Security
Last updated: September 19, 2026
We welcome further independent inspection of PizzaBin.
PizzaBin is an Android content blocker that enforces device-wide blocking of pornography across browsers and apps. It is built for users who want enforcement that holds up in practice, without breaking everyday phone functionality.
What This Page Covers
This page records verifiable details about the build PizzaBin currently distributes: the exact file published for download, how to confirm you hold that file, independent analysis of it, the checks the app applies before installing an update, why the app requires root access, and the Android permissions it declares.
The analysis cited here is produced by VirusTotal, Hybrid Analysis, and OPSWAT MetaDefender Cloud, independent services used as standard references across the security industry. VirusTotal and MetaDefender Cloud are multi-engine scanners that aggregate detection results across many antivirus engines; Hybrid Analysis performs automated behavioural analysis of the submitted file. All three reports are public and linked in full below, so the results can be read at source.
For how data is collected, stored, and shared, see the Privacy Policy. For short answers to common questions about how PizzaBin works, see the FAQ.
Support: support@pizzabinblocker.com
Current Public Build
These values describe the APK served by the Download button on this site, which is the same file published on the GitHub release below. The build / release date is when that APK was published, not the date of the third-party analysis reports.
| App label | PizzaBin |
| Version | 2.1.9 (versionCode 219) |
| Distribution | GitHub release v2.1.9 from scut093/pizzabinapk |
| Build / release date | 18 September 2026 (UTC) |
| SHA-256 | 69e4387632c285f0b605bf34460cf1fdae4ec345a27b33501fca0f992396e87f |
Verify Your Download
To confirm that the file you downloaded is the file described above, compute its SHA-256 and compare it with the value in the table:
- macOS:
shasum -a 256 pizzabin.apk - Linux:
sha256sum pizzabin.apk - Windows PowerShell:
Get-FileHash pizzabin.apk -Algorithm SHA256
If the values match, you hold the exact file that was submitted for the independent analysis below.
Independent Analysis
The file identified above was submitted to VirusTotal, Hybrid Analysis, and MetaDefender Cloud, with the following results:
- VirusTotal — 0/66 detections. View report
- Hybrid Analysis — UNDETECTED, AV 0/23. View report
- MetaDefender — No Threats Detected, 0/20 supported engines. View report
When a new APK ships, this section is updated with the new hash and fresh reports.
What the hash does and does not cover. The SHA-256 above identifies this exact file and nothing else. A later release will have a different hash, and the reports linked here do not extend to it. In-app updates are not checked against this value either — they are gated on signing-certificate identity and a higher versionCode, as described below.
How Updates Are Verified
Update integrity rests on signing-certificate identity rather than on a published file hash. Before the app installs an update, the updater requires all of the following:
- The download URL must use HTTPS.
- The package name must match the installed application.
- The signing certificate must match the installed application. This is a SHA-256 comparison of the signing certificate, not of the APK file.
- The versionCode must be strictly higher than the installed version, so downgrades are rejected.
- Android's own package installer independently refuses to replace an app with a differently signed build.
For precision: the sha256 field carried in the update metadata is logged rather than compared against the downloaded file. Signing-key identity is the integrity anchor here — an update signed with any other key cannot be installed over an existing PizzaBin install, whatever its metadata claims.
Why PizzaBin Uses Root
Root access lets PizzaBin apply blocking at the system level — across every browser and app on the device, rather than inside a single app — and keeps enforcement in place after a reboot. It also closes the bypass routes that app-level filters leave open: pointing Chrome's secure DNS at another provider, changing Private DNS under the Android Settings app, or adding a VPN profile that sends DNS elsewhere does not disable enforcement. Access to essential services, ordinary websites, and normal phone functionality is left intact.
PizzaBin is installed deliberately by the user on their own device, so the restriction is self-imposed. Enforcement strength is the product: users choose it precisely because a filter that is easy to switch off tends to get switched off.
Uninstall Protection
Uninstall protection is optional and inactive until the user turns it on; while it is off, PizzaBin uninstalls like any other Android app. Once enabled, removal runs through a typing gate: the user types out a series of paragraphs — at least roughly 300 words — before the app comes off, and root-level enforcement keeps the ordinary uninstall and bypass routes closed in the meantime. The friction is the purpose: the commitment is made in advance, while the user's judgement is clear.
If you need help removing PizzaBin from a device, email support@pizzabinblocker.com and we will walk you through it.
Permissions Declared by This Build
The permissions below are those declared in the manifest of the scanned APK.
| Permission | Purpose |
|---|---|
| QUERY_ALL_PACKAGES | List installed apps so they can be added to a blocklist or whitelist |
| INTERNET | Sign in, sync settings, and check for updates |
| REQUEST_INSTALL_PACKAGES | Install app updates delivered through the in-app updater |
| FOREGROUND_SERVICE+ DATA_SYNC, SPECIAL_USE | Keep enforcement running reliably rather than being killed in the background |
| RECEIVE_BOOT_COMPLETED | Restore enforcement after the device restarts, so a reboot is not a bypass |
| POST_NOTIFICATIONS | Show the status notification for background services |
| ACCESS_NETWORK_STATE | Detect connectivity changes |
| SYSTEM_ALERT_WINDOW | Draw the overlay used to enforce blocking and uninstall protection |
| PACKAGE_USAGE_STATS | Detect when a screen used to disable protection is opened, while protection is enabled |
| WAKE_LOCK | Hold the device awake briefly during enforcement work |
What the app does and does not collect is set out in the Privacy Policy.
Contact
For questions about anything on this page, including verification of a build or help removing the app, email support@pizzabinblocker.com.