Skip to content
Jjepeta.
ScannerGuidesEvidenceResearchDocs
Scan a token
TRUST / SOURCES

Sources & Trust Center

Provider roles, signals, freshness, failure behavior and limitations. This page is generated from config/providers.json, Jepeta's provider-governance source of truth.

Registry review: 2026-09-28 · Machine schema: 1.0.0
Machine JSONMethodologyPublic evidenceAPI docs

How to read provider status

Required means Jepeta cannot issue a verdict when required evidence is unusable. Optional sources add context or shadow evidence. Optional failure remains visible and never turns into a reassuring provider state. A source can be critical only to a named path without being required for the public V4 scan.

Provider output is evidence, not a Jepeta verdict. Providers are not listed in Jepeta's sameAs. Jepeta does not claim partnership, endorsement, certification, official integration, or provider authorization unless separately documented.

GoPlus Security

Status: active_required · Required: yes · Optional: no · Critical: yes — public_v4_scan, internal_full_scan

Role

required_security, token_security

Signals supplied

  • security.honeypot
  • supply.mintable
  • permissions.cannot_sell_all
  • permissions.cannot_buy
  • ownership.hidden_owner
  • permissions.owner_change_balance
  • permissions.selfdestruct
  • permissions.external_call
  • permissions.slippage_modifiable
  • permissions.personal_slippage_modifiable
  • permissions.transfer_pausable
  • permissions.trading_cooldown
  • permissions.is_blacklisted
  • ownership.can_take_back_ownership
  • verification.open_source
  • contract.is_proxy
  • market.buy_tax_percent
  • market.sell_tax_percent
  • holders.top10_concentration_percent
  • holders.top10_count
  • holders.reported_sample
  • liquidity.lp_locked_percent_observed
  • liquidity.lp_holder_sample_count

Freshness

Normalized GoPlus observations expire 120 seconds after retrieval. Required expired evidence is unusable and cannot produce a verdict. Maximum age: 120 seconds.

Failure semantics

  • 2 — PARTIAL_RETRYABLE -> HTTP 503 -> no verdict; bounded retry guidance only
  • 2021 — TOKEN_NOT_COVERED -> HTTP 422 -> no verdict
  • 4029 — RATE_LIMITED -> HTTP 429 -> no verdict; Retry-After when applicable
  • transport_429 — RATE_LIMITED -> HTTP 429 -> no verdict
  • timeout_or_unavailable — HTTP 503 -> no verdict
  • required_unknown — HTTP 422 -> no verdict

Limitations

  • Coverage is provider-dependent; TOKEN_NOT_COVERED is an explicit no-verdict condition.
  • Jepeta uses normalized signals and does not expose or redistribute raw GoPlus payloads.

Attribution and branding

  • Identify GoPlus as the source when GoPlus-derived security signals are materially presented.
  • No partnership, endorsement, certification, co-branding, or logo-use claim without separate documented authorization.

Public references

  • docs
  • rate_limits
  • service

Last reviewed: 2026-09-28

DEX Screener

Status: active_optional · Required: no · Optional: yes · Critical: no

Role

market_context, liquidity_context

Signals supplied

  • liquidity.usd
  • liquidity.matching_pair_addresses
  • market.volume_24h_usd
  • market.buys_24h
  • market.sells_24h

Freshness

Normalized DEX Screener observations expire 30 seconds after retrieval. Missing or expired optional market context remains explicit. Maximum age: 30 seconds.

Failure semantics

  • partial — source_status=PARTIAL; missing values remain null; cannot produce a clean PASS solely by normalizing missing market data
  • rate_limited — source_status=RATE_LIMITED; missing values remain null
  • unavailable — source_status=UNAVAILABLE; missing values remain null

Limitations

  • Context is limited to exact matching Base token pairs returned by the source and is not a complete market census.
  • DEX Screener is optional context; provider failure does not become a clean source status and does not supply a Jepeta verdict.

Attribution and branding

  • Identify DEX Screener as the source where its market context is materially presented.
  • No partnership, endorsement, certification, or unauthorized brand/logo use.

Public references

  • terms
  • docs

Last reviewed: 2026-09-28

Sourcify

Status: active_shadow_v2_readonly · Required: no · Optional: yes · Critical: no

Role

contract_verification, source_metadata

Signals supplied

  • verification.sourcify_status

Freshness

Sourcify shadow verification observations expire 300 seconds after retrieval. Maximum age: 300 seconds.

Failure semantics

  • shadow_only — EXACT_MATCH/MATCH/NOT_FOUND/UNAVAILABLE/RATE_LIMITED/ERROR are evidence-only and never affect V4 verdicts.
  • not_found — NOT_FOUND means only that Sourcify returned no record for the lookup; it is not proof that a contract is unverified.
  • failure — UNAVAILABLE/RATE_LIMITED/ERROR remain explicit evidence states and never become PASS.

Limitations

  • Stage 8 use remains optional shadow evidence only and does not independently set the public V4 verdict.
  • NOT_FOUND means only that the lookup returned no Sourcify record; it is not proof that a contract is unverified.

Attribution and branding

  • Preserve Sourcify provenance on observations derived from Sourcify.
  • No partnership, endorsement, certification, or unauthorized brand/logo use.

Public references

  • docs
  • api

Last reviewed: 2026-09-28

Base RPC / direct on-chain

Status: active_shadow_configured_rpc_and_settlement · Required: no · Optional: yes · Critical: yes — acp_settlement_only

Role

direct_onchain, settlement_verification

Signals supplied

  • contract.chain_id
  • contract.chain_id_matches_base
  • contract.exists
  • contract.bytecode_sha256
  • supply.total_supply_raw
  • contract.decimals
  • contract.symbol
  • contract.name
  • contract.eip1967_implementation_present
  • contract.eip1967_implementation_address

Freshness

Direct on-chain shadow observations expire 30 seconds after retrieval. Maximum age: 30 seconds.

Failure semantics

  • public_v4_scan — Shadow-only; RPC failure never changes or blocks the V4 response.
  • shadow_failure — Unavailable/rate-limited/error checks remain explicit evidence states and never become PASS.
  • existing_settlement_failure — Fail the affected settlement verification path; never infer successful settlement.

Limitations

  • Direct on-chain evidence remains optional shadow evidence for risk intelligence; it does not independently set the public V4 verdict.
  • Production shadow collection requires a fixed operator-configured production-suitable Base RPC; the public Base RPC is not used for production-scale evidence.

Attribution and branding

  • Record chain id 8453 and direct-on-chain provenance for derived observations.
  • No partnership, endorsement, or Base-affiliation claim.

Public references

  • network_notice

Last reviewed: 2026-09-28

Blockscout

Status: active_discovery_isolated_legacy_path_pending_terms_review · Required: no · Optional: yes · Critical: no

Role

token_discovery, explorer_index

Signals supplied

  • bounded token discovery candidates
  • explorer index context

Freshness

Used only inside bounded discovery/research workflows; it is not a V4/V5 verdict freshness source.

Failure semantics

  • discovery_failure — Skip/defer discovery work and record the provider failure; manual/core scans remain available.
  • public_v4_scan — Not a V4 verdict dependency and cannot create PASS/WARN/BLOCK.

Limitations

  • The current Blockscout path is isolated discovery only and is not a verdict authority.
  • Dependency expansion is blocked pending a fresh terms/API review.

Attribution and branding

  • Preserve Blockscout provenance for discovery observations.
  • No partnership, endorsement, certification, or unauthorized brand/logo use.

Public references

  • docs
  • limits
  • terms

Last reviewed: 2026-09-28

GeckoTerminal

Status: planned_disabled_pending_terms_review · Required: no · Optional: yes · Critical: no

Role

market_context_candidate

Signals supplied

  • none while disabled

Freshness

No production observations are collected while the provider remains disabled pending review.

Failure semantics

  • stage3 — Provider is disabled and performs no network calls; core/manual scan availability is unaffected.
  • future_optional_failure — Represent as partial/unavailable discovery context only; never create PASS/WARN/BLOCK.

Limitations

  • No production discovery or trust use is active in Stage 8.
  • Any future activation requires a separate terms review, adapter approval, provenance, and then-current attribution compliance.

Attribution and branding

  • Public API guide asks for link attribution; if enabled later, preserve source provenance and satisfy then-current attribution requirements.
  • No partnership, endorsement, certification, or unauthorized brand/logo use.

Public references

  • docs
  • guide
  • terms

Last reviewed: 2026-09-28

Decision ownership

Independent risk assessment by Jepeta. Upstream observations are normalized, compared for conflicts, and evaluated by Jepeta rules. PASS is not a safety guarantee and provider failure, UNKNOWN, UNAVAILABLE or PARTIAL states do not become PASS.

Jepeta Risk Guard · Base / 8453

Heuristic screening only. Not a smart-contract audit, safety guarantee, or investment recommendation.