App Intel

AltMap: Bug Bounty & Pentest

LiveAppRiser3 apps · 716 installsToolsFree · contains adsIn-app purchases: $3.29 - $99.99 per itemcom.appriser.altmap

Advanced web vulnerability, SQLi, and XSS scanner for bug bounty hunters.

Alert me★ WatchOpen in Play ↗
Total installs
153
exact · Play shows 100+
Installs / day
—
measured after our second crawl (about a day)
Rating
—★
— ratings · — reviews
Released
24 May 2026
5mo ago
Last update
27 Aug 2026
v1.9 · 1mo ago
Countries
—
not checked yet

Install history

exact counter from Google Play
Not enough history yet — check back tomorrow
Not enough history yet — check back tomorrow

Installs per day · last 90 days

Not enough history yet — check back tomorrow

Change timeline

No changes recorded yet. We compare every crawl with the previous one and list title, icon, screenshots, description, version, price and availability changes here.

Country availability

Availability has not been checked for this app yet. “Check all countries” looks the app up in about 140 Google Play storefronts and shows where it is live, listed but not installable, or missing — plus any country-specific (custom) store listings.

Top countries

Country data will be available soon.

We estimate where downloads come from using the app’s position in Google Play’s top charts in about 140 countries. This app is not in any chart we have collected yet; the estimate appears as soon as it is.

Top chart positions

Not in any tracked top chart.

App manifest

Read this app's manifest from Google Play: permissions, declared SDKs, components and AdMob app ID. Saved analysis appears here automatically.

Manifest analysis reads only the required APK ranges. Base APK downloads may need separate device splits to install.

Data safety

declared by the developer on Google Play
  • Shares data with third parties Personal info
  • Collects data Personal info
  • Data is encrypted in transit

This is the developer's own declaration, summarised from the Play listing. The permissions below show what the app is technically able to access.

Permissions

12 in 3 groups
4 Sensitive4 Notable4 Routine

What this app can do with your phone

  • Read photos, videos, and other files saved in your phone's shared storage
  • Add, change or delete photos, videos and other files in your phone's storage
Photos/Media/FilesSensitive2

Access to photos, videos, music and other files stored on your device

  • Read photos, videos, and other files saved in your phone's shared storageread the contents of your USB storage · READ_EXTERNAL_STORAGE
  • Add, change or delete photos, videos and other files in your phone's storagemodify or delete the contents of your USB storage · WRITE_EXTERNAL_STORAGE
StorageSensitive2

Access to files, photos and media saved on your phone's storage

  • Read photos, videos, and other files saved in your phone's shared storageread the contents of your USB storage · READ_EXTERNAL_STORAGE
  • Add, change or delete photos, videos and other files in your phone's storagemodify or delete the contents of your USB storage · WRITE_EXTERNAL_STORAGE
OtherNotable8

Access to miscellaneous device features that don't fit other categories

  • Change how your phone connects to networks, like switching connections on or offchange network connectivity · CHANGE_NETWORK_STATE
  • Receive data sent to all devices on your Wi-Fi network, which uses more batteryallow Wi-Fi Multicast reception · CHANGE_WIFI_MULTICAST_STATE
  • Connect to or disconnect from Wi-Fi networks and change saved Wi-Fi settingsconnect and disconnect from Wi-Fi · CHANGE_WIFI_STATE
  • Keep your phone's processor or screen from going to sleep, which can use more batteryprevent device from sleeping · WAKE_LOCK
  • Check whether you are online and whether you use Wi-Fi or mobile dataview network connections · ACCESS_NETWORK_STATE
  • Connect to the internet to load content and send datafull network access · INTERNET
  • Check with Google Play that you got this app legitimatelyGoogle Play license check · com.android.vending.CHECK_LICENSE
  • Receive push messages sent from the app's servers over the internetreceive data from Internet · com.google.android.c2dm.permission.RECEIVE

Sensitive = can reach personal data, location, camera/mic or act on your behalf. Notable = changes how your device behaves. Routine = normal for almost every app. Source: Google Play's permission list for all versions of this app.

Store listing

Full description
AltMap: Web Pentesting in Your Pocket Transform your Android device into a desktop-grade web application vulnerability scanner. Designed specifically for ethical hackers, bug bounty hunters, and security researchers, AltMap automates the heavy lifting of web security auditing so you can hunt for bounties from anywhere. With our massive Version 1.6 update, AltMap introduces advanced SQL Injection and XSS engines capable of bypassing WAFs and intercepting background network traffic to find web vulnerabilities that traditional scanners miss. 🔥 KEY FEATURES 🔥 📚 10,000+ Vulnerability Templates (CVEs) • Instantly scan web targets against a massive, constantly updated database of over 10,000 known vulnerabilities, exposures, and misconfigurations. • Custom Templates: Write and edit your own custom YAML templates directly in the app to test for proprietary vulnerabilities and zero-days. 🛡️ Advanced SQL Injection Engine • Deep-scan URL parameters and POST data with highly customizable risk, level, and depth settings. • Equip 12 built-in tamper scripts to bypass Web Application Firewalls (WAFs), including space2comment, apostrophemask, base64encode, randomcase, and more. • Configure scans to stop on the first vulnerability found, or silently collect all vulnerabilities for a comprehensive bug bounty report. 👾 Live XSS Scanner & Auto-Crawler • Manual Mode: Test payloads directly inside a live, floating browser. Inject payloads with a single tap and verify JS execution on the fly! • Auto Mode: Set your crawl depth and let the scanner automatically traverse links and inject Cross-Site Scripting (XSS) payloads across the entire target application. 🤖 Smarter "JS Crawl" with WebView Interception Traditional scanners miss modern web apps. AltMap utilizes a hidden WebView engine during automated SQL and XSS scans to execute JavaScript, intercept background AJAX/Fetch network requests, and extract hidden forms—ensuring no parameter goes untested. ⚡ Assisted Scans & Automation Orchestration • Smart Target Profiling: Automatically extracts keywords and technologies from your target URL/Domain to instantly find the exact CVE templates you need. • Orchestrate massive Full Scans from a single dialog: run your matched templates, SQL injection, and XSS scans simultaneously! • Granular control over your bulk scans with customizable thread counts, rate limits, import from csv, batch processing and campaign defined bullk scans. ## Upcoming / TODOs - [ ] **SQL Scanner Engine**: Investigate and fix false positive results reported by the SQL scanner. - [ ] **Vuln Scanner Flows**: Fix and improve the flow templates for the Vulnerability Scanner to ensure robust payload execution and detection. ⚠️ LEGAL DISCLAIMER & TERMS OF USE AltMap is a professional network auditing and penetration testing tool designed exclusively for ethical hackers, bug bounty hunters, and system administrators. You may only use this tool on networks, web applications, and infrastructure that you own, or where you have been granted explicit, documented permission to test. Unauthorized access or scanning of third-party networks is strictly prohibited and illegal. The developers of AltMap assume no liability and are not responsible for any misuse, damage, or legal consequences caused by this application.

What's new

Fixed union sql injection false positive case. Added Bug Reporting. Fixed errors in assisted scan.

Growing in Tools

Category →