GuideHQ

How do I check an app is safe before I install it?

The checks that take a minute in an app store, the permission requests that should stop you, and why the subscription terms matter more than the malware risk.

Difficulty
beginner
Time
10 min
Read
3 min

Short answer

Check the developer name against the organisation you expect, read the recent one-star reviews rather than the average, look at what permissions it wants and whether they make sense, and check the subscription terms before installing. On modern phones, the commonest harm is a subscription trap, not a virus.

The official stores do filter out most outright malicious software. What they do not filter is misleading apps: clones of popular ones, free trials that become expensive subscriptions, and apps that harvest far more data than they need.

Step by step

  1. Check the developer, not the app name.Tap the developer name to see what else they publish. A bank's app is published by the bank; a clone is published by a name you have never heard of with twenty other apps.
  2. Reach the app from the organisation's own website where possible.Banks, councils, utilities and delivery firms link to their genuine app. That defeats clones entirely, which is the main risk for anything handling money.
  3. Read the recent one and two-star reviews.The average is easily inflated. The recent negative reviews tell you about a subscription that cannot be cancelled, an update that broke everything, or a paywall behind a 'free' label.
  4. Look at the permissions before installing.Both stores list what the app can access. A torch or calculator asking for contacts, location or microphone is the classic signal. Ask whether each permission is needed for the function you want.
  5. Read the price line carefully.'Free' with in-app purchases can mean a three-day trial that renews at a high weekly rate. The store lists the in-app purchase prices; check them before installing rather than after.
  6. Check the data collection summary.Both major stores require a privacy summary showing what is collected and whether it is linked to you. Compare it against what the app plausibly needs to function.
  7. Prefer the boring option.For common jobs — scanning documents, editing photos, reading PDFs — the tool built into the phone usually does it, free, without permissions or a subscription.
  8. Review afterwards, not just before.Grant permissions at first use rather than in advance, and revisit the permission list occasionally. Anything you no longer use should be deleted rather than left installed.

Tips

  • Only install from the official store on a phone. Sideloaded apps from a link in a message are how the genuinely dangerous ones arrive.
  • On a computer, download from the software's own site or the platform's store, never from a search advert — paid search results for popular software are a known route for bundled junk.
  • If an app demands accessibility permissions on a phone, be very careful. Those permissions allow it to read and control the screen.

Common mistakes

  • Judging by the star rating and download count — Both are easily bought. A clone can display a high average and a large number while the recent reviews describe a subscription trap.
  • Granting every permission at install to make it work — Most apps function with far fewer than they request. Denying and seeing what breaks is a reasonable approach on a phone, since permissions can be granted later.

If it doesn't work

Installed an app that immediately demands a subscription

Cause: The store listing described it as free with in-app purchases — Fix: Delete it and cancel the trial through the store's subscription list, not the app. Deleting the app alone does not cancel a subscription.

An app keeps asking for location in the background

Cause: It wants continuous tracking rather than occasional use — Fix: Set it to 'while using' or deny entirely. Very few apps genuinely need background location; navigation and fitness tracking are the honest exceptions.

Suspect the app is a clone of a real service

Cause: Search results in stores are gameable — Fix: Delete it, change the password for the real service if you signed in, and install the genuine one via a link from the organisation's website.

Questions people ask

Do I need antivirus on a phone?

For a phone kept updated and installing only from the official store, no. The security products sold for phones mostly duplicate features the phone already has. Updates and permission discipline matter far more.

Are paid apps safer than free ones?

Somewhat, in that the business model is visible. A free app has to make money somehow, and the two usual answers are advertising with data collection, or a subscription.

Written and maintained by the GuideHQ editorial team. More in Technology.