70% of projects with high test coverage (80%+) face regressions in business logic — this is the statistic from our audits. The reason: tests cover UI and getters, not Use Cases and ViewModels. Typical scenario: you add a new feature, CI is green, but after merge, working functionality breaks. A mobile app codebase audit finds such "blind spots" and shows where tests are actually needed. Our experience diagnoses problems that remain hidden in 60% of projects until the first incident. We guarantee the report contains actionable recommendations, not general phrases.
How does a codebase audit prevent regressions?
Code review checks a single PR: style, logic, bugs. An audit answers the question: "Can we live with this code for the next two to three years, add features without constant regressions, onboard new developers in reasonable time?" It's an analysis of systemic technical debt, not point problems. Cyclic dependencies between modules occur in 40% of projects, hardcoded API keys in 30%. Without an audit, these numbers stay hidden until the first incident. According to the OWASP Mobile Security Testing Guide, such vulnerabilities are classified as High Risk.
What exactly do we check?
Architecture cohesion. We examine the dependency graph: are there cyclic dependencies between modules, are layer boundaries violated, does the UI directly depend on specific network libraries? For iOS — we check separation into feature modules or at least adherence to MVVM/VIPER within a single target. For Android — Clean Architecture with Use Cases, or everything dumped into an Activity. Tools: Xcode Dependency Graph, Android Studio Module Dependencies, ArchUnit for automated verification.
Test coverage. We look not only at the percentage but also at what is covered. 80% coverage on trivial getters and 10% on business logic is worse than 30% of correct tests on Use Cases and ViewModels. We check for integration tests (UI, XCUITest, Espresso), mocks for network dependencies, tests for edge cases (empty list, network error, timeout). In 70% of projects, test coverage of business logic does not exceed 20%, leading to regressions. Automated analysis reduces review time by 3-5 times compared to manual review.
Dependency management. CocoaPods vs SPM, Gradle catalogs, outdated versions. Libraries with known CVE — we check via OWASP Dependency-Check or a snapshot from pod outdated / ./gradlew dependencyUpdates. We pay special attention to libraries requesting excessive permissions (Analytics SDK, Ad SDK) — they may violate App Store/Play Store privacy policies.
Performance and memory leaks. Static analysis does not replace a profiler, but in 90% of cases it finds patterns: synchronous tasks on the main thread, image created without caching in a loop, URLSession created per-request instead of a singleton. For Flutter — const constructors not used where they should be, expensive computations in build(). Average memory leak frequency in large projects is 3-5 per 1000 lines of code.
Security. Automated analysis via MobSF (Mobile Security Framework) or Semgrep with mobile rules. We look for: hardcoded API keys in code or plist, logging of sensitive data, insecure IPC (exported Activities without permission), use of outdated algorithms (MD5, SHA1 for critical operations). We also check Code Signing configurations, provisioning profiles, Push Notifications settings (APNs/FCM), deep linking (Universal Links / App Links), and ATT (App Tracking Transparency). According to App Store Review Guidelines, user data must be handled with care — hardcoded credentials are a direct violation.
What tools do we use?
| Task | iOS | Android |
|---|---|---|
| Static analysis | SwiftLint, Periphery (unused code) | Detekt, Android Lint |
| Dependencies/CVE | pod audit + OWASP Dependency-Check |
OWASP Dependency-Check |
| Code complexity | SonarQube | SonarQube |
| Security | MobSF | MobSF |
| Memory leaks | Instruments (Leaks) | LeakCanary |
SonarQube integrates into CI and calculates cyclomatic complexity, code duplication, cognitive complexity. A function with complexity > 15 is a candidate for refactoring — this is not a matter of taste, but a measurable risk.
| Problem | Frequency in projects |
|---|---|
| Cyclic dependencies between modules | 40% |
| Test coverage of business logic < 20% | 70% |
| Outdated libraries with CVE | 5-8 on average per project |
| Memory leaks | 60% |
| Hardcoded API keys | 30% |
Why don't automated tools replace manual analysis?
Although tools like Periphery find unused code and MobSF identifies vulnerabilities, only a manual architecture audit can assess how technical debt will affect future development. In one project, we discovered a cyclic dependency that increased build time by 40% — the static analyzer didn't show it because dependencies were via reflection. Our experience prevents such situations.
How do we conduct an audit?
- Metrics collection — static analysis of the entire code, dependency graph, test coverage.
- Deep architecture review — identify cyclic dependencies, violations of Clean Architecture.
- Manual security check — review configurations, manifests, plists.
- Performance profiling — search for leaks and bottlenecks.
- Report creation — roadmap with risk assessment and priorities.
Using automated tools reduces analysis time by 3-5 times compared to manual review. Periphery for iOS finds unused functions, classes, protocols. In a large codebase, thousands of lines of dead code accumulate — which are read, maintained, and feared to be deleted.
What do you get as a result?
- Report with four levels: Critical (immediate fix — data leak, crasher), High (next sprint — architectural risk, security issue), Medium (technical debt, plan), Low (quality recommendations).
- Refactoring roadmap with risk assessment and priorities — what to refactor first, what can be postponed.
- Documentation of found issues and recommendations for resolution.
- List of outdated dependencies with CVE and migration versions.
- Recommendations for improving CI/CD to automate quality control.
Contact us for project assessment. Get a consultation on the audit — we will estimate timelines and scope individually. An audit without an action plan is a meaningless document, so we always give actionable recommendations.
Timelines — from 3 to 5 days for a medium-sized project (up to 200k lines). Large projects (300k+ lines, multiple platforms) — up to 2 weeks. Exact cost is calculated after reviewing the project. Budget savings on refactoring with our recommendations can reach 40% due to prioritization of critical issues.







