Plus Messenger is a fork of Telegram for Android with over 50 million Google Play installs. Telegram’s Android code is GPL-2.0-or-later. The fork hasn’t published a line of source since September 2017, and its current release carries an advertising and billing layer that exists in no public repository. Everything below links to something you can open and check yourself.
The published source stopped in 2017
The developer’s GitLab project holds three commits and no tags. You can verify that in a browser right now:
0978c068 2017-09-13 Add readme.md
1d961518 2017-09-13 Update to v4.2.1.1 (the last code commit, ever)
b418c867 2019-02-07 Update README.md (documentation only)
https://gitlab.com/api/v4/projects/4142452/repository/commits
Its build.gradle carries versionCode 1047. The current Play release is 12.10.1.0, dated 2026-08-29. Two source requests citing the licence have sat open on that tracker since October 2018.
The shipped binary contains code that appears in no published source
Release 12.10.1.0, obtained 2026-09-01 and checked with apksigner:
base APK SHA-256 d332a1304fc0c0c3daecc8fe7321893f7a6e88ffb59916743d175bf626fbbfef
V3 signer cert 6ebb622268aad319dbe8a1f414837d2843a9b35856aefb7dee2971a3d493f276
signature schemes v1 + v2 + v3: verified
The signer certificate is the developer’s own, so this is his build. Inside: current upstream Telegram GPL code, including 2026 features, plus a proprietary layer under org.telegram.plus with ads.AdsController, ads.BillingHelper, helpers.FirebaseHelper and ads.RemoveAdsBottomSheet, bundled with AdMob, Firebase Analytics and the Play billing client. The purchase sheet sells ad removal for 5.99 euros and donation tiers up to 99.99. There is no licence text, no written offer and no source link anywhere in the app. In the published repositories the path org/telegram/plus returns HTTP 404.
The stated reason now describes the developer
The support group’s pinned rules, in place since 2019, say the source is withheld to stop third-party developers “using the code for their own benefit by adding advertising”, and that the group is not the place to ask about source code. On 2025-10-02 the developer announced advertising and a paid removal himself. Eight months later the group’s automated responder was still telling users the app “is not a commercial project”.
What happened when this was reported
I posted the record on the F-Droid forum on 1 September. At 03:47 UTC the next morning the forum deleted my account, citing no rule, with the topic still sitting in the new-user moderation queue. Two minutes later, at 03:49, a person whose F-Droid forum title reads “Contributor, F-Droid Board Member” turned up on the Telegram-FOSS tracker on GitHub under my comment there and wrote: “please delete this comment from the bot above. The bot has come and posted on several forums. Just created account and posted this. Banned them. Reporting this as well.”
https://github.com/Telegram-FOSS-Team/Telegram-FOSS/issues/377#issuecomment-5504070601
I asked F-Droid about it on their own admin tracker, which is where their Code of Conduct sends complaints. The issue was closed 80 seconds after my reply with “ah, ok then”, followed by “I would have deleted your post and account too”. A second issue, about the board member specifically, was closed as a duplicate with no comment on it at all.
https://gitlab.com/fdroid/admin/-/issues/700
The “off-topic” defence has a hole in it. The developer submitted this exact app to the F-Droid forum in March 2015, describing it in his own words as “GNU GPL v2”, and a moderator declined it for bundling play-services. That thread is still up: https://f-droid.org/forums/topic/plus/
Where it stands
Telegram, the copyright holder and the only party that can force a store takedown, has been notified twice and hasn’t replied. Its GitHub repository has issues disabled. Google Play’s public intellectual-property form refuses the category outright, leaving only the rights-holder DMCA form. The FSF Compliance Lab, the Software Freedom Conservancy, FSFE and the Software Freedom Law Center have the file. A formal section 3 source request sits unanswered on the developer’s own tracker: https://gitlab.com/rafalense/plus-messenger/-/issues/84
Full write-up with every hash and citation: https://xdaforums.com/t/plus-messenger-9-years-of-telegram-gpl-code-with-no-source-now-with-an-unpublished-paid-ads-layer.4800334/
I’m one person, writing under a pseudonym because the same developer also made WhatsApp Plus and I’d rather he never learned my name. That new account is what got me called a bot. If the source is published, I’ll say so.


Why you suppose that necroposting in unreladed projects’ forums and issue trackers is the right way to report a licensing issue?
Good question. Shame about the facts.
The licence report went where licence reports go: an issue on the developer’s own GitLab repo (#84, sitting next to #20 and #22, both unanswered), plus the FSF, Software Freedom Conservancy, Telegram and Huawei by email. None of that is a forum.
The F-Droid forum is a discussion forum for free software, where people argue about licences every day. A GPL-2.0 fork with 50M+ Play installs, no published source since 2017 and a paid ad layer that appears in no repository isn’t off-topic there. It’s the whole subject of the room.
And my topic never went live anyway. Staff deleted my account before any moderator approved it. Two minutes after that deletion, an F-Droid board member showed up on a different project’s GitHub tracker, called my report a bot, asked for it to be deleted, and wrote “Banned them. Reporting this as well.” He followed the report to another site to get it removed there too. That’s what the fdroid/admin issues are about. Not the licence. The deletion, and him.
Which leaves one comment on Telegram-FOSS 377, the only public thread about this app anywhere in a Telegram-fork community. Ten years of this, one comment.
Several people have now told me where I should have posted. Not one has told me which line is wrong. No hash, no commit date, no sentence of GPLv2 section 3 has been touched.
Want more data? All of it is here, every claim linked to something you can open yourself: https://opensource-compliance-gh.github.io/plus-messenger-gpl/