- [ ] Scan security related flags: `JavaScriptEnabled`, `AllowUniversalAccessFromFileURLs`, etc. - [ ] Live js evaluation - [ ] Inspect [Native Bridges](https://developer.android.com/privacy-and-security/risks/insecure-webview-native-bridges) - [ ] Enable F12