Security Score

Project security checklist

Answer each item and a weighted 0-100 score is calculated in real time. Unanswered items count as zero, so a complete checklist is needed for a reliable result.

Smart contract audits

Evaluates whether external security audits exist and how rigorous they are.

0 / 36
0%
Highest-tier audit firmw12

What is the highest-tier firm that has audited this project?

Number of independent auditsw8

Number of audit reports from different firms.

Time since last auditw6

Time since the most recent audit covering deployed code.

Audit reports publicw4

PDF reports are accessible at a public, unrestricted location.

Critical/High issues resolvedw6

All reported Critical/High findings are fixed or explicitly accepted.

Code quality

Engineering maturity: tests, documentation, formal verification.

0 / 22
0%
Test coveragew6

Line and branch coverage levels.

Open-sourcedw5

Production contract source is in a public repository.

On-chain source verifiedw4

Source is verified on Etherscan or equivalent.

Formal verification appliedw4

Core invariants verified with Certora, K, Halmos, or similar tools.

Fuzzing / invariant testsw3

Repository contains Foundry or Echidna invariant tests.

Operational security

Admin keys, upgrade paths, timelocks, and operational controls.

0 / 22
0%
Admin multisigw7

Admin keys are operated through a multisig such as Safe.

Timelockw5

Admin actions are gated through a timelock.

Upgrade pathw4

Whether and how the contracts can be upgraded.

Emergency pausew3

Critical functions support a pause or circuit breaker.

On-chain monitoringw3

Real-time monitoring via Forta, Tenderly, Phalcon, or similar.

Bug bounty

Size and operation of external whitehat incentives.

0 / 11
0%
Bounty platformw4

Where the official bug bounty program runs.

Maximum rewardw5

Top payout for a Critical issue.

Scope and PoC requirements clearw2

Scope, severity rules, and PoC requirements are documented.

Decentralization & dependencies

Oracle, bridge, and governance dependency risks.

0 / 12
0%
Oracle designw5

Safety and diversity of price feeds.

Governancew4

Token power distribution, proposal periods, and quorum.

Bridge dependencyw3

Whether external bridges sit in the critical fund flow.

Incident response

Incident history and response transparency.

0 / 8
0%
Past incidentsw4

History of significant fund loss.

Postmortem policyw2

Explicit policy committing to publishing incident postmortems.

War-room / contact channelw2

Documented 24/7 security contact channel and SLA.