
The strongest argument for distributing software through an app store has never been the download button. It is the feeling that someone checked what sits behind it. A store badge compresses a difficult trust decision into one familiar signal: this app has a publisher, a policy, and a platform willing to stand between the user and obvious abuse.
A new audit of 4,779 mobile VPN apps complicates that promise. The findings do not prove that open-web distribution is safer, or that store review has no value. They show something more useful for web-app builders: trust cannot be outsourced to a storefront. It has to survive every link between discovery, installation, identity, permissions, support, and long-term operation.
TechRadar examined 3,392 Android VPN apps with more than 1,000 downloads and 1,387 iOS VPN apps with at least one review. According to its audit, 61.4% of the iOS sample and 40.8% of the Android sample passed all of its main validity checks.
The weak points were frequently outside the app binary. The audit reported that 82.7% of the iOS apps had a valid developer website, compared with 52.2% of the full Android sample. It also found large numbers of privacy policies and support pages hosted on free services, along with copied templates, incomplete documents, and contact details that offered limited evidence of an accountable organization.
A follow-up analysis focused on the destinations linked from store listings. TechRadar reported that 339 Android links, or 5.3% of those assessed, and 188 iOS links, or 6.8%, used unencrypted HTTP. Its researchers also encountered obscured destinations, expired domains, irrelevant pages, advertising redirects, and multiple listings whose links led to scareware.
These figures require careful reading. This was a TechRadar investigation, not an independent academic audit, and the sample covered VPNs—a category in which identity and privacy claims carry unusually high stakes. A page hosted on a free platform is not automatically fraudulent, and the investigation did not establish that every app with a weak website was technically malicious. What it did test was whether the public trust trail around those apps looked durable, attributable, and safe.
An app-store listing is not a sealed product. It is a junction between native software and the web: developer sites, privacy policies, subscription help, account deletion, security documentation, and customer support often live on external domains. Those destinations can change after review. Domains expire, redirects are replaced, documents disappear, and company identities become difficult to trace.
Apple’s current review guidelines require apps to link to an accessible privacy policy, keep metadata accurate, and provide truthful, current developer information. Apple also imposes additional organizational and privacy requirements on VPN apps. Google’s Data safety guidance requires developers to describe their data practices and makes them responsible for accurate declarations.
The audit therefore exposes a gap between policy and persistent verification. A store may review an app and its submitted metadata, yet the surrounding web surface remains dynamic. The findings suggest that checking a destination once is insufficient when that destination continues borrowing the store’s authority months or years later.
Web apps are often asked to defend themselves against one blunt objection: Why should I trust software that did not come from an app store? The wrong response is to treat this investigation as proof that storefronts are pointless. Stores still provide discovery, payments, malware scanning, account controls, and familiar recovery paths. The better response is to build trust that users and partners can inspect directly.
This is also a product-design opportunity. Open-web distribution can expose more evidence before installation than a compact store card: live documentation, a working demo, public incident history, transparent pricing, and permission explanations tied to real features. None of those signals guarantees safety, but together they create verifiable confidence instead of relying on a single badge.
The next competitive layer in app distribution may be continuous trust rather than one-time approval. IndApp will watch whether stores begin rechecking outbound links, detecting domain-ownership changes, flagging unencrypted destinations, and making publisher identity easier to verify after installation.
The audit does not crown the open web as the safer channel. It removes the convenient fiction that a storefront alone completes the trust job. For installable web apps, that is a demanding but valuable conclusion: the product must earn confidence at every step, and the evidence should remain visible wherever the app is discovered.