jepeta.
Jepeta/Articles/research
original research

Jepeta source audit: where token security evidence stops

Audit the boundary between Jepeta scanner evidence and external security guidance.

Direct answer

Jepeta's public methodology is designed to expose evidence rather than certify safety. This audit compares that methodology with Base security guidance and records the boundary: scanner signals can support a risk decision, while application behavior and user-granted permissions still require separate verification.

Audit method and evidence

Jepeta's public methodology treats scanner output as evidence-led screening and explicitly stops short of calling a result a safety guarantee or contract audit.

Base security guidance adds controls outside a token-risk verdict, including contract verification, minimizing exposure of user funds and transparent onchain interactions.

Jepeta findings

The source audit therefore identifies a deliberate boundary: scanner evidence can inform a token decision while application behavior and user-granted permissions still need separate checks.

Jepeta should present the scanner as one evidence layer in a broader security workflow, not as a replacement for permission review or application verification.

Research limits

This pilot research reports what the cited evidence supports and records its boundary. It does not generalize the findings beyond the audited sources.

Original Jepeta evidence

  • jepeta data — Source audit compares Jepeta screening methodology with Base application controls. It identifies permission review and application verification as checks outside a scanner verdict. · observed Oct 5, 2026

Sources

Related Jepeta resources