Flutter health check

pulse

29 September 2026 · checked against Flutter 3.47.5

2 high 3 medium 3 low
74grade C
DependenciesB
86 / 100 · 1 medium, 2 low
Android & Google PlayC
69 / 100 · 1 high, 1 medium, 1 low
iOS & App StoreA
100 / 100 · no findings
Security & secretsA
100 / 100 · no findings
Code healthA
100 / 100 · no findings
Tests & CIC
72 / 100 · 1 high, 1 medium
Assets & sizeA
100 / 100 · no findings

Fix first

  1. High Release builds are signed with the debug key · Android & Google Play
  2. High No tests · Tests & CI

Dependencies

86 · B
Medium

haptic_feedback is 2 breaking releases behind (0.6.4+3 → 0.8.0)

Each breaking release (a new major version, or a new minor before 1.0) can need code changes. The further behind, the bigger the eventual upgrade, and fixes only land on the latest line.

Fix: Read the changelog for each one and upgrade a step at a time.

pubspec.lock
deps.breaking-behind
Low

7 direct dependencies are one breaking release behind

animations 2.2.0 → 3.0.0; cached_network_image 3.4.1 → 4.0.3; freezed 3.2.6-dev.1 → 4.0.2; go_router 17.3.0 → 18.0.2; google_fonts 8.1.0 → 9.0.0; home_widget 0.9.3 → 0.10.0; permission_handler 12.0.3 → 13.0.2

Fix: Upgrade while the gap is one version; it gets harder with each release you skip.

pubspec.lock
deps.one-breaking-behind
Low

7 dependencies are never imported: animations, collection, flutter_hooks, flutter_image_compress, haptic_feedback, hooks_riverpod, lottie

No Dart file imports them. Unused packages still add native code, permissions and upgrade work.

Fix: Check each one is not used some other way (a font, native code, a build step), then remove it.

pubspec.yaml
deps.unused

Android & Google Play

69 · C
High

Release builds are signed with the debug key

This is the template's placeholder so that flutter run --release works. Google Play rejects uploads signed with a debug key. (If a CI step signs the bundle after the build, this does not apply.)

Fix: Create an upload keystore, load its passwords from a key.properties file kept out of git, and give release its own signingConfig: https://docs.flutter.dev/deployment/android#sign-the-app

android/app/build.gradle.kts:37
android.debug-signing
Medium

Health Connect data to declare: READ_STEPS, READ_ACTIVE_CALORIES_BURNED, READ_TOTAL_CALORIES_BURNED

Google Play reviews access to Health Connect: the Health apps declaration in Play Console must list each data type and why the app needs it, and access is granted only for the uses the policy allows.

Fix: Request only the data types the features use, and prepare the declaration (App content → Health apps) before submitting.

android/app/src/main/AndroidManifest.xml:4android/app/src/main/AndroidManifest.xml:5android/app/src/main/AndroidManifest.xml:6
android.health-connect
Low

Exact alarms are off by default for new installs

Since Android 14, SCHEDULE_EXACT_ALARM is denied by default for newly installed apps (apart from alarm and calendar apps), so scheduling an exact alarm fails until the user turns it on in settings.

Fix: Check canScheduleExactAlarms() before scheduling; fall back to an inexact alarm or send the user to the setting.

android/app/src/main/AndroidManifest.xml:9
android.exact-alarm-denied

Tests & CI

72 · C
High

No tests

Every release is verified by hand, so regressions reach users, and nobody can refactor safely.

Fix: Start where bugs cost most: unit tests for the business logic (pricing, auth state, data parsing), then widget tests for the main flows. Run them in CI.

test/
testing.none
Medium

No CI configuration

Nothing builds the app or runs the tests on each change, so a broken build is found by whoever builds next, often on release day.

Fix: Add a workflow that runs flutter analyze, flutter test and a release build on every pull request (GitHub Actions and Codemagic both have free tiers).

testing.no-ci

Dependencies

PackageUsed byLockedLatestLast releasepub pointsNotes
animationsapp2.2.03.0.02026-08-19160/1601 breaking release behind
build_runnerdev only2.15.02.16.12026-09-02160/160
cached_network_imageapp3.4.14.0.32026-09-29150/1601 breaking release behind
cloud_firestoreapp6.6.06.10.02026-09-14150/160
collectionapp1.19.11.19.12024-10-21140/160
firebase_authapp6.5.36.7.02026-09-14140/160
firebase_coreapp4.11.04.15.02026-09-14160/160
fl_chartapp1.2.01.2.02026-03-13150/160
flutter_animateapp4.5.24.5.22024-11-25150/160
flutter_hooksapp0.21.3+10.21.3+12025-08-19150/160
flutter_image_compressapp2.4.02.5.12026-07-25150/160
flutter_lintsdev only6.0.06.0.02025-05-27160/160
flutter_local_notificationsapp22.0.122.3.12026-09-13150/160
flutter_riverpodapp3.3.23.4.32026-09-03140/160
flutter_svgapp2.3.02.3.02026-05-08160/160
flutter_timezoneapp5.1.05.1.02026-05-28150/160
freezeddev only3.2.6-dev.14.0.22026-09-18160/1601 breaking release behind
freezed_annotationapp3.1.03.1.02025-07-02150/160
gapapp3.0.13.0.12023-06-24160/160no release since 2023
go_routerapp17.3.018.0.22026-09-28150/1601 breaking release behind
google_fontsapp8.1.09.0.02026-09-28160/1601 breaking release behind
google_sign_inapp7.2.07.2.02025-09-17160/160
haptic_feedbackapp0.6.4+30.8.02026-09-26160/1602 breaking releases behind
healthapp13.3.113.3.22026-08-14160/160
home_widgetapp0.9.30.10.02026-09-17160/1601 breaking release behind
hooks_riverpodapp3.3.23.4.32026-09-03150/160
image_pickerapp1.2.21.2.32026-06-30160/160
intlapp0.20.30.20.32026-06-25160/160
json_annotationapp4.12.04.12.02026-05-15150/160
json_serializabledev only6.14.06.14.12026-07-30160/160
lottieapp3.3.33.6.12026-09-18160/160
mobile_scannerapp7.2.07.4.22026-09-14160/160
openfoodfactsapp3.30.23.30.22026-02-15150/160
path_providerapp2.1.62.1.62026-06-15160/160
pedometerapp4.2.04.2.02026-02-24160/160
permission_handlerapp12.0.313.0.22026-09-04160/1601 breaking release behind
riverpod_annotationapp4.0.34.0.72026-09-03130/160
riverpod_generatordev only4.0.44.0.92026-09-03130/160
shared_preferencesapp2.5.52.5.52026-03-25160/160
sign_in_with_appleapp8.1.08.2.02026-08-27150/160
timezoneapp0.11.10.11.12026-06-29160/160
uuidapp4.5.34.6.02026-07-15160/160

Project facts

App version
0.1.0+1
Platforms
android, ios, web
Audited with
Flutter 3.47.5
Dart SDK constraint
>=3.12.0 <4.0.0
Packages
45 direct, 166 transitive
targetSdk
36 (flutter.targetSdkVersion, Flutter 3.47.5)
compileSdk
36
minSdk
26
Android application ID
com.devshakib.pulse
Gradle
9.1.0
Android Gradle Plugin
9.0.1
Kotlin Gradle Plugin
2.3.20
Android permissions (app manifest)
ACTIVITY_RECOGNITION, READ_STEPS, READ_ACTIVE_CALORIES_BURNED, READ_TOTAL_CALORIES_BURNED, RECEIVE_BOOT_COMPLETED, SCHEDULE_EXACT_ALARM
iOS bundle ID
com.devshakib.pulse
iOS deployment target
16.0
Podfile platform
16.0
iOS privacy manifest (app)
none
Files scanned for secrets
223
Dart code (lib/)
161 files, 29773 lines
State management
Riverpod
Lint rules
package:flutter_lints/flutter.yaml
Analyzer (with Flutter 3.47.5)
0 errors, 0 warnings, 0 deprecated API uses, 62 lint infos
Tests
0 test cases in 0 files
CI
none found
Bundled assets
6 files, 1.1 MB

Beyond this report