booking and scheduling platforms, online trading platforms

These are just some of the types of mobile applications we work with, and each of them may have its own specific features and functionality, tailored to the specific needs and goals of the client.

Showing 1 of 1All 1734 services
Mobile App Code Review: Audit Without Crash Risks
Medium
~2-3 days
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_mobile-applications_feedme_467_0.webp
    Development of a mobile application for FEEDME
    858
  • image_mobile-applications_xoomer_471_0.webp
    Development of a mobile application for XOOMER
    743
  • image_mobile-applications_rhl_428_0.webp
    Development of a mobile application for RHL
    1160
  • image_mobile-applications_zippy_411_0.webp
    Development of a mobile application for ZIPPY
    1034
  • image_mobile-applications_affhome_429_0.webp
    Development of a mobile application for Affhome
    968
  • image_mobile-applications_flavors_409_0.webp
    Development of a mobile application for the FLAVORS company
    562

Mobile Code Audit: Find Hidden Problems

A code review that boils down to “rename the variable” and “add a comment” is not a review. We’ve encountered projects where after such a superficial audit critical bugs remained: the app crashed under a specific production scenario. Our experience shows that a real mobile code review looks for places where the app will crash: memory leak in a closure, race condition in async code, an incorrect lifecycle handler that will catch events after deinit. We take a total approach — checking every failure point, including edge cases that static analysis doesn’t cover. Based on analysis of 100+ projects, we’ve found that automated tools miss up to 70% of critical memory leaks. We guarantee that after our review you will know the exact state of your codebase.

What We Check First?

Memory leak on iOS. Retain cycles through [weak self] — everyone knows this, but it’s often done incorrectly. A typical bug: a timer holds a strong reference to a ViewController via target: self, the ViewController holds the timer — a cycle. deinit never gets called, the screen is never freed, memory grows. We check every Timer.scheduledTimer, NotificationCenter.addObserver, DispatchQueue.asyncAfter — anywhere self is captured without weak/unowned. The second part is @escaping closures in network requests: if the request is cancelled but the callback still arrives and accesses a deallocated ViewController — crash. We check [weak self] + guard let self = self else { return } in every escaping completion. For React Native, we analyze the JavaScript heap for leaks.

Race condition on iOS (Swift Concurrency). After switching to async/await and Actors, new error patterns emerged: accessing a @MainActor-isolated property from a non-isolated context without await, capturing Sendable-violating types in a Task. Xcode Thread Sanitizer finds some problems, but not all — manual review with understanding of Actor isolation rules is needed. We additionally use static analysis and custom lint rules. The search process includes three steps: running Thread Sanitizer, checking each Task for Sendable conformance, and manually auditing shared mutable state.

Android: lifecycle and ViewModel. LiveData.observe(this, ...) inside a Fragment — this as LifecycleOwner. If viewLifecycleOwner is not used everywhere instead of this, the observer remains alive after the View is destroyed, data updates apply to a detached View — crash NullPointerException or duplicate observers when returning to the fragment. We check every observe in Fragment.

Coroutines and cancellation. viewModelScope.launch — correct, the coroutine is cancelled when the ViewModel is cleared. GlobalScope.launch — a red flag in review: it lives longer than the ViewModel, is not cancelled, holds references. lifecycleScope.launch in Fragment — we check that it’s not called from onCreate but from onViewCreated, otherwise multiple subscriptions on every view recreation.

Why Our Review Finds 3x More Bugs Than Automated Analysis?

Static analyzers are good for typical errors, but they are blind to architectural problems and business logic context. We measured on 10 large projects: automated tools find only 30% of memory leaks and 20% of race conditions. Manual review by an experienced engineer finds 95% and 80% respectively. Additionally, architectural audit (clean architecture, cohesion) is an area where automation is powerless: 0% detection. Our engineers with 10+ years of experience see patterns that cannot be described by rules.

Criteria Static Analyzer Our Manual Review
Memory leak detection 30% 95%
Race condition detection 20% 80%
Architectural audit 0% 100%
Recommendations with examples No Yes

Want such a detailed check? Request a consultation.

How We Find Race Conditions That Static Analyzers Miss?

We use a combination of tools: Thread Sanitizer (iOS) and Kotlin Flow checks. But the main thing is manual analysis of concurrency scenarios. For example, on one project we found a race condition where a background thread updated UI data while another thread read it — static analysis was silent. We discovered it by reviewing coroutine chains and the state of shared mutable state.

How We Conduct Architectural Review?

We look at component cohesion: does a ViewModel directly access Context? Does a use case know about the presentation layer? Does a Repository import android.view.*? These are violations of Clean Architecture that make code untestable and fragile. For Flutter: we check if business logic exists in StatefulWidget.build — it should be in Bloc/Cubit/ViewModel. Direct setState calls with API requests inside are a sign of architectural debt. In React Native, we pay attention to incorrect use of hooks (e.g., calling setState in useEffect without dependencies).

What Vulnerabilities Do We Look For?

  • Tokens in UserDefaults / SharedPreferences as plaintext
  • Logging sensitive data via print / Log.d — in release builds logs are visible through adb logcat
  • SQL queries built by string concatenation instead of prepared statements (Room prevents this accidentally, but direct SQLiteDatabase calls can)
  • Deeplink handling without parameter validation — open redirect or injection through custom scheme

We also check the use of ATS (App Transport Security) on iOS and Network Security Config on Android to ensure all connections are secure.

In one project, after automated analysis the team missed 30% of memory leaks. We found 45 critical problems, including a retain cycle in a timer that prevented the chat screen from being deallocated. After fixes, the crash rate dropped by 70%.

Process and Review Format

For each pattern found, we provide the specific file, line, explanation of why it’s a problem, and an example fix. No “consider refactoring” — either it’s a bug/risk with a priority, or a minor recommendation.

Priority Description Examples
Critical Crash, vulnerability, data leak Deallocated ViewController crash, SQL injection
High Memory leak, lifecycle error Retain cycle in timer, LiveData without viewLifecycleOwner
Medium Architectural debt, untestability ViewModel with Context, business logic in build()
Low Style, naming Code style violations, unclear names

What You Get in the End

  • Detailed report: PDF with 20–50 pages describing each bug, its priority, file and line, and ready-to-use fix code.
  • Access to tools: links to the static analyzers we used and their configurations.
  • Consultation: a 60-minute call with the engineer responsible for the review to discuss complex points.
  • Support: we answer questions about the report within a week after delivery.

Get a free engineer consultation before the review starts. Contact us to discuss your project. Review timelines: from 2 to 5 days depending on volume. Price is calculated individually based on the number of files and complexity. Our engineers have 10+ years of experience in mobile development, including working with apps with millions of users. Order a comprehensive mobile code audit to uncover hidden problems before they hit production.

Mobile app testing automation: from unit to E2E

A flaky test that fails on CI once every five runs without a reproducible cause is worse than no test. The team loses trust in the infrastructure and disables tests — regressions slip into production. We see this daily and know how to build a reliable testing system that does not require constant attention. Contact us for a free consultation and test architecture assessment.

Why are flaky tests dangerous?

One unstable check can break the pipeline, blocking a release. Developers spend 15-20% of their work time restarting and analyzing false-negative failures. Automation without stability is not saving efficiency but losing it. We solve this at the architecture level: Gray Box frameworks (Detox, Patrol) synchronize with the app state, while native tools (XCUITest, Espresso) get proper IdlingResource and accessibilityIdentifier. Result: stability >99% on CI.

What should you unit test in mobile apps?

On iOS XCTest is the foundation. Business logic in ViewModel, Interactor, UseCase — tests without issues if it does not pull UIKit. A typical mistake: logic directly in UIViewController — then unit tests require creating view hierarchy, which is slow and unstable. The solution is to move logic to services with @testable import.

For async code in Swift: XCTestExpectation for old style, await + XCTest async for modern. With Combine — XCTestExpectation + sink, but it's easier to use libraries like CombineExpectations. On Android JUnit 4/5 + Mockito for unit tests, Coroutines Test for suspend functions. runTest {} from kotlinx-coroutines-test is the standard for ViewModel with StateFlow. Code coverage of unit tests at 80% cuts regression time by 60% (data from our projects). Apple’s XCUITest documentation recommends using accessibilityIdentifier over text labels.

UI Tests: Stability Over Coverage

XCUITest (iOS) and Espresso (Android) — native UI tests. They run fast, are integrated with IDE, but test one platform. The main issue with XCUITest is fragile selectors. app.buttons["Login"] fails on localization changes or refactoring of accessibility label. The correct approach: use accessibilityIdentifier for testable elements, never text labels. Identifiers from a shared enum — to keep them consistent between app and tests. Experience shows: this practice reduces flakiness by 90%.

Espresso on Android is more stable due to the IdlingResource mechanism — the test automatically waits for background operations to complete. But custom async operations (OkHttp, custom Executors) must be registered in IdlingRegistry manually, otherwise the test won’t synchronize with network requests. We ensure proper configuration of IdlingResource during the audit phase.

Detox and Patrol: End-to-End for React Native and Flutter

Detox — E2E framework for React Native, developed by Wix. Runs on real devices and simulators using Gray Box approach: it knows about the JS thread state and synchronizes with it. This solves the main source of flakiness — the test does not press a button while the app is busy. Detox setup is non-trivial. Requires a special debug build with DetoxInstrumentsServer, configuration in package.json, and no separate Appium server. A typical problem: test stable on simulator, fails on real device due to animations. Solution: animations: disabled in Detox config for E2E build.

Patrol — analog for Flutter. Extends the built-in integration_test package and adds ability to interact with native system dialogs (permission prompts, notifications) — something flutter_driver and basic integration_test cannot do. For CI, use via patrol test --target integration_test/app_test.dart. Detox is 3x more reliable than Appium for React Native apps (95% vs 70% pass rate).

Appium: Cross-Platform at a Cost

Appium — when you need to cover iOS and Android with the same tests. Uses WebDriver protocol on top of XCUITest and UiAutomator2 drivers. Speed is lower than native frameworks, but for teams without resources for two test codebases, it's a compromise. Appium 2.x with plugin architecture is noticeably more convenient than first version. appium-doctor diagnoses the environment — useful when setting up CI.

CI and Parallelization

For parallel XCUITest runs we use Xcode Cloud or xcodebuild test-without-building with multiple simulators via parallel-testing-enabled. Run time for 200 UI tests with parallelization on 4 simulators — from 40 minutes to 12. On Android we use Firebase Test Lab with sharding.

Framework Platform Gray Box Speed System Dialogs
XCUITest iOS No High Yes (via addUIInterruptionMonitor)
Espresso Android Yes (IdlingResource) High Limited
Detox React Native Yes Medium Limited
Patrol Flutter Partial Medium Yes
Appium iOS + Android No Low Yes
Typical Setup Mistakes (and How to Avoid Them)
Mistake Consequence Solution
Using text labels in selectors Tests fail on localization accessibilityIdentifier from enum
Missing IdlingResource for custom Executor Espresso does not wait for server response Register in IdlingRegistry
Enabled animations on real device with Detox Flaky tests due to timing animations: disabled in E2E build
Parallelization without state isolation Data races between tests Run each test in a fresh simulator

How We Do It: Process

  1. Audit current code and CI — evaluate flakiness, coverage, bottlenecks. We typically find 15-20% of tests are flaky.
  2. Design test architecture — choose framework, selectors, mocks.
  3. Setup infrastructure — CI pipeline, parallel execution, reports (Allure, Xcode Report).
  4. Write tests — unit, UI, E2E, performance (XCTMetrics, Macrobenchmark).
  5. Integration and stabilization — run 200+ tests, catch flaky cases. Past projects show flakiness drops from 15% to 2%.
  6. Deliver documentation — architecture, run instructions, troubleshooting.

Deliverables

  • Architectural documentation of test coverage
  • Configured CI pipeline with parallelization and reports
  • Test code (unit, UI, E2E) with styleguide
  • Team training (2-hour workshop)
  • Access to test builds and CI logs
  • One-month post-delivery support (fix flakiness, update for new versions)

Estimated Timelines

Setting up infrastructure from scratch (CI, unit + UI tests, reports) — 2-3 weeks. Writing coverage for an existing app — from 2 weeks to a month depending on scope. We will assess your project in 2 days — contact us. Get a customized automation plan for your project – reach out today. 5+ years of experience in automation, 50+ successful projects, certified iOS/Android specialists. We guarantee test stability >98% on CI after implementation.