Bug Description
False positive: Mortgage calculator flagged for root/jailbreak detection due to financial terminology in code, despite performing only mathematical calculations with no actual payment processing or sensitive data handling.
To Reproduce
Steps to reproduce the behavior:
- Run npx rnsec on a React Native project
- Have components with names/content containing keywords like "payment", "interest"
- Components only perform calculations (may call APIs for calculation logic, but no payment processing)
- See HIGH severity warning: "Sensitive app (banking/fintech/healthcare) without root/jailbreak detection"
Expected Behavior
The tool should differentiate between:
- Actual payment/financial transaction processing should flag for root detection
- Financial calculators/mathematical operations should not be flagged
Actual Behavior
Mortgage calculator components were flagged as HIGH severity requiring root/jailbreak detection based on keyword detection alone.
Environment
- rnsec version: 1.0.0
- Node version: v22.12.0
- OS: macOS 26.0.1
- Expo version: Expo SDK 54.0.1
Command Output
HIGH Sensitive app (banking/fintech/healthcare) without root/jailbreak detection
.../src/locales/index.ts:1
HIGH Sensitive app (banking/fintech/healthcare) without root/jailbreak detection
.../components/CalculatorForm/index.tsx:1
HIGH Sensitive app (banking/fintech/healthcare) without root/jailbreak detection
.../components/CalculatorResult/index.tsx:1
Additional Context
The flagged components are part of a mortgage calculator feature that:
- Takes user input (down payment, finance period)
- Performs calculations (may call backend APIs for complex formulas)
- Displays results
- Does NOT process payments, store credentials, or handle sensitive financial data
The tool appears to use keyword-based pattern matching to detect financial apps, which creates false positives for calculator utilities.
I think context-aware analysis could help here. The tool could search for actual indicators of financial apps that need root detection, like payment sdks (Stripe, Paypal, etc), banking apis, transaction processing code.
This way it could distinguish between apps with financial calculators vs apps that actually handle money/transactions.
Bug Description
False positive: Mortgage calculator flagged for root/jailbreak detection due to financial terminology in code, despite performing only mathematical calculations with no actual payment processing or sensitive data handling.
To Reproduce
Steps to reproduce the behavior:
Expected Behavior
The tool should differentiate between:
Actual Behavior
Mortgage calculator components were flagged as HIGH severity requiring root/jailbreak detection based on keyword detection alone.
Environment
Command Output
HIGH Sensitive app (banking/fintech/healthcare) without root/jailbreak detection .../src/locales/index.ts:1 HIGH Sensitive app (banking/fintech/healthcare) without root/jailbreak detection .../components/CalculatorForm/index.tsx:1 HIGH Sensitive app (banking/fintech/healthcare) without root/jailbreak detection .../components/CalculatorResult/index.tsx:1Additional Context
The flagged components are part of a mortgage calculator feature that:
The tool appears to use keyword-based pattern matching to detect financial apps, which creates false positives for calculator utilities.
I think context-aware analysis could help here. The tool could search for actual indicators of financial apps that need root detection, like payment sdks (Stripe, Paypal, etc), banking apis, transaction processing code.
This way it could distinguish between apps with financial calculators vs apps that actually handle money/transactions.