Security

Last updated: September 19, 2026

We welcome further independent inspection of PizzaBin.

PizzaBin is an Android content blocker that enforces device-wide blocking of pornography across browsers and apps. It is built for users who want enforcement that holds up in practice, without breaking everyday phone functionality.


What This Page Covers

This page records verifiable details about the build PizzaBin currently distributes: the exact file published for download, how to confirm you hold that file, independent analysis of it, the checks the app applies before installing an update, why the app requires root access, and the Android permissions it declares.

The analysis cited here is produced by VirusTotal, Hybrid Analysis, and OPSWAT MetaDefender Cloud, independent services used as standard references across the security industry. VirusTotal and MetaDefender Cloud are multi-engine scanners that aggregate detection results across many antivirus engines; Hybrid Analysis performs automated behavioural analysis of the submitted file. All three reports are public and linked in full below, so the results can be read at source.

For how data is collected, stored, and shared, see the Privacy Policy. For short answers to common questions about how PizzaBin works, see the FAQ.

Support: support@pizzabinblocker.com


Current Public Build

These values describe the APK served by the Download button on this site, which is the same file published on the GitHub release below. The build / release date is when that APK was published, not the date of the third-party analysis reports.

App labelPizzaBin
Version2.1.9 (versionCode 219)
DistributionGitHub release v2.1.9 from scut093/pizzabinapk
Build / release date18 September 2026 (UTC)
SHA-25669e4387632c285f0b605bf34460cf1fdae4ec345a27b33501fca0f992396e87f

Verify Your Download

To confirm that the file you downloaded is the file described above, compute its SHA-256 and compare it with the value in the table:

  • macOS: shasum -a 256 pizzabin.apk
  • Linux: sha256sum pizzabin.apk
  • Windows PowerShell: Get-FileHash pizzabin.apk -Algorithm SHA256

If the values match, you hold the exact file that was submitted for the independent analysis below.

Independent Analysis

The file identified above was submitted to VirusTotal, Hybrid Analysis, and MetaDefender Cloud, with the following results:

  • VirusTotal — 0/66 detections. View report
  • Hybrid Analysis — UNDETECTED, AV 0/23. View report
  • MetaDefender — No Threats Detected, 0/20 supported engines. View report

When a new APK ships, this section is updated with the new hash and fresh reports.

What the hash does and does not cover. The SHA-256 above identifies this exact file and nothing else. A later release will have a different hash, and the reports linked here do not extend to it. In-app updates are not checked against this value either — they are gated on signing-certificate identity and a higher versionCode, as described below.


How Updates Are Verified

Update integrity rests on signing-certificate identity rather than on a published file hash. Before the app installs an update, the updater requires all of the following:

  • The download URL must use HTTPS.
  • The package name must match the installed application.
  • The signing certificate must match the installed application. This is a SHA-256 comparison of the signing certificate, not of the APK file.
  • The versionCode must be strictly higher than the installed version, so downgrades are rejected.
  • Android's own package installer independently refuses to replace an app with a differently signed build.

For precision: the sha256 field carried in the update metadata is logged rather than compared against the downloaded file. Signing-key identity is the integrity anchor here — an update signed with any other key cannot be installed over an existing PizzaBin install, whatever its metadata claims.


Why PizzaBin Uses Root

Root access lets PizzaBin apply blocking at the system level — across every browser and app on the device, rather than inside a single app — and keeps enforcement in place after a reboot. It also closes the bypass routes that app-level filters leave open: pointing Chrome's secure DNS at another provider, changing Private DNS under the Android Settings app, or adding a VPN profile that sends DNS elsewhere does not disable enforcement. Access to essential services, ordinary websites, and normal phone functionality is left intact.

PizzaBin is installed deliberately by the user on their own device, so the restriction is self-imposed. Enforcement strength is the product: users choose it precisely because a filter that is easy to switch off tends to get switched off.

Uninstall Protection

Uninstall protection is optional and inactive until the user turns it on; while it is off, PizzaBin uninstalls like any other Android app. Once enabled, removal runs through a typing gate: the user types out a series of paragraphs — at least roughly 300 words — before the app comes off, and root-level enforcement keeps the ordinary uninstall and bypass routes closed in the meantime. The friction is the purpose: the commitment is made in advance, while the user's judgement is clear.

If you need help removing PizzaBin from a device, email support@pizzabinblocker.com and we will walk you through it.


Permissions Declared by This Build

The permissions below are those declared in the manifest of the scanned APK.

PermissionPurpose
QUERY_ALL_PACKAGESList installed apps so they can be added to a blocklist or whitelist
INTERNETSign in, sync settings, and check for updates
REQUEST_INSTALL_PACKAGESInstall app updates delivered through the in-app updater
FOREGROUND_SERVICE+ DATA_SYNC, SPECIAL_USEKeep enforcement running reliably rather than being killed in the background
RECEIVE_BOOT_COMPLETEDRestore enforcement after the device restarts, so a reboot is not a bypass
POST_NOTIFICATIONSShow the status notification for background services
ACCESS_NETWORK_STATEDetect connectivity changes
SYSTEM_ALERT_WINDOWDraw the overlay used to enforce blocking and uninstall protection
PACKAGE_USAGE_STATSDetect when a screen used to disable protection is opened, while protection is enabled
WAKE_LOCKHold the device awake briefly during enforcement work

What the app does and does not collect is set out in the Privacy Policy.


Contact

For questions about anything on this page, including verification of a build or help removing the app, email support@pizzabinblocker.com.

FAQ•About PizzaBin•Privacy Policy