Solidity risk screening, on your own machine

ContractLens.

A self-hosted Solidity risk scanner that runs entirely on your machine.

FreePersonal use onlyv1.0.0244 KBmacOSWindowsLinux

ContractLens is automated static analysis for Solidity. Paste a contract into the built-in editor, or scan a whole project from the command line, and get findings with exact source locations, plain-English explanations, remediation guidance, and an Automated Risk Score. It runs locally in Docker or Node, works offline, needs no account, and never uploads your code. It is a risk-screening tool, not a substitute for a professional security audit.

ContractLens · scan result
67
of 100

Automated Risk Score

Critical0
High2
Medium1
Low2
Info0
5 findings6 functions · 53 ms
10
AST-based security rules
32
scanner tests, all passing
0 bytes
of your source ever uploaded
3
ways in: web app, CLI, library
See it work

From paste to findings in seconds.

This is the real workspace, showing the result of scanning the contract bundled with the download. Click a finding to jump to its line.

EducationalExample.sol
1// SPDX-License-Identifier: UNLICENSED
2pragma solidity ^0.8.0;SC008
3
4// Educational Example — illustrates several common Solidity risk patterns
5// so you can see what ContractLens detects. Do not deploy this as-is.
6contract EducationalExample {
7 address public owner;
8 mapping(address => uint256) public balances;
9
10 constructor() {
11 owner = msg.sender;
12 }
13
14 // tx.origin should not be used for authorization.
15 function adminWithdraw(uint256 amount) public {
16 require(tx.origin == owner, "not owner");SC002
17 payable(owner).transfer(amount);
18 }
19
20 // External call happens before the state update (reentrancy risk).
21 function withdraw(uint256 amount) public {
22 require(balances[msg.sender] >= amount, "insufficient balance");
23 (bool sent, ) = msg.sender.call{value: amount}("");SC001
24 require(sent, "transfer failed");
25 balances[msg.sender] -= amount;
26 }
27
28 function deposit() public payable {
29 balances[msg.sender] += msg.value;
30 }
31
32 // block.timestamp used for time-based logic.
33 function isAfterLaunch(uint256 launchTime) public view returns (bool) {
34 return block.timestamp >= launchTime;SC006
35 }
36
37 // Sensitive function with no visible access control.
38 function mint(address to, uint256 amount) public {SC005
39 balances[to] += amount;
40 }
41}
67
of 100

Automated Risk Score

Critical0
High2
Medium1
Low2
Info0
5 findings6 functions · 53 ms
Selected finding: tx.origin Authorization
What you get

More than a linter.

A scanner, a workspace, and a command line, all in one download and all running locally.

Ten rules that read the AST, not regexes

Your Solidity is parsed into a syntax tree and checked by ten focused rules: reentrancy ordering, tx.origin authorization, unchecked low-level calls, delegatecall, unprotected sensitive functions, timestamp dependence, weak randomness, floating pragmas, selfdestruct and inline assembly.

An Automated Risk Score you can read at a glance

Findings are weighted by severity and mapped onto a 0–100 score with a saturating curve, so a couple of findings never max it out and a pile of them clearly does. A severity breakdown sits beside it.

A real editor, not a text box

The web workspace embeds Monaco with Solidity highlighting. Filter findings by severity, click one to jump to the exact line, press Cmd/Ctrl + Enter to analyze, or load the built-in educational contract to see it work in seconds.

A CLI built for projects and CI

Point it at a file or a whole directory. It skips node_modules, build output and caches, prefixes every finding with its path and line, and offers a --fail-on gate that exits non-zero when a finding reaches the severity you choose.

Reports you can hand to someone

Export Markdown or JSON from the web UI or the CLI. Each finding carries its severity, rule, location, confidence, impact, recommendation and code snippet, followed by an honest disclaimer.

Private by construction

No upload, no account, no telemetry, no CDN. Fonts and the Monaco editor are bundled, so once it is running it works offline. Only your light/dark theme choice is stored in the browser; your source never is.

Scan one file or a whole codebase

The CLI walks a directory and scans every .sol file. The web app's Project tab merges results from several uploaded files for small folders. Files that fail to parse are skipped instead of failing the run.

Every rule explains itself

Each rule has its own documentation page inside the app with what it detects, why it matters and how to fix it. Findings state their confidence, so you know which ones to look at first.

How it works

Four steps, all local.

  1. 1

    Paste or point

    Drop Solidity into the editor, upload .sol files, or point the CLI at a directory. Nothing leaves your machine.

  2. 2

    Parse to an AST

    A Solidity parser turns each source into a syntax tree, with friendly errors when a file will not parse.

  3. 3

    Run the ten rules

    Each rule walks the tree and reports findings with severity, confidence, exact location and remediation guidance.

  4. 4

    Score and report

    Findings are de-duplicated, sorted by line, scored 0–100, and exported as Markdown or JSON, or gated in CI.

contractlens: zsh
$ node packages/cli/bin/contractlens.js scan ./examples
ContractLens scan of examples
Automated Risk Score: 67 / 100
Contracts: 1  Functions: 6  Files: 1  Duration: 53ms

  critical 0
  high     2
  medium   1
  low      2
  info     0

[HIGH] tx.origin Authorization — examples/EducationalExample.sol:15 (SC002, confidence: high)
  tx.origin is used inside an authorization condition (require/assert).
[HIGH] Potential Reentrancy Risk — examples/EducationalExample.sol:22 (SC001, confidence: medium)
  Function "withdraw" may perform a state update after an external call…
[MEDIUM] Potentially Unprotected Sensitive Function — examples/EducationalExample.sol:37 (SC005)
  Function "mint" looks like a privileged operation but no access control was found.
  … (recommendations and two low findings omitted here)

Real output from the bundled example (abridged).

Rules reference

What it looks for.

Ten rules, each one file in the scanner package, each documented inside the app with what it detects and how to fix it.

  • SC001Potential Reentrancy RiskHighAn external call followed by a write to contract state in the same function.
  • SC002tx.origin AuthorizationHightx.origin used in a require/assert or if condition.
  • SC007Weak Randomness SourceHighblock.timestamp, blockhash or prevrandao feeding values in randomness-named functions or variables.
  • SC003Unchecked Low-Level CallMediumcall, delegatecall or staticcall whose success value is discarded.
  • SC004Dangerous delegatecallMediumAny use of delegatecall, flagged for manual review.
  • SC005Potentially Unprotected Sensitive FunctionMediumPublic or external functions with privileged names (mint, burn, withdraw, upgrade…) and no access-control modifier or inline check.
  • SC006Block Timestamp DependenceLowblock.timestamp inside conditions and comparisons.
  • SC008Floating PragmaLowpragma solidity ranges (^, ~, >=) instead of a pinned version.
  • SC009selfdestruct UsageInfoCalls to selfdestruct or suicide.
  • SC010Inline AssemblyInfoassembly { … } blocks.
Quick start

Running in a minute.

Unzip the download and pick the way you like to work.

Option 1

Docker

One command, nothing to install but Docker

ShellShell
docker compose up -d
# open http://localhost:3000

No environment variables needed. Change the left side of 3000:3000 in docker-compose.yml to use another port.

Option 2

Command line

Scan files or whole projects, gate CI

ShellShell
pnpm install
node packages/cli/bin/contractlens.js scan ./contracts --fail-on high --format markdown --output report.md

Exit code 1 when a finding reaches the --fail-on severity, so any CI that can run a shell command can enforce it.

Option 3

Local development

Hack on the web app and the scanner

ShellShell
pnpm dev        # web app on http://localhost:3000
pnpm test       # scanner test suite
pnpm typecheck && pnpm lint

Requires Node.js 24+ and pnpm 12.6+. See the README for a Corepack workaround.

Under the hood

Built to be read.

A TypeScript monorepo with a clean seam: the scan engine has no React or DOM dependencies, so the web app and the CLI share exactly the same brain.

  1. 01

    Source

    Solidity text

  2. 02

    Parser

    AST + friendly errors

  3. 03

    Rules

    SC001 – SC010

  4. 04

    Dedupe + sort

    By line

  5. 05

    Score

    0 – 100

  6. 06

    Report

    UI · MD · JSON

What is in the box

  • apps/webNext.js app: Monaco editor, findings, rule docs
  • packages/scannerScan engine, free of React and DOM dependencies
  • packages/sharedMarkdown and JSON report builders
  • packages/cliThe contractlens command
  • examplesSample contract to try the CLI on

Stack

TypeScriptNext.js 16React 19Monaco EditorTailwind CSS@solidity-parser/parserVitestDocker

Third-party components keep their own licences, listed in THIRD-PARTY-NOTICES.md inside the download.

Privacy

Your contracts never leave.

  • Your code stays put

    Analysis runs in your browser or your local process. Source is never uploaded, logged or sent anywhere.

  • Works offline

    Fonts and the Monaco editor are bundled, not loaded from a CDN. After installation there are no network calls.

  • No account, no telemetry

    There is nothing to sign up for and nothing phoning home. The only thing stored in your browser is your theme choice.

Honest limits

A screen, not an audit.

  • It is a screening step, not a security audit. A clean scan does not mean a contract is secure.
  • Automated static analysis only: no business-logic, economic, oracle or cross-contract analysis.
  • Each file is parsed on its own; imports are not followed.
  • Rules are heuristics. Expect false positives and false negatives; every finding states its confidence.
  • Sources over 200,000 characters are rejected in the browser.
FAQ

Questions worth asking.

Is ContractLens a security audit?

No. It is automated static analysis that screens for common risk patterns. It cannot find every vulnerability class, and findings can be false positives. Have contracts that will hold real value reviewed by a professional auditor.

Does my source code get uploaded anywhere?

No. Analysis happens in your browser or in a local process. There is no account, no analytics and no telemetry, and the app works offline once it is running.

What do I need to run it?

Docker Desktop (or Docker Engine with Compose) for the packaged web app, or Node.js 24+ and pnpm 12.6+ for local development and the CLI. A modern browser for the web workspace.

Can I use it in CI?

Yes, with the CLI: run a scan with --fail-on high (or any severity) and the command exits with code 1 when a finding reaches that level. Reports can be written as Markdown or JSON. Remember the licence: this freebie is for personal, non-commercial use.

Can I use ContractLens at work or for client contracts?

Not under the free licence, which covers personal, non-commercial use only. If you need commercial use, write to the studio and we can agree a commercial licence.

Can I add my own rules?

Yes, for your own use. Rules are one file each in the scanner package, registered in a single list, with fixtures and tests. The README walks through it. The licence does not allow redistributing modified copies.

Does it follow imports?

No. Each file is parsed on its own. For multi-file projects, use the CLI so every .sol file is scanned and findings are prefixed with their file path.

Get it

Free for you, owned by the studio.

Enter your email and we will send a private download link for ContractLens v1.0.0. It is licensed to you for personal, non-commercial use only; Northline Studio owns the software and keeps all rights.

  • Web app, scanner engine, and CLI source (TypeScript monorepo)
  • Dockerfile and docker-compose.yml for one-command setup
  • Example contracts to try the scanner on
  • README.md, THIRD-PARTY-NOTICES.md, and LICENSE.txt
  • Needs: Docker Desktop, or Node.js 24+ with pnpm
  • Needs: A modern browser

Read the full licence. Need commercial use? Write to hello@northlinestudio.dev.

Get ContractLens free

Enter your email and we will send you a private download link.

We use your email to deliver the download. See the privacy policy.

Released 24 Sep 2026 · v1.0.0

Have a product to sell? We review, list, and sell it for you — you keep 90% of every sale.

Apply to sell with us