Identity and signing
See signing status, Team ID, bundle ID, version, distribution type, certificate chain, secure signing timestamp, whether the build can keep validating after its certificate expires, and whether the signature still matches the file on disk.
Apple safety signals
Review Developer ID or Mac App Store distribution, notarization and attached offline tickets, certificate revocation, quarantine, sandboxing, Hardened Runtime, and network declarations.
Update delivery safety
Detect Sparkle update delivery, review feed transport security and update signature verification, and flag timestamp problems that could make a signed build stop validating after its certificate expires.
Risky runtime and development capabilities
Get prominent warnings for unvalidated third-party code, unsigned executable memory, debugger attachment, development push notifications, and the affected component paths.
Privacy access
Camera, microphone, screen recording, accessibility, contacts, calendars, reminders, photos, location, Bluetooth, local network, speech recognition, Apple Events, and other sensitive access are grouped into readable labels.
Saved permission decisions
When macOS allows the local privacy database to be read, App Trust Preview can show saved decisions such as allowed, denied, limited, add-only, not decided, or unknown.
Download history and file metadata
See the original source URL, download application, date, file type, quarantine status, macOS processing metadata, and additional source details recovered from macOS. Copy the original download URL in one click.
Internet access and potential connections
See whether sandbox rules restrict direct internet access alongside domains and URLs found through static analysis. Potential destinations are presented as clues, not claims that the app actually connects to them. Copy the detected URL list for further review.
Technical details and metadata
Compare logical size with actual disk use and review relevant code-signing, Finder, and system file metadata. DMG reports keep disk image metadata separate from the extracted app and its bundled components.
Inside apps and disk images
Helper tools, login items, XPC services, extensions, frameworks, plug-ins, dynamic libraries, nested apps, architectures, and affected component paths are surfaced. The main app's minimum macOS requirement is shown separately from the highest requirement among bundled components.
Save analyzed apps
Keep an analyzed app as an app bundle, ZIP archive, or DMG disk image. Install it in Applications only when you explicitly choose Install, including apps inspected from DMG files, and optionally move the downloaded DMG to the Trash afterward.
Packages, binaries, and scripts
Installer components, install locations, scripts, package payload files, Mach-O metadata, linked libraries, runtime search paths, code signatures, executable hashes, clickable VirusTotal report links, and readable script source previews are shown when available.
Technology and private API signals
Detect Sparkle, Electron, Chromium, CEF, Firefox, Gecko, ToDesktop, Tauri, Wry, WebKit, Qt WebEngine, SwiftUI, React Native, Flutter, Unity, Unreal Engine, Godot, Wine, CrossOver, Java, .NET, Python, Node.js, Mac Catalyst, iOS apps on Mac, Apple private framework links, URL schemes, associated domains, keychain groups, App Groups, and recognized entitlements.