Pingoby YallaAi
Guide

Is my Wi-Fi secure? What a phone can read from the network’s own beacons

The beacon is public. The password, the firmware and the router settings are not.

A Wi-Fi network broadcasts beacons that state its own security settings: the security type, the cipher in use, whether management frames are protected, and whether WPS is advertised. Pingo’s Wi-Fi hardening check reports what the network this phone is on advertises about its own security, read from beacons already in the air. It does not knock any device off the network, capture a handshake or try a password.

That means a clean read is not a clean bill of health. When nothing the check reads for is advertised, the app says so in those words, and then lists what stays out of reach.

Steps in Pingo

  1. Open the Tools tab, then the Secure group, then Wi-Fi hardening check. It carries READ-ONLY and ON-DEVICE badges, and a refresh control whose tooltip reads Read the beacon again.
  2. Under What the beacon says, read Network, Security, Cipher, Frame protection, WPS and Last seen. None of those cells is coloured, because this grid is what the beacon says rather than what it means.
  3. Below the grid, findings are grouped as Read from the beacon, Reasoned from the network name, and What this check cannot see. There is no score and no grade.
  4. For a guest network, open VLAN isolation test from the Tools tab and tap Test this network.

Advertised, never "off"

The WPS cell reads ADVERTISED or NOT ADVERTISED, and never "off". Advertised is a statement about the beacon; off would be a statement about the router’s settings, which nothing on a phone can see. The same care applies to the platform itself: the flags for frame protection and WPS only reach an app from Android 11 onwards, so on older versions an absent flag is not a reading of the beacon at all, and the check treats it that way.

The verdicts cover the network this phone is joined to. Assessing the neighbours would be a security assessment of other people’s property, so the check does not do it.

The four blind spots it always shows

  • Your Wi-Fi password. A beacon carries no part of the passphrase, not even its length.
  • Whether the WPS PIN would give way here. Telling that apart means running the PIN exchange against your router, which is an attack.
  • The router firmware version. It is not in the beacon, so there is nothing to look up.
  • Known flaws in this router model. A guess from a name would be a guess printed as a fact.

Guest Wi-Fi: what reaching none actually proves

The VLAN isolation test opens connections from the Wi-Fi you are on to addresses that are not on this phone’s subnet, and answers with one of three words. NOT isolated is the hard finding: this Wi-Fi reached hosts on other subnets, so a device here could talk to those networks. Isolation looks correct is the softer one, and the app spells out why: it only proves the addresses that were tested, not that every VLAN is blocked, and a silent host can look the same as a blocked one.

A test that stopped part way answers Couldn’t test rather than passing. So does a run with no other-subnet targets to try, because a "no reply" there would be a zero-host non-result. The readout prints addresses checked as a count out of a total, never a bare tally.

What Pingo can and cannot tell you here

What it can tell you

  • Report the security type, cipher, frame protection and WPS flag the connected network advertises.
  • Separate what was read from the beacon from what was reasoned from the network name.
  • Say when an absent flag is not a reading, because the Android version would not have written it.
  • Test whether this Wi-Fi can reach addresses on other subnets, and name each one it reached.

What it cannot

  • Test your Wi-Fi password, or tell you whether it is strong. It captures no handshake and tries nothing.
  • Tell you whether the WPS PIN would give way, which would mean attacking your own router.
  • Read the router firmware or look up flaws in the model.
  • Prove a guest network is isolated. Only a host it reached is a hard finding; silence is not.

Related tools

Wi-Fi hardening check, VLAN isolation test, Default password check, Admin and RDP port exposure and the rest of the security group are on the tools page.

Get Pingo on Google Play

Last updated: 13 September 2026