Introduction
device_shield is a Flutter plugin that tells your app whether it is running
on a device that has been modified or is being inspected. It covers:
- Root (Android) and jailbreak (iOS)
- Emulators and the iOS Simulator
- An attached debugger
- Mock (fake) locations
- Screenshots and screen recording
It can also block screenshots on Android and blur the app-switcher snapshot on both platforms.
How it works
Section titled “How it works”Call a check, such as DeviceShield.checkRoot(), or run them all with
DeviceShield.check(). The native side (Kotlin on Android, Swift on iOS)
inspects the device and reports which signals fired. Each signal has a
strength, and the result says whether the check:
- detected its condition (at least one strong or two medium signals),
- came back clear,
- doesn’t apply on this platform, or
- failed to run.
Nothing is sent over the network and nothing is stored. Your app decides what to do with each result. See Detection results.
Project status
Section titled “Project status”What’s been verified:
- Android: every check and protection ran on an Android 17 emulator (API 37). Nothing has been tested on a physical Android device, or on a rooted one.
- iOS: the Simulator only (iOS 26.5). Nothing has been tested on a physical iPhone yet.
- iOS screenshot protection is experimental until it’s verified on a device. See Screenshot protection.
Platform support lists exactly what has been verified where.
Next steps
Section titled “Next steps”InstallationAdd the package and configure each platform.
Quick startRun your first check in a few lines.
Security modelWhat on-device checks can and can't guarantee.
Signals referenceEvery signal, what it checks, and how much to trust it.