Unused variables, unreachable branches, or commented-out guards indicate incomplete logic; a 'critical' variable that is set but never enforced can mean a missing security check.
modifier whenNotPaused(){ require(!paused, "paused"); _; }
// apply to the functions that must respect pause
Largest recorded losses in the same failure class — related, not the same bug:
The SaferICO scanner runs 201 detectors over your Solidity source, SAFE-0077 among them. Paste an address or the source itself — a small per-scan fee, shown before you sign, or unlimited on any plan.