Public scan registry
Scans of deployed contracts that their owners chose to publish. Every entry can be checked by anyone: open it and your own browser re-runs the same engine version on the same verified source. A record that does not match what your browser finds is shown in red — so an entry here never asks you to take a number on trust.
Re-checked when you open itThe engine is downloaded with its sha-256 enforced by your browser, and the source comes from the explorer — not from the publisher.
Deployed contracts onlyPasted code cannot be published: nobody else could fetch the same source to check it.
An automated scan, not an audit201 detectors on the verified source. A clean result means nothing matched — not that the contract is safe.
Loading the registry…
Get your contract listed
- Scan the deployed contract on the scanner — by address, with its source verified on the explorer.
- Sign in (a free account) so the report has an owner who can withdraw it.
- Press Publish a public report under the result. You get a link at
saferico.com/r/…, and the registry entry if you leave “list it” ticked.
Where the numbers come from
- The scan ran in the publisher's browser. Only finding ids, severities and function names were sent — the server recomputes the score from them.
- When you open an entry, your browser downloads the same engine version, checks its sha-256, fetches the verified source from the explorer and runs the scan again.
- If the two disagree, the page says so in red and shows what your browser found. The score in this list is the one that was published; opening an entry is what checks it.
An entry is an automated scan of verified source, published by an account — not a manual audit, and not an endorsement by SaferICO. For a human review, see published audits or request one.