ContractReader logo
Code Review Testing · Security Code Scanning

ContractReader

ContractReader opens any verified EVM smart contract in a readable browser view, with syntax highlighting, live on-chain values and side-by-side code comparison across seven networks. Its beta Audit Tool adds GPT-4 security reviews.

Active GDPR compliant No public API 18+ Verified by Guidaio
Overview

What is ContractReader?

ContractReader is a browser-based reader for smart contracts deployed on EVM networks, published by Contract Reader, a small outfit based in Austin, Texas. The principle is deliberately narrow: you paste a contract address or an Etherscan URL, and the verified source appears in a reading interface rather than in the raw output of a block explorer. Syntax highlighting makes the Solidity structure legible, live on-chain values are shown as you read, and an in-browser comparison lets you check one piece of code against another. Seven networks are served — Mainnet, Sepolia, OP Mainnet, Polygon, Arbitrum One, BNB Smart Chain and Base — so layer 2 deployments and testnet work are treated like mainnet. Every contract gets its own address of the form /contract/:network/:contract_address, complete with a generated title, description and social image. That URL is the product's second idea: it can be shared, bookmarked, or dropped into an iframe to display contract code inside another site or dApp, an integration the publisher documents in a public GitHub repository with a React example. Reading requires no account — a contract page answers without authentication — although the interface itself renders in JavaScript. Five sample contracts on the homepage, among them WETH9 and NounsToken, give a starting point to anyone without an address at hand. The artificial intelligence sits in a second, separate product. The Audit Tool, presented as smart contract auditing tools built for your workflow, is reached by signing up to a beta with an email address. It promises private code pages, pasting raw code, testnet imports, access control based on ENS names, rich comments, contract read and write, and GPT-4 security reviews. The public reader itself advertises no generative feature. Around the product sits a small open-source footprint: an MIT-licensed Chrome extension adding a ContractReader button on Etherscan, OpenSea and Blur, the integration repository, and an ENS experiment. The team is two co-founders under the pseudonyms Backseats and Plaid Shaman. The domain dates from January 2022 and the footer is current for 2026, yet the site remains three pages deep, with no terms, no pricing and no about page.

What it does

  • Open any verified EVM contract from its address or an Etherscan URL
  • Read Solidity source with syntax highlighting instead of raw explorer output
  • Watch live on-chain values while reading the code
  • Compare two pieces of contract code inside the browser
  • Switch between seven networks, mainnet and testnet alike
  • Embed a contract view in your own site or dApp through an iframe
  • Request private code pages and GPT-4 security reviews via the beta Audit Tool
Audience

When to use ContractReader / When not to

A quick filter to help you decide if ContractReader is the right fit.

When to use ContractReader

  • Solidity developers who need to read a deployed contract before calling it or building on top of it
  • Security researchers and auditors who compare code, annotate it and want GPT-4 assisted review
  • dApp teams that want contract code displayed inside their own site through the documented iframe embed
  • Crypto users who check a token or NFT contract found on Etherscan, OpenSea or Blur before interacting with it
  • Engineers working on testnets, since Sepolia and testnet imports are served like mainnet

When not to use ContractReader

  • Anyone after legal contract review: despite the name, this tool reads on-chain code, not legal documents
  • Teams building on non-EVM chains such as Solana, Bitcoin or Cosmos, which the site never mentions
  • Organisations needing contractual guarantees, since there are no terms of service, no SLA and no published pricing
  • Buyers who need a formal, signed security audit rather than GPT-4 assisted reading
  • Mobile-first users and integrators expecting a documented API, as neither exists
Get started

How to use ContractReader

A typical end-to-end flow, from setup to results.

  1. Open contractreader.io; the search field sits on every page of the site
  2. Paste a contract address or an Etherscan URL into the field and press Search
  3. Pick the right network if the contract does not live on Ethereum mainnet: seven are served
  4. Read the verified source, following the structure through the syntax highlighting
  5. Watch the live on-chain values displayed alongside the code
  6. Use the in-browser comparison to check one version of the code against another
  7. With no address at hand, start from the sample contracts listed on the homepage
  8. Share or bookmark the contract URL, built as /contract/:network/:contract_address
  9. To show the same view inside your own site, drop that URL into an iframe with a width and a height
  10. For private code pages, comments and GPT-4 security reviews, sign up with your email on the Audit Tool page
Quick read

Pros & Cons

Pros

  • Reading a contract takes no account, no installation and no payment
  • Every contract has a stable URL that can be shared or embedded
  • Coverage reaches layer 2 networks — OP Mainnet, Arbitrum One, Base, Polygon — not just Ethereum mainnet
  • Live on-chain values turn a static listing into something you can actually inspect
  • Built-in code comparison helps when dealing with proxies and forks
  • The browser extension and the integration example are open source, the extension under an MIT licence
  • The Audit Tool brings GPT-4 security reviews and ENS-based access control to shared code pages

Cons

  • No pricing is published anywhere: no plans, no rates, not even a free tier stated as such
  • No terms of service, so nothing contractually defines the service, its availability or liabilities
  • The Audit Tool, which carries every AI feature, is still gated behind a beta waiting list
  • The privacy notice has not been revised since February 2023
  • No about page and no contact page; a single email address, published only inside the privacy notice
  • No documented API, and the interface renders in JavaScript, so nothing is readable statically
  • No legal form, no hosting country, no DPA and no security certification disclosed, and both co-founders use pseudonyms
Pricing

Pricing & Plans

ContractReader publishes no pricing. There is no rates page, no plan and no amount anywhere on the site or in its sitemap, and no free tier is advertised as such. In practice the public reader is used without an account and without payment, a contract page answering without authentication, while the Audit Tool is obtained by joining a beta waiting list rather than by purchase. The privacy notice nevertheless provides for collecting billing addresses and card numbers should a purchase be made, so a paid offer may exist or be planned without being documented anywhere on the site.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how ContractReader handles your data.

GDPR overview

GDPR is addressed explicitly but modestly. A dedicated section states that the GDPR and the UK GDPR require the publisher to justify its processing, and lists four legal bases: consent, legitimate interests, legal obligations and vital interests. Visitors in the EEA, the UK and Canada are told they may request access and a copy, rectification or erasure, restriction of processing and portability, and may object to processing; consent can be withdrawn at any time. The notice links to the European Commission's directory of supervisory authorities and to the Swiss authority. Requests go through a Termly form or to info@contractreader.io. Two gaps matter for European readers: no Article 27 EU representative and no data protection officer are named, and no international transfer mechanism is described although the publisher sits in Texas.

Who owns the data?

The privacy notice, last updated on 21 February 2023, presents Contract Reader as the controller of the personal data it collects: names, email addresses, passwords, billing addresses, card numbers and authentication data supplied at sign-up, plus automatically captured IP addresses, device characteristics, log data and location. The publisher states that it processes no sensitive personal information and receives none from third parties. It also declares that it has neither sold nor shared personal data in the preceding twelve months and will not do so in future. Users keep the right to review, correct or delete their data through a Termly request form or by writing to info@contractreader.io.

Reuse rights

No terms of service are published, so nothing on the site grants or restricts what a visitor may do with the contract code shown: that code is public on-chain material ContractReader renders rather than owns. On the publisher's side, the privacy notice limits processing to account creation and authentication, feedback requests, usage-trend analysis, security, fraud prevention and legal compliance, with cookies and pixels used for measurement. Personal data is shared in one situation only, a business transfer, and with service providers bound by written contract. Internal research for technological development is explicitly excluded from the definition of selling, and Do-Not-Track signals are not honoured. Nothing in the notice says whether user content feeds AI model training.

Data retention & training

Retention summary
Personal data is kept only as long as the purposes of the privacy notice require, unless a longer period is imposed by law for tax or accounting reasons. The publisher sets one explicit ceiling: no purpose justifies keeping personal data beyond the period during which a user holds an account. Once the need ends, data is deleted or anonymised; where that is impossible, inside backups for instance, it is stored securely and isolated from further processing until deletion becomes possible. Closing an account triggers deactivation or deletion from the active databases, with a residual copy kept to prevent fraud, troubleshoot, support investigations and meet legal obligations. Deletion is requested through the Termly form or by email to info@contractreader.io.
GDPR contact

Hosting summary

Nothing is published. The privacy notice names no hosting country, no region and no infrastructure provider, and a targeted search across every archived page returned nothing. The only third-party reference is a generic mention, in the CCPA section, of service providers bound by a written contract: no subprocessor list, no data processing agreement, and no security certification such as SOC 2 or ISO 27001. What can be said comes from outside the publisher's own statements. The company is established in Austin, Texas, with no declared European establishment or representative, and the domain resolves to 76.76.21.21, an anycast address that geolocation places in the United States. That last point describes a network node, not a commitment about where personal data lives. A European reader should therefore treat the hosting jurisdiction as undocumented rather than assume it, and ask directly before entrusting anything sensitive to the beta Audit Tool.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting ContractReader.

  • The name misleads: this tool reads on-chain code, not legal agreements, and several third-party directories wrongly file it under legal contract review
  • GPT-4 security reviews assist reading; they are not an audit, and no methodology, guarantee or certification is published
  • What you see is the verified source as published: an unverified contract or a proxy may not show what actually executes
  • Legible code invites false confidence, and a contract that reads cleanly can still be malicious
  • No terms of service define availability or liability, the publisher discloses no legal form, and both co-founders use pseudonyms
  • The privacy notice allows location data collection and states that Do-Not-Track signals are not honoured
  • Pasting unpublished code into the Audit Tool's private pages means trusting a publisher with no DPA and no stated hosting jurisdiction
Setup

Setup & Integrations

Technical difficulty

Very low to read, higher to exploit. A browser is enough: no account, no installation, no configuration. You do need a contract address or an Etherscan URL, and you must know which of the seven networks it belongs to. Getting real value assumes familiarity with Solidity and on-chain concepts, since the tool makes code legible rather than explaining it. Embedding a contract view in another site takes a few lines of HTML or JSX. The Chrome extension installs manually from GitHub, unpacked. The Audit Tool requires signing up to a beta whose opening date is unknown.

Deployment

Web app

Integrations

Etherscan ENS
Company

Behind ContractReader

Company name
Contract Reader
Founded
11/01/2022
Country of origin
🇺🇸 United States
Headquarters
1413 Valleyridge Dr. Unit B, Austin, TX 78704, United States
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Support contact
Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What exactly does ContractReader do?
It displays the verified source code of an EVM smart contract in a reading interface, with syntax highlighting, live on-chain values and in-browser code comparison, instead of the raw output of a block explorer.
Which networks are covered?
Seven are listed on the homepage: Mainnet, Sepolia, OP Mainnet, Polygon, Arbitrum One, BNB Smart Chain and Base.
Do I need an account?
Not to read a contract: the page answers without authentication. The Audit Tool is different, since it requires signing up to its beta with an email address.
How much does it cost?
No price is published anywhere on the site and no paid offer is presented. The privacy notice does provide for billing data in case of a purchase, without describing any offer.
Where does the AI come in?
In the Audit Tool, which announces GPT-4 security reviews alongside private code pages and comments. The public reader advertises no generative feature.
Can I embed it in my own site?
Yes. The contract URL follows the pattern /contract/:network/:contract_address and can be placed in an iframe with a width and a height; a React example is published on the publisher's GitHub.
Is there a browser extension?
An official Chrome extension is published on GitHub under an MIT licence and adds a ContractReader button on Etherscan, OpenSea and Blur. Its README still lists submission to the Chrome Web Store as pending.
Is there an API?
No API documentation is published. The only documented scheme is the contract URL used for iframe embedding.
Who publishes the tool and how do I reach them?
Contract Reader, 1413 Valleyridge Dr. Unit B, Austin, TX 78704, United States, by email at info@contractreader.io. Two co-founders are shown under the pseudonyms Backseats and Plaid Shaman.
What happens to my data?
It is kept while the account exists, then deleted or anonymised, with a residual copy retained for fraud prevention and legal obligations. Deletion is requested through a Termly form or by email.
Conclusion

Should you pick ContractReader?

ContractReader does one thing and does it plainly: it takes a contract address and gives back code you can actually read, with the on-chain values moving next to it. For a Solidity developer checking a deployment, a researcher comparing a fork with its original, or a user verifying a token before signing anything, that is a genuine improvement on a block explorer, and it costs nothing, needs no account and works across seven EVM networks including several layer 2s. The stable per-contract URL and the documented iframe embed make it useful beyond a single browser tab, and the open-source extension shows a publisher comfortable with being read. What has to be accepted is the thinness of everything around the product. There are no terms of service, no pricing of any kind, no about or contact page, and a privacy notice frozen in February 2023. The publisher is a name without a legal form at an Austin address, run by two co-founders under pseudonyms. The artificial intelligence everyone will come for — GPT-4 security reviews — lives in an Audit Tool still behind a beta waiting list, so it cannot be judged on evidence. Treat ContractReader as an excellent free companion to a block explorer rather than as a service you can lean on contractually, and remember that a legible contract is not a safe contract: readable code, and even a model's commentary on it, is no substitute for an audit. On that understanding, it is a tool worth keeping one click away.