Get only the source-code findings for a contract
curl --request GET \
--url https://api.webacy.com/contracts/{contractAddress}/code-analysis \
--header 'x-api-key: <api-key>'import requests
url = "https://api.webacy.com/contracts/{contractAddress}/code-analysis"
headers = {"x-api-key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'x-api-key': '<api-key>'}};
fetch('https://api.webacy.com/contracts/{contractAddress}/code-analysis', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.webacy.com/contracts/{contractAddress}/code-analysis",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.webacy.com/contracts/{contractAddress}/code-analysis"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("x-api-key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.webacy.com/contracts/{contractAddress}/code-analysis")
.header("x-api-key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.webacy.com/contracts/{contractAddress}/code-analysis")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["x-api-key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"analysis": {
"contract_address": "0x1234567890123456789012345678901234567890",
"chain": "eth",
"analysis_date": "2023-11-15T10:30:00Z",
"status": "completed",
"findings": [
{
"risk": "reentrancy",
"details": {},
"function_signatures": [
{
"function_name": "withdraw",
"function_signature": "function withdraw(uint256 amount) external"
}
],
"statements": [
{
"statement_type": "call",
"statement_text": "msg.sender.call{value: amount}(\"\")"
}
]
}
],
"urls": [
{
"url": "https://example.com/analysis-report"
}
]
}
}{
"error": "Invalid contract address format"
}{
"message": "Unauthorized"
}{
"x402Version": 1,
"error": "payment required"
}{
"message": "Contract analysis not found"
}{
"message": "Rate limit exceeded. Please try again later."
}{
"message": "Payment service temporarily unavailable"
}Smart Contract
Get only the source-code findings for a contract address
Returns just the source-code (Solidity) analysis for a contract: the same source_code_analysis block already embedded in the real-time endpoint (GET /contracts/). Use this when you want the source-code findings alone, without the rest of the risk payload. If you already call the real-time endpoint, you don’t need this one.
GET
/
contracts
/
{contractAddress}
/
code-analysis
Get only the source-code findings for a contract
curl --request GET \
--url https://api.webacy.com/contracts/{contractAddress}/code-analysis \
--header 'x-api-key: <api-key>'import requests
url = "https://api.webacy.com/contracts/{contractAddress}/code-analysis"
headers = {"x-api-key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'x-api-key': '<api-key>'}};
fetch('https://api.webacy.com/contracts/{contractAddress}/code-analysis', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.webacy.com/contracts/{contractAddress}/code-analysis",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.webacy.com/contracts/{contractAddress}/code-analysis"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("x-api-key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.webacy.com/contracts/{contractAddress}/code-analysis")
.header("x-api-key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.webacy.com/contracts/{contractAddress}/code-analysis")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["x-api-key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"analysis": {
"contract_address": "0x1234567890123456789012345678901234567890",
"chain": "eth",
"analysis_date": "2023-11-15T10:30:00Z",
"status": "completed",
"findings": [
{
"risk": "reentrancy",
"details": {},
"function_signatures": [
{
"function_name": "withdraw",
"function_signature": "function withdraw(uint256 amount) external"
}
],
"statements": [
{
"statement_type": "call",
"statement_text": "msg.sender.call{value: amount}(\"\")"
}
]
}
],
"urls": [
{
"url": "https://example.com/analysis-report"
}
]
}
}{
"error": "Invalid contract address format"
}{
"message": "Unauthorized"
}{
"x402Version": 1,
"error": "payment required"
}{
"message": "Contract analysis not found"
}{
"message": "Rate limit exceeded. Please try again later."
}{
"message": "Payment service temporarily unavailable"
}This returns only the
source_code_analysis block, which is already embedded in the full contract risk report. If you already call that endpoint, you don’t need this one.Authorizations
Path Parameters
Contract address to analyze
Query Parameters
Selected chain. This includes 'eth', 'base', 'bsc', 'pol', 'opt' and 'arb'. Supported blockchain networks
Available options:
eth, base, bsc, pol, opt, arb, hedera Re-analyze contract address and retrieve fresh data
Response
Success - Returns analysis results, an informational message, or an error message for unsupported chains
- Option 1
- Option 2
- Option 3
Show child attributes
Show child attributes
