Skip to content

Android setup

Minimum: API 21. The plugin compiles against API 36 with Java 17.

Gradle merges these entries from the plugin into your app’s manifest. You don’t need to add them.

<uses-permission android:name="android.permission.DETECT_SCREEN_CAPTURE" />

Screenshot detection on Android 14 (API 34) and later uses Activity.registerScreenCaptureCallback, which requires this permission. It’s a normal permission: granted at install, with no prompt. Older Android versions ignore it.

Android 11 (API 30) and later hide other installed apps unless you declare which ones you look for. The plugin declares 31 specific packages: 21 root-management and root-cloaking apps (such as com.topjohnwu.magisk and eu.chainfire.supersu) and 10 fake-GPS apps. Without these entries, the “app installed” signals would never fire.

The plugin deliberately doesn’t use QUERY_ALL_PACKAGES, which Google Play restricts.

The plugin doesn’t declare or request location permission. Without it, mock-location detection can still flag installed fake-GPS apps and a selected mock-location app, but not a mocked location itself.

To enable the location-based signals, declare and request the permission in your app:

android/app/src/main/AndroidManifest.xml
<uses-permission android:name="android.permission.ACCESS_FINE_LOCATION" />

Request it at runtime with your usual permission flow. The result’s locationPermissionGranted tells you whether the SDK could read a location.

Root, emulator, debugger and mock-location checks run on a background thread, one at a time, and deliver their result back on the main thread. Root detection still starts three short-lived processes and makes 21 package lookups, so a check takes noticeably longer than a frame. Await it; don’t run it on every rebuild.

  • Emulators are detected as emulators. On the Android 17 emulator image (API 37) the build-property signals hardware and product fire.
  • Root on an emulator: some emulator images set ro.debuggable=1, which fires the weak dangerous_system_props signal. Weak signals never mean detected, so emulators come back clear.
  • Debug builds fire the weak debuggable_flag signal, so the debugger check stays clear unless a debugger is actually attached.

Test your handling of real results on a release build on a physical device.