Mobile App Codebase Audit: iOS, Android, Flutter

70% of projects with high test coverage (80%+) face regressions in business logic — this is the statistic from our audits. The reason: tests cover UI and getters, not Use Cases and ViewModels. Typical scenario: you add a new feature, CI is green, but after merge, working functionality breaks. A mobi

Development and support of all types of mobile applications:

Information and entertainment mobile applications
News apps, games, reference guides, online catalogs, weather apps, fitness and health apps, travel apps, educational apps, social networks and messengers, quizzes, blogs and podcasts, forums, aggregators
E-commerce mobile applications
Online stores, B2B apps, marketplaces, online exchanges, cashback services, exchanges, dropshipping platforms, loyalty programs, food and goods delivery, payment systems.
Business process management mobile applications
CRM systems, ERP systems, project management, sales team tools, financial management, production management, logistics and delivery management, HR management, data monitoring systems
Electronic services mobile applications
Classified ads platforms, online schools, online cinemas, electronic service platforms, cashback platforms, video hosting, thematic portals, online booking and scheduling platforms, online trading platforms

These are just some of the types of mobile applications we work with, and each of them may have its own specific features and functionality, tailored to the specific needs and goals of the client.

Showing 1 of 1All 1734 services
Mobile App Codebase Audit: iOS, Android, Flutter
Medium
~3-5 days

Our competencies:

Frequently Asked Questions

Latest works

  • image_mobile-applications_feedme_467_0.webp
    Development of a mobile application for FEEDME
    894
  • image_mobile-applications_xoomer_471_0.webp
    Development of a mobile application for XOOMER
    782
  • image_mobile-applications_rhl_428_0.webp
    Development of a mobile application for RHL
    1216
  • image_mobile-applications_zippy_411_0.webp
    Development of a mobile application for ZIPPY
    1079
  • image_mobile-applications_affhome_429_0.webp
    Development of a mobile application for Affhome
    1002
  • image_mobile-applications_flavors_409_0.webp
    Development of a mobile application for the FLAVORS company
    597

70% of projects with high test coverage (80%+) face regressions in business logic — this is the statistic from our audits. The reason: tests cover UI and getters, not Use Cases and ViewModels. Typical scenario: you add a new feature, CI is green, but after merge, working functionality breaks. A mobile app codebase audit finds such "blind spots" and shows where tests are actually needed. Our experience diagnoses problems that remain hidden in 60% of projects until the first incident. We guarantee the report contains actionable recommendations, not general phrases.

How does a codebase audit prevent regressions?

Code review checks a single PR: style, logic, bugs. An audit answers the question: "Can we live with this code for the next two to three years, add features without constant regressions, onboard new developers in reasonable time?" It's an analysis of systemic technical debt, not point problems. Cyclic dependencies between modules occur in 40% of projects, hardcoded API keys in 30%. Without an audit, these numbers stay hidden until the first incident. According to the OWASP Mobile Security Testing Guide, such vulnerabilities are classified as High Risk.

What exactly do we check?

Architecture cohesion. We examine the dependency graph: are there cyclic dependencies between modules, are layer boundaries violated, does the UI directly depend on specific network libraries? For iOS — we check separation into feature modules or at least adherence to MVVM/VIPER within a single target. For Android — Clean Architecture with Use Cases, or everything dumped into an Activity. Tools: Xcode Dependency Graph, Android Studio Module Dependencies, ArchUnit for automated verification.

Test coverage. We look not only at the percentage but also at what is covered. 80% coverage on trivial getters and 10% on business logic is worse than 30% of correct tests on Use Cases and ViewModels. We check for integration tests (UI, XCUITest, Espresso), mocks for network dependencies, tests for edge cases (empty list, network error, timeout). In 70% of projects, test coverage of business logic does not exceed 20%, leading to regressions. Automated analysis reduces review time by 3-5 times compared to manual review.

Dependency management. CocoaPods vs SPM, Gradle catalogs, outdated versions. Libraries with known CVE — we check via OWASP Dependency-Check or a snapshot from pod outdated / ./gradlew dependencyUpdates. We pay special attention to libraries requesting excessive permissions (Analytics SDK, Ad SDK) — they may violate App Store/Play Store privacy policies.

Performance and memory leaks. Static analysis does not replace a profiler, but in 90% of cases it finds patterns: synchronous tasks on the main thread, image created without caching in a loop, URLSession created per-request instead of a singleton. For Flutter — const constructors not used where they should be, expensive computations in build(). Average memory leak frequency in large projects is 3-5 per 1000 lines of code.

Security. Automated analysis via MobSF (Mobile Security Framework) or Semgrep with mobile rules. We look for: hardcoded API keys in code or plist, logging of sensitive data, insecure IPC (exported Activities without permission), use of outdated algorithms (MD5, SHA1 for critical operations). We also check Code Signing configurations, provisioning profiles, Push Notifications settings (APNs/FCM), deep linking (Universal Links / App Links), and ATT (App Tracking Transparency). According to App Store Review Guidelines, user data must be handled with care — hardcoded credentials are a direct violation.

What tools do we use?

Task iOS Android
Static analysis SwiftLint, Periphery (unused code) Detekt, Android Lint
Dependencies/CVE pod audit + OWASP Dependency-Check OWASP Dependency-Check
Code complexity SonarQube SonarQube
Security MobSF MobSF
Memory leaks Instruments (Leaks) LeakCanary

SonarQube integrates into CI and calculates cyclomatic complexity, code duplication, cognitive complexity. A function with complexity > 15 is a candidate for refactoring — this is not a matter of taste, but a measurable risk.

Problem Frequency in projects
Cyclic dependencies between modules 40%
Test coverage of business logic < 20% 70%
Outdated libraries with CVE 5-8 on average per project
Memory leaks 60%
Hardcoded API keys 30%

Why don't automated tools replace manual analysis?

Although tools like Periphery find unused code and MobSF identifies vulnerabilities, only a manual architecture audit can assess how technical debt will affect future development. In one project, we discovered a cyclic dependency that increased build time by 40% — the static analyzer didn't show it because dependencies were via reflection. Our experience prevents such situations.

How do we conduct an audit?

  1. Metrics collection — static analysis of the entire code, dependency graph, test coverage.
  2. Deep architecture review — identify cyclic dependencies, violations of Clean Architecture.
  3. Manual security check — review configurations, manifests, plists.
  4. Performance profiling — search for leaks and bottlenecks.
  5. Report creation — roadmap with risk assessment and priorities.

Using automated tools reduces analysis time by 3-5 times compared to manual review. Periphery for iOS finds unused functions, classes, protocols. In a large codebase, thousands of lines of dead code accumulate — which are read, maintained, and feared to be deleted.

What do you get as a result?

  • Report with four levels: Critical (immediate fix — data leak, crasher), High (next sprint — architectural risk, security issue), Medium (technical debt, plan), Low (quality recommendations).
  • Refactoring roadmap with risk assessment and priorities — what to refactor first, what can be postponed.
  • Documentation of found issues and recommendations for resolution.
  • List of outdated dependencies with CVE and migration versions.
  • Recommendations for improving CI/CD to automate quality control.

Contact us for project assessment. Get a consultation on the audit — we will estimate timelines and scope individually. An audit without an action plan is a meaningless document, so we always give actionable recommendations.

Timelines — from 3 to 5 days for a medium-sized project (up to 200k lines). Large projects (300k+ lines, multiple platforms) — up to 2 weeks. Exact cost is calculated after reviewing the project. Budget savings on refactoring with our recommendations can reach 40% due to prioritization of critical issues.