SportsFansZone.addLiquidity(uint256,uint256) (#1868-1883) sends eth to arbitrary user
Dangerous calls:
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
SportsFansZone.sendHolderDividends(uint256) (#1884-1891) sends eth to arbitrary user
Dangerous calls:
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
Ensure that an arbitrary user cannot withdraw unauthorized funds.
Additional information: link
Reentrancy in SportsFansZone._transfer(address,address,uint256) (#1738-1810):
External calls:
- swapAndDistribute(balanceOf(address(this))) (#1776)
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
- uniswapV2Router.swapExactTokensForETHSupportingFeeOnTransferTokens(tokenAmount,0,path,address(this),block.timestamp) (#1858-1864)
External calls sending eth:
- swapAndDistribute(balanceOf(address(this))) (#1776)
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
State variables written after the call(s):
- super._transfer(from,address(this),fees) (#1792)
- _balances[sender] = _balances[sender].sub(amount,ERC20: transfer amount exceeds balance) (#1138)
- _balances[recipient] = _balances[recipient].add(amount) (#1139)
- super._transfer(from,to,amount) (#1795)
- _balances[sender] = _balances[sender].sub(amount,ERC20: transfer amount exceeds balance) (#1138)
- _balances[recipient] = _balances[recipient].add(amount) (#1139)
- _isSwapping = false (#1778)
Reentrancy in DividendPayingToken._withdrawDividendOfUser(address) (#1321-1337):
External calls:
- (success) = user.call{gas: _gasForWithdrawingDividendOfUser,value: _withdrawableDividend}() (#1326)
State variables written after the call(s):
- withdrawnDividends[user] = withdrawnDividends[user].sub(_withdrawableDividend) (#1329)
Reentrancy in SportsFansZone.tryToDistributeTokensManually() (#1812-1823):
External calls:
- swapAndDistribute(balanceOf(address(this))) (#1819)
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
- uniswapV2Router.swapExactTokensForETHSupportingFeeOnTransferTokens(tokenAmount,0,path,address(this),block.timestamp) (#1858-1864)
External calls sending eth:
- swapAndDistribute(balanceOf(address(this))) (#1819)
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
State variables written after the call(s):
- _isSwapping = false (#1821)
Apply the check-effects-interactions pattern.
Additional information: link
Unable to find manual contract audit (e.g. Certik, PeckShield, Solidity...)
SportsFansZone._transfer(address,address,uint256) (#1738-1810) contains a tautology or contradiction:
- require(bool,string)(amount >= 0,ERC20: Transfer amount must be greater or equals to zero) (#1741)
Fix the incorrect comparison by changing the value type or the comparison.
Additional information: link
Combination 1: Reentrancy vulnerabilities + Functions that send Ether to arbitraty destination. Usual for scams. May be justified by some complex mechanics (e.g. rebase, reflections). DYOR & manual audit are advised.
Contract ownership is not renounced (belongs to a wallet)
SportsFansZone.claim() (#1712-1714) ignores return value by dividendTracker.processAccount(address(msg.sender),false) (#1713)
SportsFansZone._transfer(address,address,uint256) (#1738-1810) ignores return value by dividendTracker.process(gas) (#1803-1808)
SportsFansZone.addLiquidity(uint256,uint256) (#1868-1883) ignores return value by uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
Ensure that all the return values of the function calls are used.
Additional information: link
DividendPayingToken.constructor(string,string)._name (#1276) shadows:
- ERC20._name (#960) (state variable)
DividendPayingToken.constructor(string,string)._symbol (#1276) shadows:
- ERC20._symbol (#961) (state variable)
Rename the local variables that shadow another component.
Additional information: link
SportsFansZone.setTradingEnabledTimestamp(uint256) (#1728-1731) should emit an event for:
- tradingEnabledTimestamp = timestamp (#1730)
SportsFansZone.setSwapTokenAtAmount(uint256) (#1954-1958) should emit an event for:
- _swapTokensAtAmount = amount * 10 ** 9 (#1956)
Emit an event for critical parameter changes.
Additional information: link
SportsFansZone.getStuckBNBs(address).to (#1922) lacks a zero-check on :
- to.transfer(address(this).balance) (#1924)
Check that the address is not zero.
Additional information: link
DividendPayingToken._withdrawDividendOfUser(address) (#1321-1337) has external calls inside a loop: (success) = user.call{gas: _gasForWithdrawingDividendOfUser,value: _withdrawableDividend}() (#1326)
Favor pull over push strategy for external calls.
Additional information: link
SafeMathInt.MAX_INT256 (#392) is never used in SafeMathInt (#390-448)
Remove unused state variables.
Additional information: link
SportsFansZone.BNBRewardsFee (#1444) should be constant
SportsFansZone.giftFee (#1447) should be constant
SportsFansZone.giftWallet (#1438) should be constant
SportsFansZone.liquidityFee (#1445) should be constant
SportsFansZone.marketingFee (#1446) should be constant
SportsFansZone.marketingWallet (#1437) should be constant
Add the constant attributes to state variables that never change.
Additional information: link
SportsFansZone.swapAndDistribute(uint256) (#1824-1847) performs a multiplication on the result of a division:
-marketingAmount = newBalance.mul(marketingFee).div(85).mul(10) (#1835)
SportsFansZone.swapAndDistribute(uint256) (#1824-1847) performs a multiplication on the result of a division:
-dividendAmount = newBalance.mul(BNBRewardsFee).div(85).mul(10) (#1836)
SportsFansZone.swapAndDistribute(uint256) (#1824-1847) performs a multiplication on the result of a division:
-giftAmount = newBalance.mul(giftFee).div(85).mul(10) (#1837)
Consider ordering multiplication before division.
Additional information: link
Reentrancy in SportsFansZone.updateDividendTracker(address) (#1562-1582):
External calls:
- newDividendTracker.excludeFromDividends(address(newDividendTracker)) (#1569)
- newDividendTracker.excludeFromDividends(address(this)) (#1570)
- newDividendTracker.excludeFromDividends(owner()) (#1571)
- newDividendTracker.excludeFromDividends(address(uniswapV2Router)) (#1572)
- newDividendTracker.excludeFromDividends(address(marketingWallet)) (#1573)
- newDividendTracker.excludeFromDividends(address(giftWallet)) (#1574)
- newDividendTracker.excludeFromDividends(address(uniswapV2Pair)) (#1575)
State variables written after the call(s):
- dividendTracker = newDividendTracker (#1581)
Apply the check-effects-interactions pattern.
Additional information: link
SportsFansZone._transfer(address,address,uint256).claims (#1803) is a local variable never initialized
SportsFansZone._transfer(address,address,uint256).lastProcessedIndex (#1803) is a local variable never initialized
SportsFansZone._transfer(address,address,uint256).iterations (#1803) is a local variable never initialized
Initialize all the variables. If a variable is meant to be initialized to zero, explicitly set it to zero to improve code readability.
Additional information: link
Variable 'SportsFansZone._transfer(address,address,uint256).claims (#1803)' in SportsFansZone._transfer(address,address,uint256) (#1738-1810) potentially used before declaration: ProcessedDividendTracker(iterations,claims,lastProcessedIndex,true,gas,tx.origin) (#1804)
Variable 'SportsFansZone._transfer(address,address,uint256).iterations (#1803)' in SportsFansZone._transfer(address,address,uint256) (#1738-1810) potentially used before declaration: ProcessedDividendTracker(iterations,claims,lastProcessedIndex,true,gas,tx.origin) (#1804)
Variable 'SportsFansZone._transfer(address,address,uint256).lastProcessedIndex (#1803)' in SportsFansZone._transfer(address,address,uint256) (#1738-1810) potentially used before declaration: ProcessedDividendTracker(iterations,claims,lastProcessedIndex,true,gas,tx.origin) (#1804)
Move all variable declarations prior to any usage of the variable, and ensure that reaching a variable declaration does not depend on some conditional if it is used unconditionally.
Additional information: link
Reentrancy in SportsFansZone.constructor() (#1512-1550):
External calls:
- uniswapV2Pair = IUniswapV2Factory(uniswapV2Router.factory()).createPair(address(this),uniswapV2Router.WETH()) (#1522-1523)
- _setAutomatedMarketMakerPair(uniswapV2Pair,true) (#1525)
- dividendTracker.excludeFromDividends(pair) (#1628)
- dividendTracker.excludeFromDividends(address(dividendTracker)) (#1528)
- dividendTracker.excludeFromDividends(address(this)) (#1529)
- dividendTracker.excludeFromDividends(owner()) (#1530)
- dividendTracker.excludeFromDividends(address(uniswapV2Router)) (#1531)
- dividendTracker.excludeFromDividends(address(marketingWallet)) (#1532)
- dividendTracker.excludeFromDividends(address(giftWallet)) (#1533)
- dividendTracker.excludeFromDividends(address(DEAD)) (#1534)
State variables written after the call(s):
- _mint(owner(),1 * 10 ** 15 * (10 ** 9)) (#1548)
- _balances[account] = _balances[account].add(amount) (#1158)
- _canTransferBeforeTradingIsEnabled[owner()] = true (#1546)
- excludeFromFees(liquidityWallet,true) (#1537)
- _isExcludedFromFees[account] = excluded (#1600)
- excludeFromFees(marketingWallet,true) (#1538)
- _isExcludedFromFees[account] = excluded (#1600)
- excludeFromFees(giftWallet,true) (#1539)
- _isExcludedFromFees[account] = excluded (#1600)
- excludeFromFees(address(this),true) (#1540)
- _isExcludedFromFees[account] = excluded (#1600)
- excludeFromMaxSellTransactionAmount(owner(),true) (#1543)
- _isExcludedFromMaxSellTransactionAmount[account] = excluded (#1613)
- _mint(owner(),1 * 10 ** 15 * (10 ** 9)) (#1548)
- _totalSupply = _totalSupply.add(amount) (#1157)
Reentrancy in SFZDividendTracker.processAccount(address,bool) (#2176-2186):
External calls:
- amount = _withdrawDividendOfUser(account) (#2177)
- (success) = user.call{gas: _gasForWithdrawingDividendOfUser,value: _withdrawableDividend}() (#1326)
State variables written after the call(s):
- lastClaimTimes[account] = block.timestamp (#2180)
Reentrancy in SportsFansZone.swapAndDistribute(uint256) (#1824-1847):
External calls:
- swapTokensForEth(amount.sub(liquidityTokensToNotSwap)) (#1831)
- uniswapV2Router.swapExactTokensForETHSupportingFeeOnTransferTokens(tokenAmount,0,path,address(this),block.timestamp) (#1858-1864)
- addLiquidity(liquidityTokensToNotSwap,liquidityAmount) (#1841)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
External calls sending eth:
- addLiquidity(liquidityTokensToNotSwap,liquidityAmount) (#1841)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
State variables written after the call(s):
- addLiquidity(liquidityTokensToNotSwap,liquidityAmount) (#1841)
- _allowances[owner][spender] = amount (#1204)
Apply the check-effects-interactions pattern.
Additional information: link
Reentrancy in SportsFansZone._setAutomatedMarketMakerPair(address,bool) (#1623-1632):
External calls:
- dividendTracker.excludeFromDividends(pair) (#1628)
Event emitted after the call(s):
- SetAutomatedMarketMakerPair(pair,value) (#1631)
Reentrancy in SportsFansZone._transfer(address,address,uint256) (#1738-1810):
External calls:
- swapAndDistribute(balanceOf(address(this))) (#1776)
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
- uniswapV2Router.swapExactTokensForETHSupportingFeeOnTransferTokens(tokenAmount,0,path,address(this),block.timestamp) (#1858-1864)
External calls sending eth:
- swapAndDistribute(balanceOf(address(this))) (#1776)
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
Event emitted after the call(s):
- Transfer(sender,recipient,amount) (#1140)
- super._transfer(from,address(this),fees) (#1792)
- Transfer(sender,recipient,amount) (#1140)
- super._transfer(from,to,amount) (#1795)
Reentrancy in SportsFansZone._transfer(address,address,uint256) (#1738-1810):
External calls:
- swapAndDistribute(balanceOf(address(this))) (#1776)
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
- uniswapV2Router.swapExactTokensForETHSupportingFeeOnTransferTokens(tokenAmount,0,path,address(this),block.timestamp) (#1858-1864)
- dividendTracker.setBalance(address(from),balanceOf(from)) (#1797)
- dividendTracker.setBalance(address(to),balanceOf(to)) (#1798)
- dividendTracker.process(gas) (#1803-1808)
External calls sending eth:
- swapAndDistribute(balanceOf(address(this))) (#1776)
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
Event emitted after the call(s):
- ProcessedDividendTracker(iterations,claims,lastProcessedIndex,true,gas,tx.origin) (#1804)
Reentrancy in SportsFansZone.burn(uint256) (#1948-1952):
External calls:
- _transfer(_msgSender(),DEAD,amount) (#1949)
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
- uniswapV2Router.swapExactTokensForETHSupportingFeeOnTransferTokens(tokenAmount,0,path,address(this),block.timestamp) (#1858-1864)
- dividendTracker.setBalance(address(from),balanceOf(from)) (#1797)
- dividendTracker.setBalance(address(to),balanceOf(to)) (#1798)
- dividendTracker.process(gas) (#1803-1808)
External calls sending eth:
- _transfer(_msgSender(),DEAD,amount) (#1949)
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
Event emitted after the call(s):
- Burn(amount) (#1950)
Reentrancy in SportsFansZone.constructor() (#1512-1550):
External calls:
- uniswapV2Pair = IUniswapV2Factory(uniswapV2Router.factory()).createPair(address(this),uniswapV2Router.WETH()) (#1522-1523)
- _setAutomatedMarketMakerPair(uniswapV2Pair,true) (#1525)
- dividendTracker.excludeFromDividends(pair) (#1628)
Event emitted after the call(s):
- SetAutomatedMarketMakerPair(pair,value) (#1631)
- _setAutomatedMarketMakerPair(uniswapV2Pair,true) (#1525)
Reentrancy in SportsFansZone.constructor() (#1512-1550):
External calls:
- uniswapV2Pair = IUniswapV2Factory(uniswapV2Router.factory()).createPair(address(this),uniswapV2Router.WETH()) (#1522-1523)
- _setAutomatedMarketMakerPair(uniswapV2Pair,true) (#1525)
- dividendTracker.excludeFromDividends(pair) (#1628)
- dividendTracker.excludeFromDividends(address(dividendTracker)) (#1528)
- dividendTracker.excludeFromDividends(address(this)) (#1529)
- dividendTracker.excludeFromDividends(owner()) (#1530)
- dividendTracker.excludeFromDividends(address(uniswapV2Router)) (#1531)
- dividendTracker.excludeFromDividends(address(marketingWallet)) (#1532)
- dividendTracker.excludeFromDividends(address(giftWallet)) (#1533)
- dividendTracker.excludeFromDividends(address(DEAD)) (#1534)
Event emitted after the call(s):
- ExcludeFromFees(account,excluded) (#1602)
- excludeFromFees(giftWallet,true) (#1539)
- ExcludeFromFees(account,excluded) (#1602)
- excludeFromFees(marketingWallet,true) (#1538)
- ExcludeFromFees(account,excluded) (#1602)
- excludeFromFees(liquidityWallet,true) (#1537)
- ExcludeFromFees(account,excluded) (#1602)
- excludeFromFees(address(this),true) (#1540)
- ExcludeFromMaxSellTransactionAmount(account,excluded) (#1614)
- excludeFromMaxSellTransactionAmount(owner(),true) (#1543)
- Transfer(address(0),account,amount) (#1159)
- _mint(owner(),1 * 10 ** 15 * (10 ** 9)) (#1548)
Reentrancy in SFZDividendTracker.processAccount(address,bool) (#2176-2186):
External calls:
- amount = _withdrawDividendOfUser(account) (#2177)
- (success) = user.call{gas: _gasForWithdrawingDividendOfUser,value: _withdrawableDividend}() (#1326)
Event emitted after the call(s):
- Claim(account,amount,automatic) (#2181)
Reentrancy in SportsFansZone.processDividendTracker(uint256) (#1708-1711):
External calls:
- (iterations,claims,lastProcessedIndex) = dividendTracker.process(gas) (#1709)
Event emitted after the call(s):
- ProcessedDividendTracker(iterations,claims,lastProcessedIndex,false,gas,tx.origin) (#1710)
Reentrancy in SportsFansZone.sendGiftDividends(uint256) (#1900-1906):
External calls:
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
Event emitted after the call(s):
- SendGiftDividends(amount) (#1904)
Reentrancy in SportsFansZone.sendHolderDividends(uint256) (#1884-1891):
External calls:
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
Event emitted after the call(s):
- SendHolderDividends(amount) (#1889)
Reentrancy in SportsFansZone.sendMarketingDividends(uint256) (#1893-1899):
External calls:
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
Event emitted after the call(s):
- SendMarketingDividends(amount) (#1897)
Reentrancy in SportsFansZone.swapAndDistribute(uint256) (#1824-1847):
External calls:
- swapTokensForEth(amount.sub(liquidityTokensToNotSwap)) (#1831)
- uniswapV2Router.swapExactTokensForETHSupportingFeeOnTransferTokens(tokenAmount,0,path,address(this),block.timestamp) (#1858-1864)
- addLiquidity(liquidityTokensToNotSwap,liquidityAmount) (#1841)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
External calls sending eth:
- addLiquidity(liquidityTokensToNotSwap,liquidityAmount) (#1841)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
Event emitted after the call(s):
- Approval(owner,spender,amount) (#1205)
- addLiquidity(liquidityTokensToNotSwap,liquidityAmount) (#1841)
Reentrancy in SportsFansZone.swapAndDistribute(uint256) (#1824-1847):
External calls:
- swapTokensForEth(amount.sub(liquidityTokensToNotSwap)) (#1831)
- uniswapV2Router.swapExactTokensForETHSupportingFeeOnTransferTokens(tokenAmount,0,path,address(this),block.timestamp) (#1858-1864)
- addLiquidity(liquidityTokensToNotSwap,liquidityAmount) (#1841)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- sendHolderDividends(dividendAmount) (#1842)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
External calls sending eth:
- addLiquidity(liquidityTokensToNotSwap,liquidityAmount) (#1841)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- sendHolderDividends(dividendAmount) (#1842)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
Event emitted after the call(s):
- SendHolderDividends(amount) (#1889)
- sendHolderDividends(dividendAmount) (#1842)
Reentrancy in SportsFansZone.swapAndDistribute(uint256) (#1824-1847):
External calls:
- swapTokensForEth(amount.sub(liquidityTokensToNotSwap)) (#1831)
- uniswapV2Router.swapExactTokensForETHSupportingFeeOnTransferTokens(tokenAmount,0,path,address(this),block.timestamp) (#1858-1864)
- addLiquidity(liquidityTokensToNotSwap,liquidityAmount) (#1841)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- sendHolderDividends(dividendAmount) (#1842)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
- sendMarketingDividends(marketingAmount) (#1843)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
External calls sending eth:
- addLiquidity(liquidityTokensToNotSwap,liquidityAmount) (#1841)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- sendHolderDividends(dividendAmount) (#1842)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
- sendMarketingDividends(marketingAmount) (#1843)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
Event emitted after the call(s):
- SendMarketingDividends(amount) (#1897)
- sendMarketingDividends(marketingAmount) (#1843)
Reentrancy in SportsFansZone.swapAndDistribute(uint256) (#1824-1847):
External calls:
- swapTokensForEth(amount.sub(liquidityTokensToNotSwap)) (#1831)
- uniswapV2Router.swapExactTokensForETHSupportingFeeOnTransferTokens(tokenAmount,0,path,address(this),block.timestamp) (#1858-1864)
- addLiquidity(liquidityTokensToNotSwap,liquidityAmount) (#1841)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- sendHolderDividends(dividendAmount) (#1842)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
- sendMarketingDividends(marketingAmount) (#1843)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
- sendGiftDividends(giftAmount) (#1844)
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
External calls sending eth:
- addLiquidity(liquidityTokensToNotSwap,liquidityAmount) (#1841)
- uniswapV2Router.addLiquidityETH{value: ethAmount}(address(this),tokenAmount,0,0,liquidityWallet,block.timestamp) (#1874-1881)
- sendHolderDividends(dividendAmount) (#1842)
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
- sendMarketingDividends(marketingAmount) (#1843)
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
- sendGiftDividends(giftAmount) (#1844)
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
Event emitted after the call(s):
- SendGiftDividends(amount) (#1904)
- sendGiftDividends(giftAmount) (#1844)
- SwapAndLiquify(amount.sub(liquidityTokensToNotSwap),newBalance,liquidityTokensToNotSwap) (#1845)
Reentrancy in SportsFansZone.updateDividendTracker(address) (#1562-1582):
External calls:
- newDividendTracker.excludeFromDividends(address(newDividendTracker)) (#1569)
- newDividendTracker.excludeFromDividends(address(this)) (#1570)
- newDividendTracker.excludeFromDividends(owner()) (#1571)
- newDividendTracker.excludeFromDividends(address(uniswapV2Router)) (#1572)
- newDividendTracker.excludeFromDividends(address(marketingWallet)) (#1573)
- newDividendTracker.excludeFromDividends(address(giftWallet)) (#1574)
- newDividendTracker.excludeFromDividends(address(uniswapV2Pair)) (#1575)
Event emitted after the call(s):
- UpdateDividendTracker(newAddress,address(dividendTracker)) (#1579)
Apply the check-effects-interactions pattern.
Additional information: link
Ownable.unlock() (#777-782) uses timestamp for comparisons
Dangerous comparisons:
- require(bool,string)(block.timestamp > _lockTime,Contract is still locked) (#779)
SportsFansZone.getTradingIsEnabled() (#1724-1726) uses timestamp for comparisons
Dangerous comparisons:
- block.timestamp >= tradingEnabledTimestamp (#1725)
SportsFansZone.setTradingEnabledTimestamp(uint256) (#1728-1731) uses timestamp for comparisons
Dangerous comparisons:
- require(bool,string)(tradingEnabledTimestamp > block.timestamp,SFZ: Changing the timestamp is not allowed if the listing has already started) (#1729)
SportsFansZone._transfer(address,address,uint256) (#1738-1810) uses timestamp for comparisons
Dangerous comparisons:
- ! _isSwapping && tradingIsEnabled && isSellTransfer && from != address(uniswapV2Router) && ! _isExcludedFromMaxSellTransactionAmount[to] && ! _isExcludedFromMaxSellTransactionAmount[from] (#1754-1759)
- tradingIsEnabled && canSwap && ! _isSwapping && ! automatedMarketMakerPairs[from] && from != liquidityWallet && to != liquidityWallet (#1767-1772)
- takeFee = tradingIsEnabled && ! _isSwapping (#1781)
SportsFansZone.tryToDistributeTokensManually() (#1812-1823) uses timestamp for comparisons
Dangerous comparisons:
- getTradingIsEnabled() && ! _isSwapping (#1814-1815)
SFZDividendTracker.getAccount(address) (#2039-2081) uses timestamp for comparisons
Dangerous comparisons:
- nextClaimTime > block.timestamp (#2078-2080)
SFZDividendTracker.canAutoClaim(uint256) (#2102-2108) uses timestamp for comparisons
Dangerous comparisons:
- lastClaimTime > block.timestamp (#2103)
- block.timestamp.sub(lastClaimTime) >= claimWait (#2107)
Avoid relying on block.timestamp.
Additional information: link
Context._msgData() (#635-638) is never used and should be removed
SafeMath.mod(uint256,uint256) (#593-595) is never used and should be removed
SafeMath.mod(uint256,uint256,string) (#609-612) is never used and should be removed
SafeMathInt.abs(int256) (#438-441) is never used and should be removed
SafeMathInt.div(int256,int256) (#409-415) is never used and should be removed
SafeMathInt.mul(int256,int256) (#397-404) is never used and should be removed
Remove unused functions.
Additional information: link
Pragma version^0.8.11 (#7) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#151) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#172) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#227) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#289) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#316) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#384) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#453) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#470) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#618) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#644) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#708) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#810) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#893) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#921) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#1232) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
Pragma version^0.8.11 (#1416) necessitates a version too recent to be trusted. Consider deploying with 0.6.12/0.7.6/0.8.7
solc-0.8.11 is not recommended for deployment
Deploy with any of the following Solidity versions: 0.5.16 - 0.5.17, 0.6.11 - 0.6.12, 0.7.5 - 0.7.6 Use a simple pragma version that allows any of these versions. Consider using the latest version of Solidity for testing.
Additional information: link
Low level call in DividendPayingToken._withdrawDividendOfUser(address) (#1321-1337):
- (success) = user.call{gas: _gasForWithdrawingDividendOfUser,value: _withdrawableDividend}() (#1326)
Low level call in SportsFansZone.sendHolderDividends(uint256) (#1884-1891):
- (success) = address(address(dividendTracker)).call{value: amount}() (#1886)
Low level call in SportsFansZone.sendMarketingDividends(uint256) (#1893-1899):
- (success) = address(address(marketingWallet)).call{value: amount}() (#1894)
Low level call in SportsFansZone.sendGiftDividends(uint256) (#1900-1906):
- (success) = address(address(giftWallet)).call{value: amount}() (#1901)
Avoid low-level calls. Check the call success. If the call is meant for a contract, check for code existence
Additional information: link
Function IUniswapV2Router01.WETH() (#11) is not in mixedCase
Function IUniswapV2Pair.DOMAIN_SEPARATOR() (#189) is not in mixedCase
Function IUniswapV2Pair.PERMIT_TYPEHASH() (#190) is not in mixedCase
Function IUniswapV2Pair.MINIMUM_LIQUIDITY() (#207) is not in mixedCase
Parameter DividendPayingToken.dividendOf(address)._owner (#1348) is not in mixedCase
Parameter DividendPayingToken.withdrawableDividendOf(address)._owner (#1355) is not in mixedCase
Parameter DividendPayingToken.withdrawnDividendOf(address)._owner (#1362) is not in mixedCase
Parameter DividendPayingToken.accumulativeDividendOf(address)._owner (#1372) is not in mixedCase
Constant DividendPayingToken.magnitude (#1254) is not in UPPER_CASE_WITH_UNDERSCORES
Parameter SportsFansZone.blackList(address)._account (#1927) is not in mixedCase
Parameter SportsFansZone.removeFromBlacklist(address)._account (#1938) is not in mixedCase
Variable SportsFansZone.BNBRewardsFee (#1444) is not in mixedCase
Parameter SFZDividendTracker.getAccount(address)._account (#2039) is not in mixedCase
Variable SFZDividendTracker.MINIMUM_TOKEN_BALANCE_FOR_DIVIDENDS (#1979) is not in mixedCase
Follow the Solidity naming convention.
Additional information: link
Redundant expression "this (#636)" inContext (#630-639)
Remove redundant statements if they congest code but offer no value.
Additional information: link
Variable IUniswapV2Router01.addLiquidity(address,address,uint256,uint256,uint256,uint256,address,uint256).amountADesired (#16) is too similar to IUniswapV2Router01.addLiquidity(address,address,uint256,uint256,uint256,uint256,address,uint256).amountBDesired (#17)
Variable DividendPayingToken._withdrawDividendOfUser(address)._withdrawableDividend (#1322) is too similar to SFZDividendTracker.getAccount(address).withdrawableDividends (#2044)
Prevent variables from having similar names.
Additional information: link
SportsFansZone.updateGasForProcessing(uint256) (#1642-1647) uses literals with too many digits:
- require(bool,string)(newValue >= 100000 && newValue <= 500000,SFZ: gasForProcessing must be between 100,000 and 500,000) (#1643)
SportsFansZone.slitherConstructorVariables() (#1426-1964) uses literals with too many digits:
- gasForProcessing = 300000 (#1452)
SportsFansZone.slitherConstructorConstantVariables() (#1426-1964) uses literals with too many digits:
- DEAD = 0x000000000000000000000000000000000000dEaD (#1439)
SFZDividendTracker.getAccountAtIndex(uint256) (#2083-2100) uses literals with too many digits:
- (0x0000000000000000000000000000000000000000,- 1,- 1,0,0,0,0,0) (#2094)
Use: Ether suffix, Time suffix, or The scientific notation
Additional information: link
get(IterableMapping.Map,address) should be declared external:
- IterableMapping.get(IterableMapping.Map,address) (#237-239)
getIndexOfKey(IterableMapping.Map,address) should be declared external:
- IterableMapping.getIndexOfKey(IterableMapping.Map,address) (#241-246)
getKeyAtIndex(IterableMapping.Map,uint256) should be declared external:
- IterableMapping.getKeyAtIndex(IterableMapping.Map,uint256) (#248-250)
size(IterableMapping.Map) should be declared external:
- IterableMapping.size(IterableMapping.Map) (#253-255)
renounceOwnership() should be declared external:
- Ownable.renounceOwnership() (#753-756)
transferOwnership(address) should be declared external:
- Ownable.transferOwnership(address) (#762-766)
lock(uint256) should be declared external:
- Ownable.lock(uint256) (#769-774)
unlock() should be declared external:
- Ownable.unlock() (#777-782)
authorize(address) should be declared external:
- Ownable.authorize(address) (#790-792)
unauthorize(address) should be declared external:
- Ownable.unauthorize(address) (#795-797)
name() should be declared external:
- ERC20.name() (#980-982)
symbol() should be declared external:
- ERC20.symbol() (#988-990)
decimals() should be declared external:
- ERC20.decimals() (#1005-1007)
transfer(address,uint256) should be declared external:
- ERC20.transfer(address,uint256) (#1031-1034)
allowance(address,address) should be declared external:
- ERC20.allowance(address,address) (#1039-1041)
approve(address,uint256) should be declared external:
- ERC20.approve(address,uint256) (#1050-1053)
transferFrom(address,address,uint256) should be declared external:
- ERC20.transferFrom(address,address,uint256) (#1068-1076)
increaseAllowance(address,uint256) should be declared external:
- ERC20.increaseAllowance(address,uint256) (#1090-1093)
decreaseAllowance(address,uint256) should be declared external:
- ERC20.decreaseAllowance(address,uint256) (#1109-1112)
withdrawDividend() should be declared external:
- DividendPayingToken.withdrawDividend() (#1315-1317)
- SFZDividendTracker.withdrawDividend() (#1997-1999)
dividendOf(address) should be declared external:
- DividendPayingToken.dividendOf(address) (#1348-1350)
withdrawnDividendOf(address) should be declared external:
- DividendPayingToken.withdrawnDividendOf(address) (#1362-1364)
unpause() should be declared external:
- SportsFansZone.unpause() (#1555-1557)
pause() should be declared external:
- SportsFansZone.pause() (#1558-1560)
updateDividendTracker(address) should be declared external:
- SportsFansZone.updateDividendTracker(address) (#1562-1582)
updateUniswapRouter(address) should be declared external:
- SportsFansZone.updateUniswapRouter(address) (#1584-1589)
excludeMultipleAccountsFromFees(address[],bool) should be declared external:
- SportsFansZone.excludeMultipleAccountsFromFees(address[],bool) (#1605-1609)
setAutomatedMarketMakerPair(address,bool) should be declared external:
- SportsFansZone.setAutomatedMarketMakerPair(address,bool) (#1617-1621)
updateLiquidityWallet(address) should be declared external:
- SportsFansZone.updateLiquidityWallet(address) (#1635-1640)
updateGasForProcessing(uint256) should be declared external:
- SportsFansZone.updateGasForProcessing(uint256) (#1642-1647)
isExcludedFromFees(address) should be declared external:
- SportsFansZone.isExcludedFromFees(address) (#1661-1663)
isExcludedFromDividends(address) should be declared external:
- SportsFansZone.isExcludedFromDividends(address) (#1664-1666)
isBlacklisted(address) should be declared external:
- SportsFansZone.isBlacklisted(address) (#1667-1669)
isExcludedFromMaxSellTransactionAmount(address) should be declared external:
- SportsFansZone.isExcludedFromMaxSellTransactionAmount(address) (#1670-1672)
withdrawableDividendOf(address) should be declared external:
- SportsFansZone.withdrawableDividendOf(address) (#1674-1676)
dividendTokenBalanceOf(address) should be declared external:
- SportsFansZone.dividendTokenBalanceOf(address) (#1678-1680)
blackList(address) should be declared external:
- SportsFansZone.blackList(address) (#1927-1936)
removeFromBlacklist(address) should be declared external:
- SportsFansZone.removeFromBlacklist(address) (#1938-1942)
getAccountAtIndex(uint256) should be declared external:
- SFZDividendTracker.getAccountAtIndex(uint256) (#2083-2100)
process(uint256) should be declared external:
- SFZDividendTracker.process(uint256) (#2129-2174)
Use the external attribute for functions never called from the contract.
Additional information: link
Unable to find website, listings and other project-related information
Young tokens have high risks of scam / price dump / death
Token has no active CoinGecko listing / rank
Token has no active CoinMarketCap listing / rank
Unable to find Telegram and Twitter accounts