A Solidity static analyzer to identify contract vulnerabilities and gas efficiencies.
js
.------. .------. .------. .------. .------. .------. .------.
|S.--. | |O.--. | |L.--. | |S.--. | |T.--. | |A.--. | |T.--. |
| :/\: | | :/\: | | :/\: | | :/\: | | :/\: | | (\/) | | :/\: |
| :\/: | | :\/: | | (__) | | :\/: | | (__) | | :\/: | | (__) |
| '--'S| | '--'O| | '--'L| | '--'S| | '--'T| | '--'A| | '--'T|
`------' `------' `------' `------' `------' `------' `------'
If you would like to quickly jump to any section, you can use the following links.
Currently Identified Optimizations, Vulnerabilities and QA
First, make sure that you have Rust installed. Then you can choose either of the installation methods by entering the corresponding command in your terminal below.
cargo install solstat
git clone https://github.com/0xKitsune/solstat &&
cd solstat &&
cargo install --path .
Now that you have Solstat invlolved, you can use the solstat
command from anywhere in your terminal. By default, Solstat looks for a ./contracts
directory and analyzes every file within the folder. If you would like to specify the directory Solstat should use, you can pass the --path
flag (ex. solstat --path <path_to_dir>
).
In the default configuration, Solstat runs analysis for every currently included Optimization, Vulnerability and QA, however if you would like to run analysis for select patterns, you can create a .toml
file for your custom configuration. Check out the default Solstat.toml configuration for reference. After creating a custom .toml
file, make sure to pass the --toml
flag when running Solstat (ex. solstat --toml <path_to_toml_file>
).
Once Solstat runs its analysis, a report will be generated and output as solstat_report.md
.
At any point you can use solstat --help
to see a list of all commands and options.
``` Usage: solstat [OPTIONS]
Options:
-p, --path ./contracts
-t, --toml
Below are the currently identified optimizations, vulnerabilities and qa patterns that Solstat identifies. If you would like to check out a list of patterns that are ready to be implemented and you would like to add them to the repo, you can check out the Contribution.md!
selfbalance()
instead of address(this).balance
.address(0)
.array[index] += amount
is cheaper than array[index] = array[index] + amount
. This optimization also catches other arithmetic, bitwise and other operations.if (x == bool)
, use if(x)
or when applicable, use assembly with iszero(iszero(x))
.constant
if they never change and are not marked as constants.immutable
if variables are assigned during deployment and never change afterwards. unchecked{++i}
instead of i++
, or ++i
(or use assembly when applicable). This also applies to decrementing as well.calldata
for function arguments marked as memory
that do not get mutated.Contributions are welcome and encouraged! If you are interested in contributing, please check out the Contributing.md file.