IPAScope is published by Overnight Success AI, Inc.
IPAScope is an offline iOS/macOS app security scanner, available as both a
native Mac app and the ipascan command-line tool. It inspects an
.ipa or .app bundle's entitlements, provisioning profile,
Info.plist configuration, privacy manifest, binary encryption status, embedded
endpoints, cryptography, known-vulnerable SDKs, and hardcoded secrets, then maps
findings to the OWASP MASVS framework — entirely on-device. An optional
AI-generated pentest report can be produced using your own provider API key.
For bug reports, feature requests, or general questions, email kevin@overnightsuccess.ai.
Does scanning require an internet connection?
No. The static scan runs 100% offline. A network connection is only used if you
choose to generate an AI report, sent directly to your configured provider using
your own API key.
What do I get for $129?
The full-featured Mac app (static analysis, optional dynamic analysis, and AI
report generation) plus the ipascan command-line tool — the same
engine, for CI pipelines, scripting, or batch-auditing a whole portfolio of
apps. One payment, unlocked forever.
Is there a subscription or recurring charge?
No. IPAScope Pro (signed and notarized by WANDERLUV PLATFORMS LLC) is a
one-time purchase, unlocked with an offline license key that works forever —
no account, no recurring billing.
How do I set up dynamic analysis?
Dynamic analysis — installing a scanned app on your own jailbroken Corellium
instance and observing it with Frida — is optional and off by default. In the
Mac app, open Settings (⌘,) and expand "Advanced: Dynamic Analysis
(Corellium)." It walks through every step in order: creating a Corellium
account, installing Docker, and starting the sidecar.