We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Independent trust investigation · Current build, legal entity, notarization, lab dates, settlement and permissions checked August 8, 2026

Is MacKeeper Safe in 2026? Evidence, History and Risks

The useful answer is neither “trust the badge” nor “the old reputation proves everything.” We separated the current app from its previous owners, checked what each certification actually covers, read the privacy terms, and dated the last direct malware test.

Current app: 7.7Direct lab build: 6.82015 case framed exactlyPermissions audited

Quick answer: current MacKeeper is a legitimate commercial Mac utility from Clario Tech FZCO, and the checked evidence doesn't support calling version 7.7 a virus. Apple notarization and an Active AppEsteem listing are useful trust signals, while AV-TEST gave MacKeeper 6.8 a perfect 18/18 in March 2025. The caution is freshness: today's app is 7.7, and MacKeeper is absent from the checked AV-TEST and AV-Comparatives 2026 Mac rosters. That's a reason to keep the verdict bounded, not to recycle a 2015 accusation as a 2026 malware finding.

Our verdict: safe is defensible, “fully proven current” isn't

There's enough current evidence to distinguish MacKeeper 7.7 from malware. The download comes from an identified company, the current app is presented as signed and notarized, and the recent product line has direct independent antivirus results. Nothing we checked supports the technical claim that the 2026 build replicates itself, hides as malicious code or exists only to steal money.

There isn't enough fresh comparative evidence to say the current build has been independently proven against the 2026 field. The direct AV-TEST result belongs to version 6.8 from March 2025. A later major-version result isn't listed on AV-TEST's March 2026 Mac page or AV-Comparatives' May 2026 report. The correct editorial label is legitimate current product with positive but version-limited lab evidence.

That leaves a personal risk decision. A user who wants antivirus, cleanup, a VPN, breach monitoring and optional human support in one interface may accept the bundle. Someone who wants a narrowly scoped antivirus with current-year comparative participation has a sound reason to choose a different product. Our full MacKeeper review handles the value decision; this page is only the trust audit.

The evidence ledger: six claims, six different limits

Trust pages become misleading when every logo is treated as interchangeable. A legal document can identify the responsible company but can't measure detection. Apple's notary service can inspect a submitted build for known malicious content but doesn't review subscription tactics. AppEsteem evaluates unwanted-software conduct, while AV-TEST measures protection, performance and usability under a dated test setup.

MacKeeper evidence ledger for current owner, notarization, AppEsteem, AV-TEST date and user-controlled access
Editorial evidence map. The checks answer different questions; none is a substitute for the others.
ClaimWhat we verifiedWhat it supports
Current identityMacKeeper 7.7, released July 2026; current download page and legal terms name Clario Tech FZCO.Current first-party product and legal evidence
Apple notarizationThe vendor says current MacKeeper is notarized. Apple defines notarization as an automated known-malware and signing check, not App Review.Useful platform-security signal with a strict limit
Direct antivirus testAV-TEST awarded 6/6 in protection, performance and usability to MacKeeper 6.8 in March 2025.Strong direct result for 6.8, not a direct test of current 7.7
Current comparative coverageMacKeeper is absent from the checked AV-TEST March 2026 and AV-Comparatives May 2026 home-Mac rosters.Fresh-evidence gap; absence isn't failure
AppEsteem conduct reviewAppEsteem lists MacKeeper 7.4 as Active and evaluates advertising, distribution and monetization conduct.Relevant to PUP history, not a malware-detection score
2015 settlementA class action over alleged ZeoBIT advertising and product-function claims settled without a merits decision; ZeoBIT denied wrongdoing.Real historical trust issue, not a malware conviction of current 7.7

This is also why a one-word safe/unsafe badge isn't enough. The current identity is well documented. The 2025 malware result is strong. The current 2026 comparative gap is real. The historical settlement is real. Each fact survives scrutiny only when its date, company and scope stay attached.

Virus, malware, PUP and scam aren't synonyms

A computer virus is a particular kind of malware that replicates by inserting itself into other code. “Malware” is broader and describes software designed to harm, disrupt, spy or gain unauthorized access. We didn't find current primary or independent evidence that MacKeeper 7.7 fits either technical definition.

A PUP or potentially unwanted program is different. Security vendors may use the label for aggressive distribution, surprising defaults, bundling, difficult removal or behavior that users didn't meaningfully request. MacKeeper's own current FAQ acknowledges historical PUP flags and attributes them to advertising under earlier ownership. That's a vendor explanation, not permission to dismiss every complaint, but it correctly separates PUP history from a virus finding.

“Scam” usually describes deceptive commercial conduct rather than executable code. MacKeeper is a real product with a real app, subscription and company. The brand also carries a documented civil dispute over earlier advertising. A precise article can say both without turning a marketing allegation into a malware verdict or treating a current receipt as automatically fraudulent.

Who owns MacKeeper now, and which document should you trust?

The official download page reports MacKeeper 7.7, released in July 2026, and names Clario Tech FZCO as developer. The current MacKeeper EULA and privacy policy also identify Clario Tech FZCO in Dubai. Those documents govern the current software and data processing, so they carry more weight than an old review or company-history snippet.

There's a wording conflict worth exposing. The current FAQ says MacKeeper is developed and owned by Clario Tech DMCC, while the download page and legal terms say FZCO. We use FZCO for the current legal entity because it appears in the operative documents. We don't silently collapse the two names or pretend the vendor's own pages are perfectly synchronized.

For a buyer, the practical checks are simple: download from the official domain, make sure the signed installer opens under normal Gatekeeper rules, and keep the purchase tied to the same company/domain shown in the legal terms. A lookalike “support” page, cracked installer or unsolicited renewal call doesn't inherit legitimacy merely by using the MacKeeper name.

The ownership timeline explains the reputation lag

MacKeeper began under ZeoBIT. Kromtech acquired the product in 2013, and MacKeeper says Clario acquired Kromtech in 2019. Current version 7 belongs to a different corporate and engineering period than the build discussed in the 2015 class action. That doesn't erase history; it prevents history from being attached to the wrong defendant and binary.

Brand memory moves more slowly than code and ownership. Search results, forum replies and support posts can remain visible for a decade. Some describe genuine earlier complaints; others use “virus” as shorthand for unwanted popups, regret over a purchase or difficult removal. A reader needs the date and version before deciding whether an anecdote describes today's app.

We therefore treat pre-2019 material as historical context unless a current source reproduces the behavior. Current claims require current proof: present legal terms, current installer behavior, recent lab tests, current certification listings and the permissions requested by the version actually being installed.

Apple notarization is meaningful—but it isn't an endorsement

MacKeeper says the app is notarized by Apple. Apple's own notarization documentation describes an automated service that scans Developer-ID-signed software for malicious content and checks code-signing issues. Apple explicitly says notarization isn't App Review.

That distinction matters. A successful ticket tells Gatekeeper that Apple received and checked the submitted code and found no known malware under that automated process. It also helps users detect a modified or unsigned copy. It doesn't mean Apple recommends the product, validated every cleanup claim, inspected the privacy policy, compared renewal prices or measured detection against a malware set.

Don't disable Gatekeeper to force an unexpected installer through. Apple's current safe-app guidance says software from outside the App Store should be signed and notarized under normal settings. If macOS says it can't verify the developer or check the app, stop and obtain a fresh installer from the official source rather than following a random “Open Anyway” tutorial.

The strongest direct lab result is for MacKeeper 6.8, not 7.7

AV-TEST's direct report evaluated MacKeeper 6.8 on macOS Sequoia 15.3.2 in March 2025. It awarded 6/6 for protection, 6/6 for performance and 6/6 for usability. The product detected 100% of the widespread and prevalent samples in that reference set and produced zero false detections, warnings or blockages in the listed usability checks.

That's solid evidence, but the version label must travel with it. MacKeeper's current public build is 7.7. Architecture, engine components, defaults and operating-system integration can change between major versions. A good result for 6.8 supports confidence in the recent product line; it can't be republished as if AV-TEST directly ran the July 2026 binary.

MacKeeper also displays a 99.7% figure on its own pages. The live direct AV-TEST result we checked reports 100% for its March 2025 reference set. Rather than average or merge the numbers, we use the direct lab page for the dated test and identify the other number as vendor-presented marketing. Different test sets or older results may explain the mismatch, but guessing would add certainty that the sources don't provide.

The missing 2026 roster entry is an evidence gap, not a failed score

AV-TEST's March 2026 home-Mac results list ten products; MacKeeper isn't among them. AV-Comparatives' May 2026 Mac report tested nine consumer and business products, also without MacKeeper. Those two checks are the basis for our freshness warning.

Public rosters don't tell us why a vendor is absent. Participation can depend on scheduling, submission, commercial decisions and a laboratory's program. It would be irresponsible to turn “not listed” into “failed,” “refused,” “banned” or “scored zero” without evidence. The accurate statement is narrower: we can't point to a direct public test of MacKeeper 7.7 in those current 2026 comparisons.

Readers who prioritize current-year lab parity can choose from products that appear in both the relevant roster and their desired platform test. Readers who prioritize MacKeeper's all-in-one tools may accept the older direct result and apply tighter installation, permission and renewal checks. The gap changes confidence, not the software's technical definition.

AppEsteem addresses conduct and unwanted-software risk

AppEsteem's certified-app listing shows MacKeeper 7.4 as Active under Clario Tech DMCC, dated December 31, 2025. The listing also records earlier 7.x and 6.x builds. It doesn't yet show the current 7.7 build in the visible entry we checked, so we keep that version boundary in the article.

Its certification requirements focus on whether advertising, distribution and monetization are clean and whether normal consumers are likely to feel tricked, surprised or cheated. That makes the program directly relevant to MacKeeper's historical PUP and marketing reputation.

AppEsteem isn't a substitute for AV-TEST. An Active conduct listing doesn't prove a malware-detection percentage, and a malware score doesn't audit checkout or advertising. Together they cover different layers of the trust question. The most honest sentence is: MacKeeper has recent active conduct certification for 7.4 and positive antivirus testing for 6.8, while current 7.7 still lacks the public 2026 comparative result we looked for.

What actually happened in the 2015 MacKeeper settlement

The primary document is the court-authorized notice for Yencha v. ZeoBIT LLC, No. 14-cv-00578, in the U.S. District Court for the Western District of Pennsylvania. The notice says the lawsuit alleged ZeoBIT deceptively advertised and sold MacKeeper as capable of functions it allegedly couldn't perform. The claims concerned contract, enrichment, advertising and product functions—not a criminal malware conviction.

ZeoBIT denied wrongdoing or liability and said its conduct was lawful. The notice also states that the court had not decided whether the plaintiff or defendant should win. The parties settled to avoid the cost and uncertainty of continued litigation. ZeoBIT agreed to a $2 million fund, and eligible U.S. purchasers could seek up to $39.95 subject to claims and expenses.

Two distortions should be avoided. Calling the settlement meaningless would whitewash a real trust event involving roughly 513,000 potential class members. Calling it a judicial finding that current MacKeeper is malware would invent a decision the notice says the court didn't make, attach it to the wrong kind of claim, and skip the ownership/version change.

Full Disk Access is powerful; treat it as a feature-level decision

Antivirus software needs to inspect files that ordinary apps can't freely read. Cleanup features may also need broad visibility to locate caches, leftovers and duplicates. macOS places Full Disk Access behind an explicit user approval for that reason. The request is not, by itself, proof of malware—but it isn't a harmless cosmetic toggle either.

Download the verified app first, let macOS identify it normally, then grant only the permissions required for the features you intend to use. Check that the listed process belongs to MacKeeper, not to an unfamiliar helper with a similar name. Our safe installation guide separates antivirus permissions from optional browser and support access, while the next compatibility spoke will cover current macOS paths in detail.

Review the list again after a trial, uninstall or feature change. Full Disk Access can be revoked in System Settings → Privacy & Security. Removing the app icon, canceling a subscription and revoking a system permission are separate actions; completing one doesn't prove the others happened.

The privacy policy is broader than a simple malware scanner

The current privacy policy says MacKeeper may process device and configuration information, identifiers, IP addresses, installed-app details, browser and network information, Find & Fix results, and activity such as crashes or errors. That scope reflects an all-in-one diagnostic utility, not only an on-demand file scanner. A reader who wants minimum telemetry should compare this footprint with a narrower product before buying.

The StopAd extension creates a separate decision. The policy says it may process the full URL or active-tab host to identify malicious pages. It also describes visible-tab screenshots processed locally when reporting a suspicious page, noting that the image may contain an email address or similar detail. Usage events and statistics can be changed in preferences or the extension's settings. Install the extension only if you want its filtering and accept that processing.

For breach monitoring, the policy says email addresses are hashed for the third-party check and that returned leak information is displayed rather than stored by the service. It also provides access, correction, restriction, portability and deletion routes through support or the account, while allowing some retention for legal and business purposes. Those are useful controls, but they don't make data collection disappear.

Remote support is optional and belongs to a separate risk envelope

MacKeeper Premium Services isn't the same thing as the antivirus app. The separate Premium Services EULA covers a broad range of technical help, including operating-system setup, data transfer, backups, account troubleshooting, performance work and remote assistance. The privacy policy says remote access requires prior explicit consent and that the user can terminate the connection.

The policy also says support records may include calls, chat, screen images and—during remote fixes—a system password. That wording deserves caution, not panic. A deliberate remote session may need local authorization, but it doesn't give any technician a reason to request your Apple Account password, bank login, card PIN or CVV, or an unrelated one-time financial code.

If you choose remote help, start from the official account or support domain, confirm which service you purchased, close or encrypt sensitive files, stay at the Mac and watch the session. When it ends, quit and remove the remote-control tool if it's no longer needed, review Login Items and permissions, and change a local password if you disclosed it. A separate cluster spoke will handle service scope and contract value; here the point is that remote control is never required to prove the core app is active.

Why community distrust persists even after the product changed

Mac communities still contain forceful warnings about MacKeeper, while a smaller number of recent comments report using the modern app without trouble. Much of the hostility points back to older advertising, popups, PUP classifications or removal experiences. Other replies reject every third-party Mac antivirus because Apple already provides Gatekeeper, notarization and XProtect.

Those views matter because software is also a support and trust relationship. They don't establish the contents of the current binary. An old “it is a virus” comment can't overrule a dated code-signing or lab record, just as one happy current user can't prove detection quality or privacy. We use community material to identify questions that need evidence, not as a vote that decides the answer.

The practical lesson is to test the experience you can observe: whether the official installer is quiet, whether scan findings are understandable, whether prompts correspond to a chosen feature, whether cancellation terms match the checkout, and whether the app uninstalls cleanly. Reputation should make the verification stricter, not replace it.

A cautious MacKeeper safety checklist

  • Use the official download: type the MacKeeper domain directly and avoid cracked installers, “premium keys” and unsolicited support links.
  • Keep Gatekeeper on: don't bypass an unexpected unidentified-developer or notarization warning.
  • Check the current identity: the download page and legal terms should name Clario Tech FZCO; preserve the receipt and account email.
  • Grant access by purpose: approve Full Disk Access for intended protection/cleanup features, and treat browser-extension access separately.
  • Run one real-time antivirus: don't enable two overlapping real-time engines and then interpret high CPU or conflicts as malware.
  • Read findings before deleting: quarantine uncertain items and verify paths rather than using “fix all” as a reflex.
  • Review privacy choices: decide whether StopAd, breach monitoring, diagnostics and usage statistics match your needs.
  • Separate support from software: remote access is optional; stay present and revoke it afterward.
  • Verify renewal in the account: the first charge, renewal, cancellation and refund are different events; our pricing and renewal guide keeps the current math separate.
  • Recheck after major updates: current 7.7 is newer than the direct 6.8 lab result, so watch for fresh public testing and permission changes.

This checklist doesn't assume MacKeeper is malicious. It applies the level of scrutiny appropriate to any security utility that requests broad disk access, processes diagnostic data and sells optional remote help.

Who should choose another product

Choose another Mac antivirus if a current 2026 lab entry is non-negotiable. AV-TEST and AV-Comparatives currently list several Mac products with direct 2026 participation. Compare the exact platform, build and test date rather than a generic badge on a sales page.

A narrower product also makes sense if you don't want cleanup, memory, VPN, browser-extension or remote-support features. Bundles can be convenient, but every extra module adds settings, permissions, data handling or renewal questions. The best antivirus for Mac hub is the better starting point when the goal is to compare alternatives rather than investigate this brand's history.

MacKeeper remains a plausible choice for someone who specifically wants an all-in-one Mac utility, prefers one interface, accepts the current privacy terms and understands that the strongest direct antivirus test isn't for the current major version. “Plausible fit” is intentionally less sweeping than “proven best.”

MacKeeper safety FAQ

Is MacKeeper safe to install in 2026?

The checked evidence supports treating current MacKeeper as a legitimate signed and Apple-notarized commercial Mac utility, not as a virus. The strongest direct malware test is for version 6.8 in March 2025, while the current app is 7.7 and is absent from the two checked 2026 Mac test rosters. Install only from the official domain, review permissions and decide whether that freshness gap is acceptable.

Is MacKeeper a virus or malware?

We found no current primary or independent evidence that MacKeeper 7.7 is self-replicating malware. Calling it a virus confuses a technical claim with the brand's older reputation. A potentially unwanted program label, criticism of marketing, privacy concerns and malware are different claims and need different evidence.

Is MacKeeper a scam?

MacKeeper is a real subscription product from an identified current company. The brand has a documented history: a 2015 class action alleged deceptive advertising and product-function claims against ZeoBIT and settled without a merits ruling; ZeoBIT denied wrongdoing. That history justifies scrutiny, but it doesn't make every current transaction fraudulent.

Who owns MacKeeper now?

MacKeeper's current download page, EULA and privacy policy identify Clario Tech FZCO. The vendor FAQ still uses Clario Tech DMCC in one ownership answer, so we rely on the current legal documents and disclose the wording conflict instead of pretending the entity names are identical.

Does Apple notarization mean Apple recommends MacKeeper?

No. Apple says notarization is an automated scan for malicious content and code-signing issues, and explicitly says it isn't App Review. It's useful evidence that a submitted signed build contained no known malware when checked, but it isn't an endorsement, feature review, privacy audit or antivirus-effectiveness test.

What did AV-TEST find for MacKeeper?

AV-TEST tested MacKeeper 6.8 on macOS Sequoia 15.3.2 in March 2025 and awarded 6/6 in protection, performance and usability, with 100% detection in its reference set and zero false detections or warnings in that test. The result shouldn't be relabeled as a direct test of current MacKeeper 7.7.

Why is MacKeeper missing from 2026 Mac antivirus tests?

The public rosters don't explain why a product is absent. MacKeeper doesn't appear in AV-TEST's March 2026 home-Mac roster or AV-Comparatives' May 2026 Mac report. That creates a gap in fresh comparative evidence; it doesn't mean the product scored zero, failed privately or was rejected.

Why does MacKeeper need Full Disk Access?

Antivirus and cleanup features may need access to protected files to inspect them, and macOS requires the user to approve that access. The permission is powerful, so grant it only to the verified app for features you intend to use, then review or revoke it in System Settings when the feature or app is no longer needed.

Is MacKeeper remote support required?

No. Premium Services and remote technical support are separate from installing, scanning with or activating the core app. The privacy policy says a remote connection requires prior explicit consent and can be terminated. Stay present, close sensitive data and revoke the remote-control tool afterward if you choose that service.

Should I choose another Mac antivirus?

Choose a currently tested alternative if recent 2026 comparative participation is a hard requirement, if you want antivirus without cleanup and support extras, or if the privacy and permission footprint is wider than you accept. MacKeeper is a more plausible fit for someone who wants an all-in-one Mac utility and understands the evidence boundaries and optional services.

Bottom line: verify the build, date and access

Current MacKeeper isn't the same company/build discussed in the 2015 case, and the checked evidence doesn't support calling 7.7 a virus. Apple notarization, an Active AppEsteem 7.4 listing and AV-TEST's strong 6.8 result all add confidence—but they answer different questions and don't create a direct 2026 test of 7.7.

The remaining decision is about freshness and scope. If you accept the older direct lab boundary and want the bundle, install from the official source, review every permission and keep remote support optional. If you want the freshest independent comparative evidence or a narrower privacy footprint, choose a currently tested alternative. That's a more useful safety answer than either a recycled warning or a row of undated badges.