Open Dollar - dApp

Off-Chain (Public)
Audited on 2024/04/24
No active critical issues

Summary

Our assessment focused on the security of OpenDollar's front-end application. During our security review, we focused on assessing the secure configuration of HTTP headers, potential XSS, HTML injections, prototype pollutions, and other client-side attacks. The scope of this project is relatively small and the attack surface is narrow. The Quantstamp team found 4 low- and 4 informational-severity findings. No vulnerabilities with direct harm to the decentralized application were found, however, it is still recommended to address all the issues to harden the system and reduce the possibility of an attack. In addition to security concerns, we also identified UI/UX issues that could disrupt users from engaging with the application as intended, practically leading to a DoS for the end-users. The testing, conducted on an environment specifically prepared by the OpenDollar team for this audit, revealed that certain functionalities consistently failed, impeding the standard user workflow. While most of the functionalities were flawless in the main staging application. Identifying and resolving the causes of these UI/UX issues is crucial to prevent their recurrence in the production stage. In addition, the OpenDollar front-end does not employ any automated software testing scripts such as unit tests, integration tests, or end-to-end tests, which are recommended to avoid introducing bugs in subsequent code commits.


Issues (8)

Low
Medium
High
Critical
Total
Not fixed
5---5
Acknowledged
----0
Fixed
3---3
Total80008


Contracts (345)

Open Dollar Security Smart Contract Audit | Trustblock