NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev
Flutter RASP plugin for Android & iOS: detects rooted/jailbroken devices, Frida/Xposed hooking, emulators, debuggers, and app tampering with NDK-level detection.
Last release 22 days ago
16 Sep 2026
Ships fairly regularly
a new release about every 2 months
Most releases are documented
notes for 5 of 6 stable releases
Nothing withdrawn
no release was ever pulled
5 months old
6 releases · first in 2026
One column per month.
ARM64 Execute-Only Memory (XOM) `SIGSEGV`. Removed unsafe raw libc memory reads in the inline-hook detector (shield::detectInlineHooks()) that trigger
SIGSEGV. Removed unsafe raw libc memory reads in the inline-hook detector (shield::detectInlineHooks()) that triggered SIGSEGV (SEGV_ACCERR) on ARM64 XOM devices. Libc tampering is still detected via the raw-syscall vs libc comparison (detectHookedFileIO()) without memory faults.buildReport() used java.time.Instant (API 26+) without core-library desugaring; on API 24/25 it threw NoClassDefFoundError (an Error, not an Exception) on the worker thread and terminated the process. The report timestamp now uses SimpleDateFormat (ISO-8601 UTC), available on all supported API levels.SIGSEGV under concurrent checks. isJNIEnvIntact() and isTextSegmentWritable() parsed /proc/self/maps with the non-reentrant strtok(); an overlapping foreground check and background-monitoring tick could corrupt its shared state. Both now read the full maps file and parse it without strtok.fork()-based parent-debugger check removed. Forking from the multi-threaded ART runtime inherits locked mutexes and could deadlock/abort on some OEM/MDM devices. It was redundant with the raw-syscall TracerPid reads that remain.createJavaMap() now null-checks method IDs and clears pending exceptions, preventing an ART FatalError/abort under memory pressure.MethodChannel/EventChannel names (advance_root_detection/*) did not match the Dart and Android names (advanced_root_detection/*), so every call threw MissingPluginException and the guard blocked all iOS users. Channel names corrected.UIApplication.canOpenURL from a background queue; it now runs on the main thread.isJNIEnvIntact()/isTextSegmentWritable() read only the first 16 KB of /proc/self/maps; on apps whose maps exceed that (common with Flutter) libart.so/libshield.so lines were truncated, producing false "JNIEnv hooked" / "writable .text" blocks. The full file is now read.dlpi_name + large executable segment" check (Case 2) matched legitimate images on some devices. Removed; genuine Zygisk companion injection is still detected via its memfd//proc/self/fd mapping and the dl_iterate_phdr name scan.hasPrivilegedGroups() no longer flags GID 1000 (system) — legitimate system, platform-signed, and MDM/enterprise apps carry it. GID 0 (root) is still flagged.gadget/substrate substrings matched unrelated library paths; anchored to frida-gadget and libsubstrate.so. Default Frida/Substrate artifacts are still detected (Frida gadget is also matched by the frida signature).libhoudini (Intel's ARM→x86 translation layer used by x86 Chromebooks, x86 emulators, and the Windows Subsystem for Android) from the hook signatures — it is not a hooking framework and false-blocked those devices.system_root signature from the Magisk mount checks — it is a legitimate SAR mount path on Android 10+ and caused false blocks.127.0.0.1:27042 connect now uses an explicit 200 ms timeout instead of the ~21 s OS default, preventing the monitoring thread from stalling when loopback SYN packets are dropped (some VPN/firewall/MDM setups)./proc parsers hardened with additional bounds and d_reclen guards.RootDetectionGuard now blocks only on a critical-severity threat in a blocking category (privilegedAccess, runtimeManipulation, integrityViolation), a
RootDetectionGuard now blocks only on a critical-severity threat in a blocking category (privilegedAccess, runtimeManipulation, integrityViolation), and drives the blocked-screen message from that same set. Signals that also occur on clean, non-rooted devices are reported at high/medium and are surfaced but no longer trigger a block. Every definitive root/jailbreak indicator (su binary, Magisk daemon/socket/mounts/app-dir/properties, Zygisk injection, root-manager app, /system mounted read-write, Frida/Xposed hooks, wrong APK signer) is reported at critical, so genuinely rooted or jailbroken devices are still blocked.RootDetectionGuard blocked screen now shows a fixed user-facing message (the default "This device is rooted or jailbroken." text, or the provided blockedMessage) with a "Show error logs" link that opens a popup listing every blocking threat. Previously the first detected threat's raw description was shown as the headline, which could surface a non-blocking finding (e.g. an attached debugger) as the apparent block reason.isDebuggerPresent() check used a ptrace(PTRACE_TRACEME) self-attach that marked the process as traced by its parent and could not be undone from the tracee side, polluting the subsequent /proc/self/status TracerPid read with a non-zero parent pid. The check now relies solely on the non-destructive TracerPid read (0 when clean, the tracer pid when a debugger is attached).bypassInDebugMode flag on RootDetectionGuard — when set to true, the root/jailbreak check is skipped entirely in debug builds (kDebugMode == true), al
bypassInDebugMode flag on RootDetectionGuard — when set to true, the root/jailbreak check is skipped entirely in debug builds (kDebugMode == true), allowing installation and testing on normal (non-rooted) developer devices without triggering the blocked screen. Has no effect in profile or release builds.Shortened package description to comply with pub.dev 180-character limit
homepage, repository, and issue_tracker URLs to pubspec.yamlNothing published for this version
Initial release of advance_root_detection Flutter RASP plugin
advance_root_detection Flutter RASP pluginsu binaries, Magisk/Zygisk artifacts, test-keys, dangerous props, root manager packagesDebug.isDebuggerConnected, FLAG_DEBUGGABLE, TracerPid, native ptrace anti-attach/proc/self/maps scan, inline-hook detection, JNIEnv integrity, .text segment integrity, XOR-obfuscated stringsDYLD_INSERT_LIBRARIESsysctl P_TRACED, ptrace(PT_DENY_ATTACH)TARGET_OS_SIMULATOR, env vars, hardware modelperformCheck(), startMonitoring(), stopMonitoring(), verifyBeforeSensitiveOp(), threatStreamThreatReport, Threat, ThreatCategory, Severity, SecurityConfig, AndroidConfig, IOSConfig data modelsflutter_security_shield/methods) + EventChannel (flutter_security_shield/threats)Your coding agent can read these notes before it upgrades. Set up the MCP server →