Keep your React Native app shippable.

One command tells you whether your app can still upgrade and still ship: unsupported versions, New Architecture blockers, Google Play deadlines and secrets leaked into the app bundle.

npx nativekeel

Free and open source. No signup. Your code never leaves your machine.
See a sample report and upgrade plan →

NativeKeel health report  acme-app
React Native 0.77.1 (latest 0.87.1)
New Architecture  android: off  ios: off

✖ CRITICAL React Native 0.77.1 is no longer supported
           You are 10 minor versions behind.
✖ CRITICAL New Architecture is disabled
           Cannot upgrade past 0.81 until it migrates.
✖ CRITICAL AWS access key ID shipped inside the app
           Anyone who downloads the app can extract it.
▲ HIGH     iOS AppDelegate is missing RCTAppDependencyProvider
           A launch crash in Release once the New Architecture is on.

Summary  4 critical · 5 high · 4 medium · 6 low

From a real upgrade

The App Store rejected a release for a launch crash. The fix that shipped only hid it.

The real cause was one line missing from the iOS AppDelegate since React Native 0.77. On Android, an audio library stopped the app from starting at all, with the process still alive. Neither shows up in a debug build on your machine.

  • Both are now checks. Run on the original repository, NativeKeel flags them before any work starts.
  • So are 5 of the 7 other things that broke on the way to 0.80, from Podfile leftovers to a patch that silently stopped applying.
Read the case study
14problems fixed
0.77 → 0.80React Native, React 19
5native modules removed
~2 hengineering time

What it checks

30+ checks and 14 secret patterns for the problems that quietly turn a routine update into a three-week project, found in seconds. Tuned on 280+ open-source React Native and Expo apps to keep false alarms out. Outputs for terminal, HTML, Markdown, JSON and GitHub code scanning (SARIF).

Versions

Support status

React Native supports only the latest three minors. Expo moves just as fast. Know where you stand before a store deadline decides for you.

Architecture

New Architecture blockers

The legacy architecture is gone since 0.82. See which native modules block the switch, which library versions match each React Native release, and what to replace.

Store

Google Play and App Store rules

Target SDK, the iOS privacy manifest, and 16 KB pages: it opens your built APK or AAB and measures the alignment of every native library.

Security

Secrets and signing keys

API keys shipped in the bundle, .env values compiled into the app, committed keystores, signing passwords and App Store Connect keys.

Cleanup

Packages you can delete

Installed but never imported, never referenced natively and not required by anything else. Every package you remove is one you never upgrade.

Experience

Known traps

Things that broke real upgrades, like an AppDelegate missing the one line React Native 0.77 requires, which crashes release builds with the New Architecture. The list grows with every upgrade we do.

From report to fixed

Use the report and the plan yourself, or hand the whole thing to us.

Scan

Run npx nativekeel in your app folder. Share the HTML report with your team or client.

Plan

nativekeel plan orders the work: stop leaks, replace blockers, switch architecture, then upgrade React Native in reviewable hops.

Ship

Do it yourself with the plan, or we do it on a branch of your repo and send you a pull request with test builds.

Services

The tool and the upgrade plan are free. If you would rather not do the work, we do it for a fixed price, entirely over email and your Git host. No calls needed.

Tool

Free

Open source, MIT licensed

  • Health report and upgrade plan
  • HTML, JSON and CI baselines
  • White-label reports for agencies
npx nativekeel

Care

from $499 / month

After an upgrade, for apps that must keep shipping

  • Monthly dependency and SDK updates
  • New Apple and Google requirements handled
  • Build breakages fixed
  • Monthly health report
Ask about Care

1. Send your report

Run npx nativekeel --html report.html and email it. Nothing else is needed for a quote.

2. Get a fixed quote

Within two business days: scope, price and delivery date in writing. 50% to start, 50% on delivery, by international bank transfer.

3. Review a pull request

We work on a branch. You test the builds, review every change and merge when you are happy.

How we handle your code

Giving someone access to your app is a big decision. These are commitments, and we put them in writing with every quote.

Control

You merge, not us

All work happens on a separate branch. We never push to your main branch or release to your users. You review and merge.

Access

The minimum, then removed

Access to one repository, removed when the work ends. We never ask for your App Store or Google Play passwords, signing keys or production secrets.

Confidentiality

Your NDA, if you have one

Happy to sign your NDA before seeing any code. Your code stays on an encrypted machine and is deleted when the work ends, confirmed in writing.

AI tools

Disclosed, never trained on

We use AI coding assistants to work faster, only under terms that do not allow training on your code. If your policy forbids them, we work without.

Price

Fixed before we start

The quote is the price. If we underestimated, that is our problem. Anything outside the agreed scope is quoted separately and only done if you say yes.

Warranty

30 days on our changes

If something we changed breaks within 30 days of delivery, we fix it at no cost.

Who does the work

NativeKeel is not an agency that hands your code to someone you never hear about. Every upgrade is done by one engineer, start to finish.

AAAlican Akyol

Alican Akyol

Staff / lead engineer · mobile, frontend and backend

I have spent 14+ years shipping production systems end to end: mobile apps in React Native, iOS and Android, web frontends in React and Next.js, and the Node.js backends and API integrations behind them. I have built them for teams in banking, insurance, travel and research, including Fibabank, Anadolu Sigorta, Edenred, Turna.com, Setur and TÜBİTAK.

I also build and run my own React Native app in production, so I deal with store deadlines and native upgrades as an owner, not only as a contractor. My background in security engineering and malware analysis is why NativeKeel looks for leaked keys first.

14+ years in productionMobile · Frontend · BackendReact Native · React · Node.jsSecurity engineering

FAQ

Does my code leave my machine?

No. The scan runs locally. The only network requests are package-name lookups on npm and React Native Directory. Secret values are masked in every report.

Does it work with Expo and monorepos?

Yes. It reads Expo SDK versions and app.json, supports managed apps without native folders, and finds packages hoisted to a parent node_modules.

Is it really free? What is the catch?

The tool and the plan are free and open source under MIT. We make money when teams ask us to do the upgrade for them. The report tells you honestly whether you need that.

Do we need a call for the upgrade service?

No. Everything runs over email and your Git host: you send the report, we send a fixed quote, you grant repository access, we deliver a pull request with test builds.

Can I check what the tool does before running it on our code?

Yes. It has no dependencies and no install scripts, the source is short and public, and releases are published with npm provenance so you can verify the package matches the source (npm audit signatures). Run it with --offline to forbid all network access.

What if the report is wrong?

Version and maintenance data comes from npm and React Native Directory and can lag. Write to us and we will fix the rule. A missed upgrade blocker is a bug to us.

What if you cannot finish the upgrade?

If we cannot deliver the agreed scope, you get your deposit back. You keep the plan and any partial work on the branch.