A hand-picked guide to Android.
Open source apps worth studying, libraries worth using, projects worth starring, and people worth following.
Root and module framework for Android.
Terminal emulator and Linux environment for Android.
Dex to Java decompiler.
Reactive extensions for the JVM.
HTTP client for Android, JVM, and GraalVM.
Open source music streaming app across desktop and mobile.
Official architecture samples for common Android app patterns.
Type-safe HTTP API client for Android and JVM.
Privacy-first knowledge management app.
Popular charting library for Android.
Lightweight streaming front-end for Android.
Render After Effects animations on Android.
Mature image loading and caching library.
Barcode scanning library for Java and Android.
Memory leak detection for Android.
Private messenger with a large production Android codebase.
Use privileged Android APIs from regular apps via adb/root service.
Reverse engineering tool for Android APK files.
Official Jetpack Compose sample apps.
Mobile app security assessment framework.
Kodi media center codebase with Android support.
Android bindings for RxJava.
Compile-time dependency injection for Android and Java.
Install and update Android apps from upstream release sources.
Kernel-based Android root solution.
Material design inspiration app from a long-time Android designer.
End-to-end encrypted notes app.
Offline maps app built on OpenStreetMap data.
Open source email client formerly known as K-9 Mail.
Open source Android launcher.
Material Android front-end for YouTube.
Image loading for Android and Compose Multiplatform.
Flexible navigation drawer library.
Anki flashcards client for Android.
Private messenger built around no-user-identifier messaging.
Small, extensible logger for Android.
Modern JSON library for Kotlin and Java.
Feature-rich Android weather app.
Loop Habit Tracker for building recurring habits.
YouTube Music client for Android.
Runtime mobile exploration toolkit.
Free and open source Android ad blocker.
Production password manager and authenticator for Android.
Debug Android databases and shared preferences.
Polished MVVM sample app with Hilt, Flow, Room, and motion.
Privacy-friendly open source keyboard.
Material Design file manager for Android.
Full-featured Android package manager and app viewer.
Long-running open source podcast manager.
Kernel and system patching root solution.
Privacy-focused Chromium fork for Android.
Material You RSS reader for Android.
Cross-platform Mullvad VPN client including Android.
Static analysis for Kotlin.
Clean F-Droid client.
Compose UI elements, layouts, widgets, and demo screens.
Android cleaning and maintenance tool.
Encrypted notes and files app with mobile clients.
Material design file manager.
Scan APKs for endpoints, secrets, and URIs.
Circular progress button component.
Markdown, todo.txt, and plaintext editor for Android.
Large production sync client with real-world offline behavior.
Android tasks app continuing the Astrid lineage.
Customizable privacy-conscious Android keyboard.
Material You local music player.
Kotlin charting library for Android.
Prepare APKs for HTTPS inspection.
Colored logcat focused on a single app package.
Shizuku-powered Android app debloater.
Production privacy browser with a real modular app structure.
Cross-platform handwritten notes app.
Privacy-focused, full-featured Android email client.
Dependency license collection and UI for Android/KMP apps.
Modern Android and Compose tooltip library.
Native Android video player.
Android reverse-engineering workbench for VS Code.
No-root per-app firewall.
Official Proton VPN Android app.
Companion app spanning phone, Wear OS, and connected-device surfaces.
Lightweight confetti particle system.
Privacy-friendly Android photo and video gallery.
Tor connectivity app for Android.
Android video player built on libmpv.
SSH client for Android.
Write OS images to USB drives from Android.
High-traffic production Android client with mature product code.
Zoom and touch gestures for Android ImageView.
Sensor-driven wilderness and navigation toolkit.
Compose/KMP image loading wrapper for Glide, Coil, and Fresco.
Open source Android calendar app.
Official Jellyfin Android client.
Tracker and ad blocking controls for Android apps.
Container transform animations for views, fragments, and activities.
Interactive chart library for Android apps.
Remap hardware buttons on Android devices.
Matrix client using Jetpack Compose and the Matrix Rust SDK.
Official Tailscale Android client.
Dex to Java decompiler with a polished GUI; the daily driver for reading APKs.
Interactive HTTPS proxy — the go-to for inspecting and replaying Android app traffic.
Decode, rebuild, and sign APKs while preserving smali and resources.
JavaScript instrumentation toolkit — the de-facto runtime hooking standard.
Mobile Security Framework — automated static, dynamic, and API security testing for Android/iOS.
All-in-one Java/Android RE workbench bundling six decompilers.
Convert .dex to .jar so JVM decompilers can chew on it.
OWASP Mobile Application Security Testing Guide — the canonical reference for mobile testing.
Mobile Verification Toolkit — forensic acquisition for Android/iOS, originally used to hunt Pegasus.
Frida-powered runtime mobile exploration; bypasses, dumps, and probes without rebuilding the APK.
Pythonic Android binary analysis toolkit — APK, DEX, AXML.
Scan APKs for URIs, endpoints, API keys, and other secrets.
VS Code extension that stitches together jadx, Apktool, and Quark for an IDE-driven RE workflow.
Generic Android deobfuscator — virtually executes smali to fold reflection and string ops.
Patch APKs to disable certificate pinning so MITM proxies actually see the traffic.
Reference (dis)assembler for Dalvik bytecode.
Read-only forensic acquisition and decoder collection for Android devices.
LinkedIn's APK and source scanner for common Android vulnerabilities.
Security testing framework for Android — probe IPC, content providers, and the attack surface of a device.
Obfuscation-resistant Android malware scoring system with a rule DSL.
Runtime Mobile Security — a web UI on top of Frida for manipulating Android/iOS apps live.
Vulnerability scanner that flags risky API use and misconfigurations in APKs.
CTF-style Android app with flags covering the common mobile vuln classes.
Oversecured Vulnerable Android App — modern, broad coverage of Android-specific issues.
Intercept SSL/TLS with Frida; extract keys and dump decrypted traffic as PCAP in real time.
Taint-flow analysis for Android — precise data-flow tracking across the framework.
Damn Insecure & Vulnerable App — short, focused exercises for app pentesting.


















