
Slither
Slither is a free open-source static analyzer for Solidity and Vyper used to find smart contract vulnerabilities before deployment for auditors.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 10 October 2026
- Links
- GitHub
What it is
A Python framework from Trail of Bits that converts contract source into an intermediate representation and runs a suite of bug detectors over it. Each finding is ranked by impact and confidence, and printers summarize contract structure for review.
What it helps with
- Flagging issues such as reentrancy, unprotected self-destruct, and risky arithmetic order
- Mapping inheritance, function permissions, and state variable access during a review
- Running inside Hardhat and Foundry projects and continuous integration
- Writing custom checks through its Python detector API
Who it's for
Smart contract auditors and Solidity developers reviewing code they own or are authorized to assess.
Worth knowing
A GitHub Action reports findings to GitHub code scanning on each pull request. Projects with imports must be analyzed through their build framework, since a lone file with dependencies will fail.
Is a commercial license available?
Yes, Trail of Bits offers exceptions to the AGPL terms on request.
Does it need a specific Solidity compiler version?
Yes, it needs the compiler version your contracts target, and the companion solc-select tool switches between versions.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.