What We Found in 118 Open-Source Android APKs
We download every APK on this site from the developer’s or repository’s official release, check its hash and signing certificate, and take it apart. This report adds up what we found in the 118 apps we host — 109 apps and 9 game tools — as measured on Sep 30, 2026 (UTC). The data is free to reuse.
Key findings
- Few tracker libraries, all crash reporters. 5 of the 118 apps contain code from a library on Exodus Privacy’s tracker list, and every one is a crash reporter: ACRA (3 apps), Bugsnag and Sentry. None contains an advertising or analytics library from that list.
- Labels and code scans measure different things. 5 apps carry the “Tracking” anti-feature label from F-Droid or IzzyOnDroid, yet none of them contain a known tracker library.
- 33 apps (28%) never ask for internet access, including all 10 Fossify apps.
- Most files are signed by their developers: 80 (68%), against 38 signed by F-Droid.
- v1 signatures linger. All 45 apps that still install on Android 6.0 or older carry one, as they must; so do 24 of the 73 apps that need Android 7.0 or later.
- 89 apps (75%) target Android 15 or newer. Of the 10 that target Android 9, 7 are Termux and its plugins, held there on purpose.
- Downloads are small: the median APK is 12.3 MB; 10 are over 100 MB, led by Zalith Launcher 2 at 354.6 MB.
Tracker libraries
We scan each APK’s code for the class names in Exodus Privacy’s tracker signatures. A library only counts when its code is actually inside the APK. When an app merely refers to a tracker’s class names without shipping the library, we note it separately.
| Library | Apps | Exodus category |
|---|---|---|
| ACRA | 3 | Crash reporting |
| Bugsnag | 1 | Crash reporting |
| Sentry | 1 | Crash reporting |
Not counted: Zalith Launcher 2, Fold Craft Launcher and Amethyst Launcher include ByteHook (bhook), an open-source library that Exodus’s Pangle signature also matches. It isn’t a tracker, so we don’t count it; how we check files explains each exception.
Referred to but not shipped: OpenTelemetry (OpenCensus, OpenTracing), in Cryptomator.
Finding a library means its code is in the APK. It doesn’t tell us when, or whether, the app sends anything. And not finding one doesn’t mean an app sends nothing: the signatures only cover known third-party libraries, not an app’s own reporting. Florid, for example, sends a daily ping that no signature covers; we note it on its page.
F-Droid defines the “Tracking” anti-feature as an app that “tracks and/or reports your activity to somewhere, even when it can be turned off”. The 5 apps here with that label — APKUpdater, Aurora Store, RustDesk, Tailscale and OsmAnd~ — contain no library from the tracker list. Most likely the label is about what these apps report, for example to their own servers, which a library scan can’t see.
Who signs the APK
Android normally installs an update over an app only when both are signed with the same key, so the signer decides where you can get updates from. See “App not installed” and package conflicts.
| Where we get it | Signed by the developer | Signed by F-Droid |
|---|---|---|
| IzzyOnDroid | 65 | 0 |
| F-Droid | 4 | 38 |
| GitHub releases | 11 | 0 |
The 4 F-Droid apps signed by their developers (Obtainium, OpenConnect, LocalSend and NewPipe) use reproducible builds: F-Droid rebuilds the app from source and, when its build matches the developer’s file, publishes the developer’s file. As F-Droid puts it, this means it “can verify that an app is free software while still using the original developer’s APK signatures”. No APK in the sample has more than one signer.
| Signature schemes | APKs |
|---|---|
| v1, v2, v3 | 55 |
| v2 | 49 |
| v1, v2 | 14 |
Every APK carries a v2 signature, the scheme introduced in Android 7.0. All 38 F-Droid-signed APKs carry v1, v2 and v3; of the 80 developer-signed ones, 49 use v2 alone. The Android Open Source Project explains why v1 hasn’t gone away: “Older Android platforms ignore v2+ signatures and thus need apps to contain v1 signatures.” Here, all 45 apps that support Android 6.0 or older include a v1 signature, and 24 of the 73 apps that need Android 7.0 or later include one they don’t need. To check a signature yourself, see how to verify an APK’s signature.
Android versions
The minimum version is the oldest Android an app installs on; the target version is the one its developers say they have tested it against.
| Minimum Android version | Apps |
|---|---|
| Android 4.4 or older | 8 |
| Android 5.0–5.1 | 16 |
| Android 6.0 | 21 |
| Android 7.0–7.1 | 21 |
| Android 8.0–8.1 | 36 |
| Android 9 | 8 |
| Android 10 or newer | 8 |
The most common minimum is Android 8.0 (35 apps). 23 apps still install on Android 5.0 or older, and PPSSPP goes all the way back to Android 2.3.
| Target Android version | Apps |
|---|---|
| Android 17 (API 37) | 17 |
| Android 16 (API 36) | 52 |
| Android 15 (API 35) | 20 |
| Android 14 (API 34) | 13 |
| Android 13 (API 33) | 5 |
| Android 11 (API 30) | 1 |
| Android 9 (API 28) | 10 |
89 apps (75%) target Android 15 or newer. 7 of the 10 apps that target Android 9 are Termux and its plugins, which stay there deliberately. Their developers write: “Google requires the target SDK level to be set to at least 29, which corresponds to Android OS version 10. But due to new operating system behavior changes we cannot do so and have to use SDK level 28.” The others are RetroArch, Winlator and SkyTube. No app in the sample is old enough to trigger Android’s “built for an older version of Android” warning.
Permissions
An app lists the permissions it may use in its manifest; only some of them need your approval before the app can use them. The median app declares 10 permissions, of which 2 need approval, and 21 apps need none at all. The longest list belongs to App Manager, with 63.
| Most requested permissions that need approval | Apps |
|---|---|
| Show notifications (Android 13+) | 74 |
| Write shared storage (Android 10 and older) | 62 |
| Read shared storage (Android 12 and older) | 48 |
| Record audio with the microphone | 18 |
| Use the camera | 15 |
| Precise location | 13 |
33 apps (28%) don’t request internet access at all, so Android won’t let them open a network connection. They include all 10 Fossify apps and 5 Termux plugins.
Native code and size
96 apps include native code: 66 for both 32-bit and 64-bit ARM, 30 for 64-bit ARM only, and 71 also for Intel and AMD processors (emulators and Chromebooks). The other 22 have no native code and run on any processor. Which file fits your phone is explained in arm64-v8a or armeabi-v7a.
The median APK is 12.3 MB. 47 are under 10 MB and 10 are over 100 MB; the largest is Zalith Launcher 2, at 354.6 MB.
Releases, licences and labels
52 apps (44%) had a release in the 90 days before the snapshot, and the median current release was 126 days old. For 22 apps, the current release was more than a year old; they include Termux and its 7 plugins, Shizuku and AdAway.
81 apps (69%) use a version of the GPL-3.0, 10 the GPL-2.0 and 3 the AGPL-3.0; 18 use a permissive licence such as Apache-2.0 or MIT.
30 apps carry at least one anti-feature label. The most common is “NonFreeNet” (23 apps), which F-Droid gives to an app that “promotes or depends entirely on a non-free network service”, such as a client for a commercial video service.
18 apps use Shizuku, 9 are Xposed or LSPosed modules, and 7 use root through libsu.
Method and limits
- What we measure. Each file is checked against its official listing (hash, signing certificate, package name), then its manifest, native libraries and code are read. The full procedure is on how we check files.
- Not a random sample. These are the apps we host, chosen because people look for them. Popular, actively maintained tools are over-represented compared with open-source Android apps in general.
- One release per app: the version that was current on Sep 30, 2026, measured between 21:03 and 21:09 UTC.
- Static analysis only. We read files; we don’t run the apps or watch their network traffic.
- Provenance, not safety. A matching hash and certificate show that a file is the developer’s or repository’s original. They don’t show that the app is free of bugs or does only what it says.
Get the data
Each row is one app: name, package, version, APK SHA-256, signing-certificate SHA-256, signature schemes, minimum and target SDK, native ABIs, all permissions and those that need approval, tracker libraries found, anti-feature labels, licence and measurement time.
- JSON snapshot, Sep 30, 2026 (198 KB)
- CSV snapshot, Sep 30, 2026 (114 KB)
The data is licensed under CC BY 4.0: you may share and adapt it, commercially too, if you credit 2113 Apps with a link to this page. A continuously updated version is in our GitHub repository. Suggested citation:
2113 Apps. What We Found in 118 Open-Source Android APKs. Data snapshot of Sep 30, 2026. https://h5.2113.net/reports/open-source-apk-report-2026.html
Sources
- APK signature schemes (Android Open Source Project) checked Oct 1, 2026
- Platform versions and API levels (Android Developers, uses-sdk) checked Oct 1, 2026
- Termux and Android 10 (Termux packages wiki) checked Oct 1, 2026
- Anti-Features (F-Droid documentation) checked Oct 1, 2026
- Reproducible Builds (F-Droid documentation) checked Oct 1, 2026
- Tracker signatures (Exodus Privacy) checked Oct 1, 2026