Every project here has
been security reviewed.
GreenLight is a security review for utility and tech projects on Solana, BNB Smart Chain and Robinhood Chain. We connect a wallet, work through every signature the site asks you for, and read the contract when the source exists. Not a token scanner, and not a score out of a hundred.
Every review is dated and every report publishes the fingerprints of exactly what was looked at, so you can check for yourself whether a site has changed since. Reviews expire, and we take a badge back when we learn something that warrants it.
Reviews are done one project at a time. Turnaround depends on the queue.
Why not just trust the project
All of this runs on trust, and the only thing you are usually handed to trust is the project’s own word about its own code.
A team saying their contract is safe is not evidence. Neither is a green tick from a scanner that read the token’s mint authority and never opened the site. Between a project’s claim and your wallet there should be somebody with no stake in the outcome who actually looked.
That is the whole job. We have no position in the token, we publish the result either way, and we publish the evidence underneath it so you are not taking our word for it either.
What gets reviewed
The risk is in the app, not the ticker. A token with nothing to connect to has no connect flow to abuse, no signature to disguise and usually no contract logic worth reading. What is worth reviewing is a project that actually does something: a swap, a staking page, a claim, a bridge. That is where people lose money, and it is the part no scanner can read for you.
Wallet connection
What the site asks your wallet for when you connect, and whether connecting alone can cost you anything.
Transactions and signatures
Every transaction and signature the site puts in front of you, and whether what it shows matches what it does.
Contract code
The deployed contract, when the source is public or the team supplies it. Verified against what is actually on chain.
The third one is conditional. Plenty of projects ship without verified source, and if we cannot read the contract the report says so in the same breath as everything we could read. Reading deployed bytecode is not reading code, and we will not present it as though it were.
The registry
full registry →
No reviews published yet.
Revocations stay listed. A registry that only shows passes is an advertisement, not a record.