device_shield
Know when your Flutter app is running somewhere it shouldn’t.
device_shield gives you root, jailbreak, emulator, debugger and mock-location signals from one package, and tells you plainly when a check can’t run.
$ flutter pub add device_shield 0.1.0 coming soon
import 'package:device_shield/device_shield.dart';
final report = await DeviceShield.check();
if (report.root.detected) { // Which signals fired, and how strongly print(report.root.signals);}rootdetectedsu_binary_path · strongbusybox_present · weakWhat it checks
The runtime checks security reviews ask for, in one package.
Pre-release: Android behaviour has not yet been verified on a physical device. See platform support for what has been tested.
Root & jailbreak
su binaries, Magisk artifacts, root and cloaking apps, a writable system partition on Android. Cydia, Sileo, sandbox escapes and library injection on iOS.
Emulator & simulator
Build fingerprint, model, hardware and QEMU pipes on Android. The simulator build target on iOS.
Debugger
An attached or awaited debugger and debuggable builds on Android. The kernel’s traced-process flag on iOS.
Mock location
The platform’s mock-provider flag, the selected mock-location app and known fake-GPS apps on Android. Limited on iOS today.
Screenshots & recording
Know when a screenshot is taken (Android 14+ and iOS) and when the screen is recorded or mirrored (iOS).
Capture protection
Block screenshots, recording and the Recents thumbnail with FLAG_SECURE on Android. Blur the app-switcher snapshot on iOS.
Coming soon
What we're building next.
Planned, not yet available. Order and timing can change. Follow the roadmap for status.
Runtime hook detection
Detect instrumentation frameworks such as Frida, Xposed and Substrate hooking into your app.
App integrity
Hand you Play Integrity and App Attest tokens for your server to verify. Requires a backend.
Developer options & overlays
Flag enabled developer options and screen overlays that can be used for tapjacking.
More recording & location signals
Screen-recording detection on Android 15+, and simulated-location detection on iOS 15+.
Honest by design
A security SDK that overclaims is worse than none.
Every result says whether a check ran, what it found, and how sure it is. You decide what to do about it.
notApplicableSays when a check can’t run
Ask for jailbreak detection on Android and you get “not applicable”, never a false “clear”.
signals + strengthShows its evidence
Every result lists the signals that fired and how strong each is. Weak ones never decide on their own.
failedFails loudly
A check that errors or times out comes back as failed. It never quietly turns into a clean result.
Security model
Risk signals, not a guarantee.
These checks run on a device the user controls, so a determined attacker can hide root or hook the checks themselves. Use device_shield to raise the cost of tampering and to adapt your app’s behaviour. For hard guarantees, pair it with server-verified attestation.
- Good for flagging risky devices, gating sensitive screens, fraud signals, analytics
- Good for keeping screenshots out of banking and health screens on Android
- Not a replacement for Play Integrity or App Attest
- Not a replacement for server-side authorisation
Start with the docs.
Installation, platform setup, and what every signal means.