# Photoroom

状态：active
Platform：android
Package：com.photoroom.app
Version：2026.24.01
Opportunity：2026-06-10-photoroom

## 摘要

- 包类型：xapk，inner APK 数：36
- 引擎 / 框架：native
- SDK 线索：adjust, amplitude, facebook, firebase, revenuecat
- Endpoint candidates：80
- 结论口径：本报告只基于静态 ZIP / Manifest / 字符串证据；不代表真实运行路径已验证。

## 直接证据

- [high] Manifest package id is com.photoroom.app（source: `AndroidManifest.xml`，status: `verified`）
- [high] Manifest declares 27 permissions（source: `AndroidManifest.xml`，status: `verified`）
- [high] Engine/framework markers: native（source: `APK file inventory`，status: `verified`）
- [high] Static strings include 80 endpoint candidates（source: `Text/string scan`，status: `verified`）
- [high] Package contains 56 native libraries（source: `APK file inventory`，status: `verified`）

## 推断

- [medium] SDK markers suggest: adjust, amplitude, facebook, firebase, revenuecat（source: `Manifest, filenames, and text strings`，status: `inferred`）

## 权限和组件

### 权限

- `android.permission.ACCESS_ADSERVICES_AD_ID`
- `android.permission.ACCESS_ADSERVICES_ATTRIBUTION`
- `android.permission.ACCESS_ADSERVICES_CUSTOM_AUDIENCE`
- `android.permission.ACCESS_ADSERVICES_TOPICS`
- `android.permission.ACCESS_NETWORK_STATE`
- `android.permission.ACCESS_WIFI_STATE`
- `android.permission.CAMERA`
- `android.permission.DETECT_SCREEN_CAPTURE`
- `android.permission.FOREGROUND_SERVICE`
- `android.permission.FOREGROUND_SERVICE_MEDIA_PROJECTION`
- `android.permission.HIGH_SAMPLING_RATE_SENSORS`
- `android.permission.INTERNET`
- `android.permission.POST_NOTIFICATIONS`
- `android.permission.READ_EXTERNAL_STORAGE`
- `android.permission.READ_MEDIA_IMAGES`
- `android.permission.RECEIVE_BOOT_COMPLETED`
- `android.permission.RECORD_AUDIO`
- `android.permission.REORDER_TASKS`
- `android.permission.VIBRATE`
- `android.permission.WAKE_LOCK`
- `android.permission.WRITE_EXTERNAL_STORAGE`
- `com.android.vending.BILLING`
- `com.google.android.c2dm.permission.RECEIVE`
- `com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE`
- `com.google.android.gms.permission.AD_ID`
- `com.google.android.providers.gsf.permission.READ_GSERVICES`
- `com.photoroom.app.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION`

### 组件

- Activities：androidx.credentials.playservices.HiddenActivity, androidx.test.core.app.InstrumentationActivityInvoker$BootstrapActivity, androidx.test.core.app.InstrumentationActivityInvoker$EmptyActivity, androidx.test.core.app.InstrumentationActivityInvoker$EmptyFloatingActivity, com.android.billingclient.api.ProxyBillingActivity, com.android.billingclient.api.ProxyBillingActivityV2, com.braze.push.NotificationTrampolineActivity, com.braze.ui.BrazeWebViewActivity, com.braze.ui.activities.ContentCardsActivity, com.facebook.CustomTabActivity, com.facebook.CustomTabMainActivity, com.facebook.FacebookActivity, com.google.android.gms.auth.api.signin.internal.SignInHubActivity, com.google.android.gms.common.api.GoogleApiActivity, com.google.android.play.core.common.PlayCoreDialogWrapperActivity, com.google.firebase.auth.internal.GenericIdpActivity, com.google.firebase.auth.internal.RecaptchaActivity, com.photoroom.application.LaunchActivity, com.photoroom.application.MainActivity, com.photoroom.components.aibackgroundui.ui.AiBackgroundActivity, com.photoroom.components.aiimages.ui.AiImagesHostActivity, com.photoroom.components.backgroundremover.ui.BackgroundRemoverActivity, com.photoroom.components.batch.ui.BatchActivity, com.photoroom.components.exportui.ui.ExportV4Activity, com.photoroom.components.insert.ui.InsertActivity, com.photoroom.components.maskeditor.ui.EditMaskActivity, com.photoroom.components.productbundle.ui.ProductBundleActivity, com.photoroom.components.projectpreview.ui.ProjectPreviewActivity, com.photoroom.components.settings.ui.SettingsActivity, com.photoroom.components.upscale.ui.UpscaleActivity, com.photoroom.components.upsell.managesubscription.ui.ManageSubscriptionActivity, com.photoroom.components.videoplayer.ui.VideoActivity, com.photoroom.features.app_status.AppStatusActivity, com.photoroom.features.background_chooser.BackgroundChooserActivity, com.photoroom.features.brandkit.home.BrandKitHomeActivity, com.photoroom.features.camera.ui.CameraActivity, com.photoroom.features.churn.ChurnActivity, com.photoroom.features.coupon.ui.CouponActivity, com.photoroom.features.debugmenu.DebugActivity, com.photoroom.features.edit_project.text_concept.ui.ResizeProjectActivity, com.photoroom.features.editor.ui.EditorActivity, com.photoroom.features.export.ui.ExportActivity, com.photoroom.features.home.ui.TemplateCustomSizeActivity, com.photoroom.features.login.email.ui.EmailLoginActivity, com.photoroom.features.onboarding.ui.OnboardingActivity, com.photoroom.features.preferences.ui.PreferencesAccountActivity, com.photoroom.features.team.join.ui.TeamJoinActivity, com.photoroom.features.team.member.TeamMemberActivity, com.photoroom.features.team.people.ui.TeamPeopleActivity, com.photoroom.platform.alertui.ui.AlertActivity, com.photoroom.util.test.DummyActivity, com.revenuecat.purchases.amazon.purchasing.ProxyAmazonBillingActivity, com.shakebugs.shake.ui.ChatLauncherActivity, com.shakebugs.shake.ui.ShakeActivity, com.shakebugs.shake.ui.permissions.RequestPermissionActivity, io.didomi.sdk.notice.ctv.TVNoticeDialogActivity, io.didomi.sdk.preferences.ctv.TVPreferencesDialogActivity, io.intercom.android.sdk.activities.IntercomCarouselActivity, io.intercom.android.sdk.activities.IntercomNoteActivity, io.intercom.android.sdk.activities.IntercomSheetActivity, io.intercom.android.sdk.helpcenter.articles.IntercomArticleActivity, io.intercom.android.sdk.helpcenter.search.IntercomArticleSearchActivity, io.intercom.android.sdk.lightbox.LightBoxActivity, io.intercom.android.sdk.m5.IntercomRootActivity, io.intercom.android.sdk.m5.bubble.IntercomBubbleActivity, io.intercom.android.sdk.post.IntercomPostActivity, io.intercom.android.sdk.survey.ui.IntercomSurveyActivity, io.intercom.android.sdk.ui.preview.ui.IntercomPreviewActivity, io.purchasely.views.PLYActivity, io.purchasely.views.PLYTVLinkActivity, io.purchasely.views.PLYWebViewActivity, io.purchasely.views.flows.PLYFlowActivity, io.purchasely.views.subscriptions.tv.PLYSubscriptionsActivity
- Services：androidx.camera.core.impl.MetadataHolderService, androidx.credentials.playservices.CredentialProviderMetadataHolder, androidx.room.MultiInstanceInvalidationService, androidx.work.impl.background.systemjob.SystemJobService, androidx.work.impl.foreground.SystemForegroundService, com.google.android.datatransport.runtime.backends.TransportBackendDiscovery, com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService, com.google.android.gms.auth.api.signin.RevocationBoundService, com.google.android.gms.measurement.AppMeasurementJobService, com.google.android.gms.measurement.AppMeasurementService, com.google.firebase.components.ComponentDiscoveryService, com.google.firebase.messaging.FirebaseMessagingService, com.google.firebase.sessions.SessionLifecycleService, com.google.mlkit.common.internal.MlKitComponentDiscoveryService, com.photoroom.service.FirebaseNotificationService, com.shakebugs.shake.internal.shake.recording.ScreenRecordingService, io.intercom.android.sdk.fcm.IntercomFcmMessengerService
- Receivers：androidx.profileinstaller.ProfileInstallReceiver, androidx.work.impl.background.systemalarm.RescheduleReceiver, androidx.work.impl.diagnostics.DiagnosticsReceiver, androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver, com.braze.BrazeFlushPushDeliveryReceiver, com.braze.push.BrazePushReceiver, com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver, com.facebook.CurrentAccessTokenExpirationBroadcastReceiver, com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver, com.google.android.gms.measurement.AppMeasurementReceiver, com.google.firebase.iid.FirebaseInstanceIdReceiver, com.photoroom.components.sharing.data.broadcast.ShareBroadcastReceiver, com.shakebugs.shake.internal.NotificationReceiver
- Providers：androidx.startup.InitializationProvider, com.adjust.sdk.SystemLifecycleContentProvider, com.datadog.android.rum.DdRumContentProvider, com.facebook.internal.FacebookInitProvider, com.google.firebase.provider.FirebaseInitProvider, com.google.mlkit.common.internal.MlKitInitProvider, com.photoroom.application.PhotoroomFileProvider, com.shakebugs.shake.internal.utils.FileProvider, io.intercom.android.sdk.IntercomFileProvider, io.intercom.android.sdk.IntercomInitializeContentProvider, io.purchasely.providers.InitializerProvider

## SDK / Endpoint

### SDK

- `adjust`
- `amplitude`
- `facebook`
- `firebase`
- `revenuecat`

### Endpoint candidates

- http://www.apache.org/licenses/
- https://www.apache.org/licenses/LICENSE-2.0
- https://cs.android.com/androidx/platform/frameworks/support
- http://source.android.com
- https://opensource.org/licenses/BSD-3-Clause
- https://github.com/androidx/media
- https://github.com/cashapp/zipline/
- https://github.com/touchlab/Stately
- https://opensource.org/license/mit/
- https://github.com/adjust/adjust_signature_sdk/blob/v3.67.0/LICENSE
- https://github.com/adjust/adjust_signature_sdk.git
- https://github.com/airbnb/lottie-android
- https://github.com/algolia/algoliasearch-client-kotlin
- https://github.com/amplitude/Amplitude-Kotlin
- https://github.com/amplitude/experiment-android-client
- https://github.com/amplitude/Amplitude-Android
- https://github.com/amplitude/experiment-evaluation
- https://developer.android.com/studio/terms.html
- https://github.com/braze-inc/braze-android-sdk/blob/master/LICENSE
- http://github.com/braze-inc/braze-android-sdk
- https://github.com/BigBadaboom/androidsvg
- https://github.com/composablehorizons/compose-unstyled/blob/main/LICENSE
- https://github.com/composablehorizons/compose-unstyled/tree/main
- https://github.com/DataDog/dd-sdk-android/
- http://github.com/ehrmann/vcdiff-java.git/tree/master
- https://github.com/facebook/facebook-android-sdk/blob/main/LICENSE.txt
- https://github.com/facebook/facebook-android-sdk
- https://github.com/facebook/shimmer-android/blob/master/LICENSE
- https://github.com/facebook/shimmer-android.git
- https://github.com/firebase/firebaseui-android
- https://opensource.org/licenses/BSD-2-Clause
- https://github.com/bumptech/glide
- https://github.com/skydoves/colorpicker-compose/
- https://github.com/google/accompanist/
- https://android.git.kernel.org/
- https://github.com/firebase/firebase-android-sdk
- https://github.com/google/flexbox-layout
- https://developers.google.com/ml-kit/terms
- https://github.com/material-components/material-components-android
- https://developer.android.com/guide/playcore/license

## Warnings

- apktool manifest decode skipped 35 split APK(s)
- binary AndroidManifest.xml decoded with apktool

## 下一步

- 真机/模拟器验证 onboarding、paywall、首个可感知价值和崩溃路径。
- 把 endpoint candidates 与 HAR / MITM / Frida 动态证据对齐，避免只凭静态字符串下结论。
- 多版本对比权限、SDK、endpoint、native libs 和资源路径变化。
- 订阅/广告 SDK 线索存在，后续需拆 paywall、free trial、退款和广告频率。
