Skip to content

device_shield

Pre-release · Android & iOS

Know when your Flutter app is running somewhere it shouldn’t.

device_shield gives you root, jailbreak, emulator, debugger and mock-location signals from one package, and tells you plainly when a check can’t run.

$ flutter pub add device_shield 0.1.0 coming soon

main.dart
import 'package:device_shield/device_shield.dart';
final report = await DeviceShield.check();
if (report.root.detected) {
// Which signals fired, and how strongly
print(report.root.signals);
}
checkroot
statusdetected
signalssu_binary_path · strong
busybox_present · weak
Android & iOSone Dart API
No networknothing leaves the device
No data collectedempty privacy manifest
BSD-3open source

What it checks

The runtime checks security reviews ask for, in one package.

Pre-release: Android behaviour has not yet been verified on a physical device. See platform support for what has been tested.

Coming soon

What we're building next.

Planned, not yet available. Order and timing can change. Follow the roadmap for status.

PlannedAndroid & iOS

Runtime hook detection

Detect instrumentation frameworks such as Frida, Xposed and Substrate hooking into your app.

PlannedAndroid & iOS

App integrity

Hand you Play Integrity and App Attest tokens for your server to verify. Requires a backend.

PlannedAndroid

Developer options & overlays

Flag enabled developer options and screen overlays that can be used for tapjacking.

PlannedAndroid & iOS

More recording & location signals

Screen-recording detection on Android 15+, and simulated-location detection on iOS 15+.

Honest by design

A security SDK that overclaims is worse than none.

Every result says whether a check ran, what it found, and how sure it is. You decide what to do about it.

notApplicable

Says when a check can’t run

Ask for jailbreak detection on Android and you get “not applicable”, never a false “clear”.

signals + strength

Shows its evidence

Every result lists the signals that fired and how strong each is. Weak ones never decide on their own.

failed

Fails loudly

A check that errors or times out comes back as failed. It never quietly turns into a clean result.

Security model

Risk signals, not a guarantee.

These checks run on a device the user controls, so a determined attacker can hide root or hook the checks themselves. Use device_shield to raise the cost of tampering and to adapt your app’s behaviour. For hard guarantees, pair it with server-verified attestation.

Read the security model →
  • Good for flagging risky devices, gating sensitive screens, fraud signals, analytics
  • Good for keeping screenshots out of banking and health screens on Android
  • Not a replacement for Play Integrity or App Attest
  • Not a replacement for server-side authorisation

Start with the docs.

Installation, platform setup, and what every signal means.