Practical guide · verified against the real thing
How to tell if an app is safe before you install it
In one line: The pre-install check: what the developer listing, the permissions, the reviews and the install source each tell you — and the red flags that end the conversation.
App safety is decided before the install screen, not after. The good news: the evidence is all visible in five minutes, and the red flags are consistent across platforms. This is the check, in the order that catches the most problems fastest — it answers the "is this app safe?" question the only honest way: as a risk assessment, not a guarantee.
1. The install source is half the answer
The official Play Store vets apps continuously (automated scanning plus policy enforcement) and can remotely remove bad actors after the fact. That makes it the safest channel — not a guarantee, a distribution with recourse. Sideloaded APKs from websites and link-shortened "download" pages have none of that: no vetting, no removal mechanism, no update path — the entire suspicious-link threat model in an installer. The rule: if an app isn't on an official store, the burden of proof inverts, and "the modded premium version, free" is proof of the opposite — pirated-app repackaging is a classic malware costume, and the same reasoning as why free has a business model applies double when the "business model" is your bank credentials.
2. The developer listing: who is actually asking
Scroll past the icon to the developer line. A named company with a track record and other published apps is checkable in two taps (tap the name: their other apps, their website, how long they've existed). Brand-new developer + popular-app impersonation (the second "WhatsApp" with 50k installs) is the single most reliable red flag in the store. Impersonators survive on search typos — open store listings from the developer's official website link when the stakes are any higher than a torch app.
3. The permissions, asked in context
A torch app requesting contacts, a calculator wanting location, a game that must read SMS: permission-to-purpose mismatch is the loudest signal available, and Android shows the permission list right on the install page. Judge it the way the permission audit does: does this permission serve the app's actual job? Some mismatches have honest explanations (a camera app needing storage); most don't. And remember the install-page list is only the opening bid — apps accumulate permissions later, which is why the audit is a habit, not a ceremony.
4. Reviews, read for forensics
Ignore the star average; read the recent one-star reviews for the words that matter: "charged", "subscription", "permissions", "ads on lock screen", "my battery". A pattern of surprise-charging reviews on a flashlight is a business model, not a bug. Equally telling: a wall of five-star reviews posted within days, vague and grammatically uncanny — that's a review farm, and stores are imperfect at catching it. Review velocity against app age tells you whether popularity was earned.
5. After install: the confirmation checks
First launch is evidence too: an app that immediately demands account creation before showing any function, or floods full-screen ads in its first minute, has told you what it is — uninstall while the decision is cheap. Confirm Play Protect is on (it scans continuously), and give the app its first week under the privacy pass: check what permissions it actually claimed versus what the install page promised. The strongest safety tool in the whole piece is the one nobody markets: willingness to delete. Apps earn their place on the phone the same sources earn their place in an article — by behaving.
Next