Skip to content
CAI
Software that uses CAICheck a score

RikkaApps/Shizuku

49.2

Weak · 22 September 2026

6.5k

lines of production code

Kotlin

with Java, C++

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a privileged Android service framework that facilitates secure, wireless ADB pairing and shell execution. It manages the lifecycle of user services and handles inter-process communication through a modernized server architecture. The codebase has been significantly refactored to remove legacy hidden API overrides and socket-based communication layers in favor of a cleaner, modular structure.

How it got here

2017 — Architecture modernization and cleanup

13 changes.

This period focused on modernizing the project's build system and removing legacy code. The team migrated to a modern Gradle and Android build configuration, while simultaneously stripping out obsolete hidden API stubs, AIDL definitions, and socket-based IPC implementations. These changes reflect a shift towards a cleaner, more secure architecture with wireless debugging support.

2020–2021 — Server architecture refactoring and Shizuku integration

6 changes.

This period focused on restructuring the server-side codebase into a more modular and maintainable architecture, introducing dedicated managers for configuration, services, and user sessions. Concurrently, the project integrated the Shizuku shell loader for Rish support and implemented wireless ADB pairing, while also establishing compatibility utilities for Android API variations.

Features

Add ADB wireless pairing and TLS support

The Shizuku Manager app now includes a new ADB client implementation that supports TLS encryption and mDNS service discovery for wireless debugging. This enables secure, password-less pairing with ADB on Android 11 and above, allowing users to connect to their development computer wirelessly without needing to manually enter a pairing code. The update also introduces a dedicated tutorial activity to guide users through enabling wireless debugging and configuring notification permissions required for the background pairing service.

manager/src · high confidence

Added Shizuku shell loader for Rish integration

Added the ShizukuShellLoader component, which handles the communication protocol for the Rish shell. This includes the Java implementation for requesting and receiving the Shizuku binder via broadcast intent or activity start, loading the shell class via a custom classloader, and managing the main loop and timeout logic. The entry also includes the associated AndroidManifest and ProGuard rules for this new shell module.

shell · high confidence

Wireless ADB pairing support and improved service startup

The app now supports wireless ADB pairing, allowing users to connect to their device over Wi-Fi using a pairing code. This is implemented via new components like AdbPairingClient and AdbPairingService. Additionally, the service starter logic has been refactored to use a compatibility layer (IContentProviderCompat) for sending the service binder, and the startup process now waits for the binder to be received before closing the UI, improving reliability.

starter · high confidence

Removals

Removal of hidden API override stubs and AIDL definitions

The \hidden-api-override-m\ and \hidden-api-public\ modules have been removed. This deletes the Java stubs (e.g., \IActivityManager\, \IPackageManager\, \AppOpsManager\) and AIDL definitions that previously provided hidden Android API access. Consequently, any functionality relying on these specific override classes for system-level interactions is no longer available through this module.

hidden-api-override-m, hidden-api-public, sv-override-m · high confidence

Removed Android API override stubs and server-side bridge classes

Deleted the \hidden-api-override\ and \sv-override\ modules, which previously provided stub implementations of Android system classes (such as \ActivityManager\, \AppOpsManager\, \ITaskStackListener\, and \UserInfo\) to bypass hidden API restrictions. This removes the server-side \HideApiOverride\ and \HideApiOverrideO\ classes that converted data between the app's internal models and Android's system models, effectively eliminating the compatibility layer used to access restricted Android APIs.

(repo-wide) · high confidence

Architecture

Refactored server components into the rikka.shizuku.server package

The server-side implementation has been reorganized into the \rikka.shizuku.server\ package, introducing new files such as \ApkChangedObservers.kt\ for monitoring APK changes, \BinderSender.java\ for managing binder delivery to applications, \ShizukuClientManager.java\ for client management, \ShizukuConfig.java\ for configuration, and \ServerConstants.java\ for shared constants. This change consolidates and structures the server logic, improving code organization and maintainability.

server/src/main/java/rikka/shizuku/server · high confidence

Behavioural changes

Extracted shared utility classes into common module

The common module now includes new utility classes, BuildUtils and OsUtils, which provide helper methods for checking Android SDK versions and retrieving OS-level identifiers like UID, PID, and SELinux context. Additionally, the .gitignore and AndroidManifest.xml files have been moved from their previous locations (api and hidden-api-public) into the common directory, consolidating shared resources.

common · high confidence

Introduced compatibility utility for ContentProvider calls

Added IContentProviderUtils class to handle version-specific calls to IContentProvider, supporting Android S (API 31) and earlier versions through a unified interface.

server/src/main/java/rikka/shizuku/server/api · medium confidence

Refactored server architecture with new config, service, and user service managers

The server code has been reorganized into new classes: ShizukuConfigManager handles configuration persistence and validation, ShizukuService manages the main server loop and client connections, and ShizukuUserServiceManager handles user service lifecycle and APK change detection. These changes improve the structure of the server component, likely to support the Shizuku v13 API and better handle multi-user scenarios and package upgrades.

. · medium confidence

Removal of legacy code generator classes

The generator module has removed several legacy Java classes that were previously used to generate code. Specifically, the files AbstractPrivilegedAPIsWtiter.java, ActionWriter.java, AidlMethod.java, AidlParser.java, Arg.java, RequestHandlerWriter.java, Type.java, and Writer.java have all been deleted from the project.

generator · high confidence

Removal of legacy hidden API stubs

The hidden-api module has removed a collection of Java interface and class stubs that previously provided placeholder implementations for Android system services. Specifically, the following files have been deleted: ActivityManagerNative, AppGlobals, IActivityManager, IApplicationThread, ITaskStackListener, ProfilerInfo, IIntentReceiver, IPackageManager, IWifiManager, IUserManager, ServiceManager, and IAppOpsService. These stubs, which threw UnsupportedOperationException, are no longer present in the codebase.

hidden-api · high confidence

Removed ParcelInputStream and ParcelOutputStream classes

The server's IO layer has been refactored by removing the custom \ParcelInputStream\ and \ParcelOutputStream\ classes. These classes previously handled the serialization and deserialization of Android \Parcelable\ objects, bitmaps, and exception states over an input/output stream. Their removal indicates a shift in how the server handles IPC data, likely moving to a different serialization mechanism or library.

server/src/main/java/moe/shizuku/server/io · high confidence

Removed ProGuard configuration file

The ProGuard configuration file (proguard-rules.pro) has been removed from the api module. This means the module will no longer apply custom ProGuard rules for code shrinking and obfuscation, relying instead on default configurations.

api · high confidence

Removed legacy privileged API implementation

The legacy privileged API implementation has been removed. This includes the \Protocol.aidl\ interface, the \AndroidManifest.xml\ with its broadcast receivers and permissions, and the Java classes responsible for socket-based communication (\AbstractPrivilegedAPIs\, \PrivilegedAPIs\, \Protocol\, \Actions\, and the \io\ stream helpers). Users relying on this specific API surface will need to migrate to the updated API.

api/src · high confidence

Removed legacy socket-based server implementation

The server's previous socket-based communication layer has been removed. This includes the deletion of the \Actions\ constants, the \Protocol\ class handling versioning and result codes, the \RequestHandler\ managing socket I/O, the \Server\ entry point, the \SocketThread\ for accepting connections, and supporting utilities like \IntentReceiver\ and \Intents\. This change eliminates the old inter-process communication mechanism in favor of a new architecture.

server/src/main/java/moe/shizuku/server · high confidence

Repository structure and build tooling updated

The repository now includes a new .gitattributes file to manage line endings and binary files, and a .gitmodules file that initializes the 'api' submodule pointing to the Shizuku-API repository. The legacy apis.aidl file has been removed, and the signing.properties file has been deleted from version control. Additionally, the Gradle wrapper scripts (gradlew and gradlew.bat) have been updated to the latest standard templates, and the .gitignore has been adjusted to exclude the manager signing.properties and other build artifacts.

(repo-wide) · high confidence

Updated ProGuard rules and added resource obfuscation configuration

The manager module now includes a new aapt2-resources.cfg file that prevents obfuscation of specific Material Design color resources. Additionally, the ProGuard rules have been updated to preserve critical classes and methods for the Shizuku server, user service starter, and shell components, while also suppressing specific logging calls and ensuring source file and line number attributes are retained for debugging.

manager · high confidence

Dependencies

Migrate to modern Gradle and Android build system

The project has been migrated from the legacy Gradle build system to the modern Gradle Plugin DSL and Android Gradle Plugin 8.10.1. This update introduces a new version catalog for managing dependencies, including dev.rikka.hidden 4.4.0 and dev.rikka.tools.refine 4.4.0. The build configuration now uses Kotlin DSL, enforces a minimum SDK of 24, and targets SDK 36. The old 'api' module has been removed, and the project structure has been reorganized to include new modules such as 'common', 'shell', and 'starter', while removing obsolete hidden API override modules.

(dependencies) · high confidence

Upgrade Gradle wrapper to version 8.14

The Gradle wrapper has been updated from version 3.4.1 to 8.14. This upgrade brings modern Gradle features and improved build performance, requiring a newer version of the Gradle build tool to be installed on the developer's machine.

gradle · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 49 → 49 (+0.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 98 (-0.9)
  • Architecture 99 → 99 (+0.8)
  • Maturity 50 → 50 (+0.2)
  • Readiness 33 → 31 (-1.6)
  • Security 55 → 64 (+9.2)

Resolved (11)

  • Change coupling: HomeActivity.kt ↔ ServerStatusViewHolder.kt (manager/src/main/java/moe/shizuku/manager/home/HomeActivity.kt)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No exposed public API
  • Off-boarding risk: anonymized user #1

New (23)

  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • MultiLocaleEntity.get (cognitive 25) (manager/src/main/java/moe/shizuku/manager/utils/MultiLocaleEntity.java)
  • No ADRs found
  • No dependency advisory monitoring
  • Off-boarding risk: anonymized user #1
  • ShizukuConfigManager.<init> (cognitive 29) (server/src/main/java/rikka/shizuku/server/ShizukuConfigManager.java)
  • ShizukuConfigManager.<init> (cyclomatic 16) (server/src/main/java/rikka/shizuku/server/ShizukuConfigManager.java)
  • ShizukuService.dispatchPermissionConfirmationResult (cognitive 24) (server/src/main/java/rikka/shizuku/server/ShizukuService.java)
  • ShizukuService.getApplications (cognitive 24) (server/src/main/java/rikka/shizuku/server/ShizukuService.java)
  • …and 3 more

Architecture

  • Containers 0 added · 0 removed · contexts 2 added · 2 removed · edges 0 added · 0 removed

Added bounded contexts (2)

  • manager
  • server

Removed bounded contexts (2)

  • .
  • starter

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

RikkaApps/Shizuku was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b844bc491f1790c72328e1a8e5b2349f8978f0ea — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.