Risk scanning service2018—2026

URL & APK
risk scanning

Aggregate risk alerts from Chinese Android vendors and create public, shareable reports, with monitoring and appeal support when needed.

URL scan

Enter a URL or bare domain to aggregate risk verdicts and generate a standalone report.

  • Accepts http/https URLs and bare domains
  • Results are saved to scan history
  • Report links can be shared directly
Scan now

APK scan

Upload an APK to check alerts from Tencent, 360, Huawei, Xiaomi, OPPO, vivo, and more.

  • Extract package name, certificate, and hashes
  • One free scan every day
  • Share reports with clients or vendors
Scan now

Scan records stay in history. If an alert needs action, contact support.

Why vendor-side scanning matters

International scanning engines and install blocking by Chinese phone vendors are separate systems. An app can be clean on VirusTotal yet still show an installation warning on OPPO, vivo, Huawei, or Xiaomi devices. VendorGuard consolidates common vendor results into one report for developers and acquisition teams.

Pre-release verification

Check the package name, certificate, and hashes before release so users do not discover warnings during installation.

Campaign path checks

Scan landing, download, and redirect pages separately to locate the marked step quickly.

Appeals and rescans

Prepare evidence from the report, then force a rescan after the appeal to confirm the alert is cleared.

Our partners

We work alongside major Android vendors and internet platforms for pre-release checks, channel risk coordination, and appeal workflows.

  • OPPO
  • vivo
  • Xiaomi
  • Huawei
  • HONOR
  • Tencent
  • Alibaba

Customer stories

Anonymized examples that show how teams use VendorGuard Scan before release and during campaigns.

Fintech app

Cleared install blocks on 3 vendors before launch

Four channel builds hit install warnings in one release week. Certificate hash drift was isolated in VendorGuard Scan; appeals and rescans finished in 48 hours.

+27% install conversion
Short-video tool

Found the polluted hop in the campaign path

Landing pages were clean while the download hop was flagged. Split URL and APK scans located a tainted redirect domain; CPA dropped 18% after replacement.

2-hour triage
Cross-border commerce SDK

Weekly package and certificate patrol

Integrators submit 30+ channel builds weekly. Pro-tier API polling in CI blocks certificate reuse and stale APK recirculation.

-60% manual review

How to read our confidence

We optimize for auditability, not opaque scores.

8+Major vendor/channel sources
99.2%90-day rescan consistency*
< 30sMedian async APK job time
24hAPI result poll window
  • Verdicts aggregate vendor-side cloud and device risk policies; they are not a multi-engine malware score like international scanners.
  • The same package + certificate + hash stays consistent inside the cache window; forced rescans prefer the latest vendor response.
  • Reports include package name, certificate MD5, file hashes, and per-channel detail suitable for appeal attachments.
  • * Consistency is the share of same-fingerprint samples that keep the same verdict inside the cache window when vendor policy is unchanged (internal sample).

Frequently asked questions

Which channels does VendorGuard check?

APK scans aggregate alerts from Tencent, 360, Huawei, Xiaomi, OPPO, vivo, HONOR, Samsung, and other common vendors. URL scans help with pre-campaign checks and download-path troubleshooting.

How does the free quota work?

Guests receive one free scan per day. Signed-in accounts receive more scans by plan. APK and URL scans share the same quota; see the plan comparison for limits and API rates.

Can I show the report to clients?

Yes. Each completed scan gets a standalone report link that anyone can view without signing in.

What should I do after an alert?

Send us the report link. We can help identify the trigger, prepare appeal materials, and follow up with the vendor.