KuboCheck helps you examine links, QR codes, suspicious messages, installed apps, and Android security settings before you click, pay, reply, install, or share.
It shows the warning signs it finds, explains why they matter, and recommends practical next steps.
A convincing message, disguised link, or unfamiliar QR code can create pressure to pay, reply, install, or share information immediately. The warning signs are often small and easy to miss.
Choose what you want to inspect. KuboCheck looks for explainable warning signs, presents the evidence behind its assessment, and recommends what to do next.
Inspect a web address for suspicious structure, encoding, shortened links, IP-based destinations, obfuscation, insecure connections, and possible brand impersonation without opening the page.
Optional checks can add public domain-registration evidence and limited HTTPS redirect inspection.
Scan with the camera or choose a screenshot. KuboCheck reveals and assesses the destination before it is opened, including payment-specific guidance for recognized UPI QR codes.


Paste or share text from an SMS, email, or messaging app. KuboCheck looks for warning signs involving urgency, OTPs, passwords, payments, APK installation, KYC, digital-arrest threats, jobs, investments, electricity, and courier scams.
Each result includes a risk level, confidence, plain-language evidence, and recommended actions.
With explicit permission, KuboCheck can review received system SMS exposed by Android. Analysis runs locally, results are grouped by verdict, and retained details include clear reasons.
KuboCheck does not monitor SMS in the background and cannot send or reply to messages.
Review signals such as screen lock, security-patch age, encryption, USB debugging, developer options, Private DNS, unknown-source installation settings, and common root indicators through a weighted device-security score.
Review launchable apps visible to KuboCheck using signals such as currently granted sensitive permissions, enabled special access, installer source, and update age.
The findings explain risk indicators. They do not declare an application to be malware.


The Advanced Security Checklist combines a weighted, severity-aware score with practical Android security and privacy recommendations.
Compare a password with the Have I Been Pwned password corpus using a privacy-preserving partial-hash request. The password and complete hash stay on the device.
Use your own supported provider key to check an email address you own or are authorized to assess. The provider key is encrypted with Android Keystore.
Get prioritized actions for payment loss, exposed credentials, suspicious APK installation, or a link-only event, including access to official India reporting routes.
Keep encrypted scan history under a configurable retention policy, delete individual results, create PDF reports, and manually check GitHub for a newer full release.

Select a link, QR code, message, application, device setting, or exposure tool.
Provide only the input, permission, or optional network access needed for that check.
See the assessment, confidence, warning signs, and plain-language reasons.
Follow prioritized guidance, save or share a report, or delete the result.
Link structure, QR payloads, message text, supported SMS, installed-app signals, and device posture are analyzed locally. KuboCheck does not render submitted web pages.
Manual scan history uses AES-GCM encryption backed by Android Keystore. Retention can be set to 30 days, 90 days, or until deletion. Individual results and all local history can be deleted in the app.
The local passphrase protects this installation; it is not a cloud account. There is no recovery server, so resetting a forgotten passphrase deletes encrypted history and cached reports.

Feature availability can vary by Android release, device manufacturer, work-profile policy, granted permissions, and installer restrictions. Future Android versions may require KuboCheck updates as platform security and privacy rules change. Compatibility with every future Android version is not guaranteed without testing.
Explore the current Android testing build and review its release notes, checksum, and signing information on GitHub.
No. KuboCheck provides explainable safety assessments for supported inputs and device signals. It does not continuously monitor the device or prove that an app, sender, or destination is safe.
The default structural analysis is local and does not open the website. If you explicitly enable HTTPS and redirect inspection, KuboCheck sends limited HEAD requests but does not render or save page content.
No. You can paste or share an individual message without inbox access. Received system SMS review is a separate, user-started feature that requires explicit permission.
No. KuboCheck cannot access another app's private message database. Text from those services can be pasted or shared manually for analysis.
Manual scan history is encrypted on the device with an Android Keystore-backed key. You can configure retention, delete individual entries, or erase all local history.
No. Its account and passphrase are local to the installation. There is no cloud identity or recovery server.
Core analysis is local. Optional domain, HTTPS, password exposure, email exposure, and update checks require a network connection and disclose what they contact.
KuboCheck is designed for Android 8.0 and later today. Future platform changes may require an application update, particularly for restricted permissions such as SMS access.
No. A low-risk result means the supported checks did not find strong warning signs. It is not proof of safety.