Website & App X-Ray

In-app purchases
Content rating
Everyone
0+
Downloads
Content rating
Everyone
In-App Purchases
Learn more
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image

About this app

Type a website address and Website X-Ray tells you what it's built on, how it makes money, what's slowing it down and what it's leaving exposed. Pick an app on your phone, or open an APK file, and App X-Ray tells you what's inside it, what it can reach and who signed it.

══ WEBSITE X-RAY ══

TECHNOLOGY — framework, CMS, server, CDN, hosting, analytics, payments and JavaScript libraries, each with the evidence that found it. Plus DNS, the TLS certificate, the redirect chain and every header.

BUSINESS — the analytics, advertising, payment and marketing tools loaded, whether there's a pricing page, signup or login, and a labelled scale bracket inferred from the tooling. We never invent visitor numbers.

UX AND PERFORMANCE — time to first byte, page weight, compression, render-blocking scripts, missing viewport, unlabelled inputs. Plus the SEO picture: title and meta description, canonical URL, headings, structured data and sitemap.

SECURITY — HTTPS and redirects, HSTS, Content-Security-Policy, clickjacking protection, referrer and permissions policy, cookie Secure/HttpOnly/SameSite flags, mixed content, server version disclosure, certificate health.

══ APP X-RAY ══

Pick any app on your device, or open an APK file. Nothing is installed, launched or modified — the app is read as a file.

IDENTITY AND SIGNING — package, version, target and minimum SDK, which store installed it, and the signing certificate in full: SHA-256, subject, issuer, expiry, schemes. A build signed with Android's public debug key is called out for what it is.

PRIVACY — every permission it requests, in plain language rather than constant names, marked where Android classes it dangerous. Premium adds the analytics, ad, attribution and crash SDKs compiled into the code.

SECURITY — whether it ships debuggable, allows backups, permits unencrypted HTTP or shares a user ID, every activity, service, receiver and provider any other app can reach, and every web link that opens the app — with whether Android has verified it.

MANIFEST — the full inventory: every component with its permission gate, process, launch mode or provider authority. Plus the permissions the app defines, the hardware it requires, its meta-data and which other apps it can see.

QUALITY — target SDK against Google Play's floor, CPU architectures shipped, 16 KB page alignment of native libraries, the size breakdown, and how stale the build is.

══

EVERY CHECK RUNS FOR EVERYONE
No scan limit, and free includes the sweep for publicly readable configuration files (.env, .git/config, backups). If your site is leaking something, the free report tells you — its severity and the class of file. Every report exports as a PDF or as text.

PREMIUM UNLOCKS THE DETAIL
• Which file, what it exposed, and how to fix it.
• An AI report written from your exact scan, with a prioritised list of fixes.
• On an app: the libraries and trackers compiled into its code, the 16 KB alignment audit, and the intent filters — every web link that opens the app and whether Android has verified it.
• 100 AI reports per month. Scanning itself stays unlimited and free.

An app X-ray is a static read: it can tell you an app is able to reach your microphone, or that an analytics library is compiled in, but not what it does while it runs.

On a website it makes only ordinary read-only requests for public pages. It never logs in, guesses passwords, submits forms, or sends anything designed to trigger a bug.

PRIVACY AND PERMISSIONS
Scans run on your device and there are no accounts. When you request an AI report, what leaves your phone is a description of the one thing you inspected — nothing about you, your network or your location. Scanned addresses are never stored, and your app list is never uploaded.

Internet access only. No location, storage, camera or background services. The app list comes from Android's standard launcher query, not the broad "see all apps" permission.
X-ray any website or Android app: stack, trackers, permissions, security.
Updated on
Sep 13, 2026

Data safety

Safety starts with understanding how developers collect and share your data. Data privacy and security practices may vary based on your use, region, and age. The developer provided this information and may update it over time.
  • This app may share these data types with third parties
    App activity
  • This app may collect these data types
    App activity, App info and performance, and Device or other IDs
  • Data is encrypted in transit
  • You can request that data be deleted

What’s new

First public release.

Type a website address and see what it runs on, how it makes money, what slows it down and what it leaves exposed — with the evidence behind every finding.

Or pick an app on your phone, or open an APK, and see its permissions, signing certificate, components and deep links. Nothing is installed or run.

Every scan is free and complete. Premium adds the AI write-up and the deep review.
Content rating
Everyone
In-App Purchases
Learn more

App support

About the developer
Future Systems, LLC
hello@oonak.ai
6/1 Abelyan str. Yerevan 0038 Armenia
+374 77 598803

More by Oonak