pactlint: scan Solidity source
scan_contract_sourcepactlint: static security scan of Solidity source code, before you deploy, review or depend on a contract. Input: source (one .sol file, no imports, up to 200 KB) or standard_json (solc standard-JSON input with every import inline, up to 1 MB and 500 files); optional filename, compiler_version (X.Y.Z; default from the pragma) and the include_* flags. Checks: solc + Slither + custom detectors for recurring DeFi bug classes (unchecked ERC-20 returns, zero slippage limits, stale or spot-price oracles, ERC-4626 share inflation, signature replay and more), triaged and de-duplicated. Returns the JSON report (status; findings with severity, confidence, file:line, explanation and recommendation) plus a Markdown rendering. Price: USD 0.25 up to 3,000 normalised source lines (nSLOC), USD 0.75 up to 15,000; larger inputs are refused. Refused inputs are never charged. Free: 3 scans or 30 txpeek checks per IP per UTC day (one shared pool). Typically 1-5 s for one file and up to about 30 s for a large project; at most 60 s per scan (past it: status timeout), one scan at a time; a request waits at most 25 s in a queue of 3 (less when paid, so every answer arrives within about 90 s), otherwise 503 with Retry-After, not charged. Automated and heuristic, not an audit: findings can be false positives and an empty report does not prove the code is free of bugs.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| source | No | A single Solidity file (no imports). Give either source or standard_json. | |
| filename | No | Contract.sol | |
| include_noisy | No | ||
| standard_json | No | solc standard-JSON input with inline 'content' for every file. | |
| compiler_version | No | Exact solc version (default: from pragma). | |
| include_dependencies | No | ||
| include_informational | No |