Install Checklist: 12 Checks for an App File
Answer twelve short checks about an app file you have been sent. The tool counts how many passed, how many found a problem and how many are still open, then lists what to do about each. It never calls a file safe.
What the checklist is for
An app file, called an APK on Android, can reach you in a chat, behind an ad or on a download page. Before it goes on your phone there are twelve things worth knowing. This tool lists them in four groups: the link, the file, what it asks for, and the things around the app, such as updates and reviews.
You answer each one Fine, A problem or Not checked. The tool counts the answers and says what to do about every check that is not fine. It gives no score, and it never calls a file safe. The result is checks done and checks open.
We do not host, store or send app files, and nothing you tick is saved or sent anywhere. The App and APK guide covers the same ground in prose; this is the longer version you can tick through.
How to use it
- Start at the top and read each question. It is worded so that “Fine” is the reassuring answer.
- Answer only what you know. If you cannot tell yet, leave it as Not checked. Open is never counted as passed.
- Tap “How to check this” under a question for the steps and a link to the page that goes deeper.
- Read the result box. It shows four counts and a numbered list of what to do next, with problems first and open checks after them.
- Press “Copy a link to this result” to send your answers to someone. They travel in the link after the # sign, which a website never receives.
Two kinds of problem
Eight of the twelve checks are reasons to walk away:
- where the link came from
- why you want the file
- what it is called
- who published it
- its fingerprint
- its permissions
- any request for money
- a Play Protect warning
The tool treats a problem in any of these as a reason to walk away, however many other checks pass. The other four are things to put right: what the link points to, how the app updates, reviews, and having a way back.
Reviews are marked as the weak check on purpose. Ratings and download counts on the page that offers a file are typed by whoever uploaded it, so good reviews never outweigh a problem somewhere else.
A worked example
Say a file arrives in a chat group, with a message that you need it to claim a bonus. The link came from the group, so “Where the link came from” is a problem. It points straight to an .apk, so “What the link points to” is a problem. Nobody has said who published it, so that is a problem too, and “Why you want it” is a problem because someone told you to install it. You take a screenshot of the page, so “A way back” is fine. Everything else is not checked yet.
The tool reads that as 1 of 12 checks passed, 4 checks found a problem and 7 still open. Three of the four problems are reasons to walk away, so the advice is not to install the file. If you still want the app, start again from a source you can account for and run the checks again.
Now take a file from the publisher’s own page, with a fingerprint that matches. Ten checks pass, none finds a problem and two stay open: permissions, because a file from outside a store has no listing to read, and reviews. The tool says that no check has found a problem so far, and that open is not the same as passed. Even with all twelve passed, it says only that the risk is lower.
What the checklist cannot tell you
It cannot look at a file. It reasons from your answers, so it is only as good as they are. A fingerprint printed beside the download proves little, because whoever swapped the file could swap the number as well. A permissions list shows what an app asks for, not what it does with it. The tool cannot say whether a publisher is honest or whether an app will work with your account. Play Protect is a separate scanner on your phone, and this list does not replace it.
If something has already gone wrong, what to do after a scam gives the steps in order.
Where to go next
Each check links to the page that goes deeper. The link checker reads an address. The file fingerprint checker compares a file with a publisher’s value. Permissions to refuse explains the requests, and the mod APK guide covers files sold as “unlimited”.
If your real aim is to get into an account, installing a file will not fix it. The login troubleshooter asks a few questions and points to the right guide. The rest of the free tools are one page up.
Common questions
Can a checklist show that an app file is safe?
No. A checklist can lower the risk and it can turn up a reason to walk away, but nobody can see inside a file from outside. A fingerprint, a clean list of permissions and good reviews can all be made to look right, so this tool reports checks passed and checks open, never a safe file.
What should I do when the publisher gives no fingerprint?
Leave that check as Not checked. With no fingerprint there is nothing to compare, so the file stays unchecked, which is a reason for more care and not a pass. Lean on the other checks, or skip the file and save the web page to your home screen instead.
Why does one problem outweigh ten passed checks?
Eight of the checks cover things that no other pass can undo: a link you cannot account for, a file called mod or hack, a fingerprint mismatch, a request to read texts, a demand for money or a Play Protect warning. If one of those is true, the other passes do not change it.
Does the checklist remember my answers?
No. Your answers live on this page only while it is open. Nothing is saved on your phone and nothing is sent anywhere. If you press the copy-link button, the answers are written into the link after the # sign, which a website never receives.
Do I need to run the checks if a friend sent the file?
Yes. A friend’s chat account can be hacked, and a forwarded file has passed through other hands. Ask your friend another way whether they really sent it, then answer the source check honestly: a link you cannot account for is a problem even when it came through a chat with someone you know.
What if an app asks for a permission only after it installs?
Then the permissions check stays open until that moment, and you decide when the request appears. Say no to reading texts and to accessibility every time. A file from outside a store has no listing to read first, so the pop-ups and Settings screens are your only preview.