device_shield 0.1.0
device_shield: ^0.1.0 copied to clipboard
Runtime device-security checks for Flutter apps: root, jailbreak, emulator, debugger and mock-location detection, plus screen capture protection.
device_shield
Know when your Flutter app is running somewhere it shouldn't.
Root, jailbreak, emulator, debugger and mock-location detection, plus screen
capture protection, for Android and iOS.
Documentation · Quick start · API reference · Roadmap
Features #
- 🛡️ Five device checks. Root (Android), jailbreak (iOS), emulator or simulator, attached debugger, and mock location.
- 🔎 Evidence, not just a boolean. Every result lists the signals that fired, each rated strong, medium or weak.
- ⚖️ Fewer false positives. Weak signals common on custom ROMs, emulators and debug builds never decide a result on their own.
- 📸 Screen capture. Block screenshots and screen recording, hide content in the app switcher, and get notified when a screenshot is taken.
- ✅ Honest results. A check that doesn't apply says so, and a check that
can't run returns
failed. Nothing throws, and nothing silently passes. - 🔒 Private by design. No network requests, nothing stored, no data collected.
Platform support #
| Feature | Android | iOS |
|---|---|---|
| Root detection | ✅ | — |
| Jailbreak detection | — | ✅ |
| Emulator / simulator detection | ✅ | ✅ |
| Debugger detection | ✅ | ✅ |
| Mock location detection | ✅ | Limited |
| Screenshot detection | ✅ API 34+ | ✅ |
| Screen recording detection | — | ✅ |
| Screenshot protection | ✅ | Experimental |
| App-switcher protection | ✅ | ✅ |
Requirements: Flutter 3.44.8+, Android API 21+, iOS 15.0+.
Installation #
flutter pub add device_shield
On iOS, set your deployment target to 15.0 or later. On Android there's nothing to add: the plugin's manifest entries merge into your app automatically. For the optional location-based mock-location signals, your app requests location permission itself; see Android setup and iOS setup.
Usage #
Run every check #
import 'package:device_shield/device_shield.dart';
final report = await DeviceShield.check();
if (report.root.detected || report.jailbreak.detected) {
// e.g. hide sensitive screens or ask for extra verification
}
if (report.anyFailed) {
// A check couldn't run. Treat the report as incomplete.
}
There's nothing to initialise, and no method throws.
Inspect the evidence #
final root = await DeviceShield.checkRoot();
switch (root.status) {
case CheckStatus.detected:
print(root.signals); // [su_binary_path (strong)]
case CheckStatus.clear:
print('Clear');
case CheckStatus.notApplicable:
print('Not an Android device');
case CheckStatus.failed:
print('Could not check: ${root.error}');
}
A check is detected when at least one strong signal fires, or two medium ones. Every signal and its strength is listed in the signals reference.
Protect sensitive screens #
// When the screen opens:
await DeviceShield.setScreenshotProtection(true);
// When it closes:
await DeviceShield.setScreenshotProtection(false);
// Hide content in the app switcher / Recents:
await DeviceShield.setAppSwitcherProtection(true);
Both return a ProtectionResult: applied, unsupported or failed.
React to screenshots and recording #
DeviceShield.screenshots.listen((_) {
// The user took a screenshot.
});
DeviceShield.screenRecordingChanges.listen((isRecorded) {
// iOS: recording or mirroring started (true) or stopped (false).
});
See the example app for every feature on one screen.
Security model #
These checks run on a device the user controls, so a determined attacker can hide root or hook the checks themselves (Magisk DenyList, Shamiko, Frida). Treat the results as risk signals that raise the cost of tampering and let your app adapt, not as proof.
For hard guarantees, pair device_shield with server-verified attestation
(Play Integrity,
App Attest), and
never let a client-side result grant access on its own. More in the
security model.
Verification status #
Every check and Android protection has been verified on an Android 17 emulator, and every check on the iOS 26.5 Simulator. Physical devices, rooted or jailbroken devices, and iOS screenshot blocking (which the Simulator can't show) haven't been verified yet. Details are on the platform support page.
Roadmap #
Coming soon: runtime hook detection (Frida, Xposed), app integrity (Play Integrity / App Attest), developer options and overlay detection, Android 15 screen-recording detection, and improved iOS mock location. See the roadmap.
Contributing #
Issues and pull requests are welcome.
git clone https://github.com/Vikaskumar75/device-shield.git
cd device-shield
app/tool/setup.sh # checks and installs prerequisites
app/tool/check.sh # runs everything CI runs
Prerequisites: Flutter 3.44.8, Xcode 16+, the Android SDK with JDK 17+,
Node.js 22.12+ (docs site), and the GitHub CLI. setup.sh reports what's
missing and installs the command-line tools with Homebrew. The full table,
repository layout and coding rules are in
CONTRIBUTING.md.
License #
BSD 3-Clause. See LICENSE.
