ContractLens.
A self-hosted Solidity risk scanner that runs entirely on your machine.
ContractLens is automated static analysis for Solidity. Paste a contract into the built-in editor, or scan a whole project from the command line, and get findings with exact source locations, plain-English explanations, remediation guidance, and an Automated Risk Score. It runs locally in Docker or Node, works offline, needs no account, and never uploads your code. It is a risk-screening tool, not a substitute for a professional security audit.
Automated Risk Score
- 10
- AST-based security rules
- 32
- scanner tests, all passing
- 0 bytes
- of your source ever uploaded
- 3
- ways in: web app, CLI, library
From paste to findings in seconds.
This is the real workspace, showing the result of scanning the contract bundled with the download. Click a finding to jump to its line.
Automated Risk Score
More than a linter.
A scanner, a workspace, and a command line, all in one download and all running locally.
Ten rules that read the AST, not regexes
Your Solidity is parsed into a syntax tree and checked by ten focused rules: reentrancy ordering, tx.origin authorization, unchecked low-level calls, delegatecall, unprotected sensitive functions, timestamp dependence, weak randomness, floating pragmas, selfdestruct and inline assembly.
An Automated Risk Score you can read at a glance
Findings are weighted by severity and mapped onto a 0–100 score with a saturating curve, so a couple of findings never max it out and a pile of them clearly does. A severity breakdown sits beside it.
A real editor, not a text box
The web workspace embeds Monaco with Solidity highlighting. Filter findings by severity, click one to jump to the exact line, press Cmd/Ctrl + Enter to analyze, or load the built-in educational contract to see it work in seconds.
A CLI built for projects and CI
Point it at a file or a whole directory. It skips node_modules, build output and caches, prefixes every finding with its path and line, and offers a --fail-on gate that exits non-zero when a finding reaches the severity you choose.
Reports you can hand to someone
Export Markdown or JSON from the web UI or the CLI. Each finding carries its severity, rule, location, confidence, impact, recommendation and code snippet, followed by an honest disclaimer.
Private by construction
No upload, no account, no telemetry, no CDN. Fonts and the Monaco editor are bundled, so once it is running it works offline. Only your light/dark theme choice is stored in the browser; your source never is.
Scan one file or a whole codebase
The CLI walks a directory and scans every .sol file. The web app's Project tab merges results from several uploaded files for small folders. Files that fail to parse are skipped instead of failing the run.
Every rule explains itself
Each rule has its own documentation page inside the app with what it detects, why it matters and how to fix it. Findings state their confidence, so you know which ones to look at first.
Four steps, all local.
- 1
Paste or point
Drop Solidity into the editor, upload .sol files, or point the CLI at a directory. Nothing leaves your machine.
- 2
Parse to an AST
A Solidity parser turns each source into a syntax tree, with friendly errors when a file will not parse.
- 3
Run the ten rules
Each rule walks the tree and reports findings with severity, confidence, exact location and remediation guidance.
- 4
Score and report
Findings are de-duplicated, sorted by line, scored 0–100, and exported as Markdown or JSON, or gated in CI.
$ node packages/cli/bin/contractlens.js scan ./examples
ContractLens scan of examples
Automated Risk Score: 67 / 100
Contracts: 1 Functions: 6 Files: 1 Duration: 53ms
critical 0
high 2
medium 1
low 2
info 0
[HIGH] tx.origin Authorization — examples/EducationalExample.sol:15 (SC002, confidence: high)
tx.origin is used inside an authorization condition (require/assert).
[HIGH] Potential Reentrancy Risk — examples/EducationalExample.sol:22 (SC001, confidence: medium)
Function "withdraw" may perform a state update after an external call…
[MEDIUM] Potentially Unprotected Sensitive Function — examples/EducationalExample.sol:37 (SC005)
Function "mint" looks like a privileged operation but no access control was found.
… (recommendations and two low findings omitted here)
Real output from the bundled example (abridged).
What it looks for.
Ten rules, each one file in the scanner package, each documented inside the app with what it detects and how to fix it.
- SC001Potential Reentrancy RiskHighAn external call followed by a write to contract state in the same function.
- SC002tx.origin AuthorizationHightx.origin used in a require/assert or if condition.
- SC007Weak Randomness SourceHighblock.timestamp, blockhash or prevrandao feeding values in randomness-named functions or variables.
- SC003Unchecked Low-Level CallMediumcall, delegatecall or staticcall whose success value is discarded.
- SC004Dangerous delegatecallMediumAny use of delegatecall, flagged for manual review.
- SC005Potentially Unprotected Sensitive FunctionMediumPublic or external functions with privileged names (mint, burn, withdraw, upgrade…) and no access-control modifier or inline check.
- SC006Block Timestamp DependenceLowblock.timestamp inside conditions and comparisons.
- SC008Floating PragmaLowpragma solidity ranges (^, ~, >=) instead of a pinned version.
- SC009selfdestruct UsageInfoCalls to selfdestruct or suicide.
- SC010Inline AssemblyInfoassembly { … } blocks.
Running in a minute.
Unzip the download and pick the way you like to work.
Option 1
Docker
One command, nothing to install but Docker
docker compose up -d
# open http://localhost:3000No environment variables needed. Change the left side of 3000:3000 in docker-compose.yml to use another port.
Option 2
Command line
Scan files or whole projects, gate CI
pnpm install
node packages/cli/bin/contractlens.js scan ./contracts --fail-on high --format markdown --output report.mdExit code 1 when a finding reaches the --fail-on severity, so any CI that can run a shell command can enforce it.
Option 3
Local development
Hack on the web app and the scanner
pnpm dev # web app on http://localhost:3000
pnpm test # scanner test suite
pnpm typecheck && pnpm lintRequires Node.js 24+ and pnpm 12.6+. See the README for a Corepack workaround.
Built to be read.
A TypeScript monorepo with a clean seam: the scan engine has no React or DOM dependencies, so the web app and the CLI share exactly the same brain.
- 01
Source
Solidity text
- 02
Parser
AST + friendly errors
- 03
Rules
SC001 – SC010
- 04
Dedupe + sort
By line
- 05
Score
0 – 100
- 06
Report
UI · MD · JSON
What is in the box
apps/webNext.js app: Monaco editor, findings, rule docspackages/scannerScan engine, free of React and DOM dependenciespackages/sharedMarkdown and JSON report builderspackages/cliThe contractlens commandexamplesSample contract to try the CLI on
Stack
Third-party components keep their own licences, listed in THIRD-PARTY-NOTICES.md inside the download.
Your contracts never leave.
Your code stays put
Analysis runs in your browser or your local process. Source is never uploaded, logged or sent anywhere.
Works offline
Fonts and the Monaco editor are bundled, not loaded from a CDN. After installation there are no network calls.
No account, no telemetry
There is nothing to sign up for and nothing phoning home. The only thing stored in your browser is your theme choice.
A screen, not an audit.
- It is a screening step, not a security audit. A clean scan does not mean a contract is secure.
- Automated static analysis only: no business-logic, economic, oracle or cross-contract analysis.
- Each file is parsed on its own; imports are not followed.
- Rules are heuristics. Expect false positives and false negatives; every finding states its confidence.
- Sources over 200,000 characters are rejected in the browser.
Questions worth asking.
Is ContractLens a security audit?
No. It is automated static analysis that screens for common risk patterns. It cannot find every vulnerability class, and findings can be false positives. Have contracts that will hold real value reviewed by a professional auditor.
Does my source code get uploaded anywhere?
No. Analysis happens in your browser or in a local process. There is no account, no analytics and no telemetry, and the app works offline once it is running.
What do I need to run it?
Docker Desktop (or Docker Engine with Compose) for the packaged web app, or Node.js 24+ and pnpm 12.6+ for local development and the CLI. A modern browser for the web workspace.
Can I use it in CI?
Yes, with the CLI: run a scan with --fail-on high (or any severity) and the command exits with code 1 when a finding reaches that level. Reports can be written as Markdown or JSON. Remember the licence: this freebie is for personal, non-commercial use.
Can I use ContractLens at work or for client contracts?
Not under the free licence, which covers personal, non-commercial use only. If you need commercial use, write to the studio and we can agree a commercial licence.
Can I add my own rules?
Yes, for your own use. Rules are one file each in the scanner package, registered in a single list, with fixtures and tests. The README walks through it. The licence does not allow redistributing modified copies.
Does it follow imports?
No. Each file is parsed on its own. For multi-file projects, use the CLI so every .sol file is scanned and findings are prefixed with their file path.
Free for you, owned by the studio.
Enter your email and we will send a private download link for ContractLens v1.0.0. It is licensed to you for personal, non-commercial use only; Northline Studio owns the software and keeps all rights.
- Web app, scanner engine, and CLI source (TypeScript monorepo)
- Dockerfile and docker-compose.yml for one-command setup
- Example contracts to try the scanner on
- README.md, THIRD-PARTY-NOTICES.md, and LICENSE.txt
- Needs: Docker Desktop, or Node.js 24+ with pnpm
- Needs: A modern browser
Read the full licence. Need commercial use? Write to hello@northlinestudio.dev.
Released 24 Sep 2026 · v1.0.0